Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Totálně zasekaný notes

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Roman47cz
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 23 srp 2006 17:12

Totálně zasekaný notes

#1 Příspěvek od Roman47cz »

Nazdar, potřebuji pomoct se svým notebookem, mám před státnicemi na vysoké, bakalářku atp. Tudíž nemám příliš času na přeinstalování celého OS a všech programů. Asi tak poslední měsíc mi začal zlobit Windows, začal se postupně zpomalovat, takže teď trvá přihlášení do systému i několik minut, veškerý aplikace mi během chodu zamrzají. Fakt nevím co s tím, již jsem zkoušel antiviry, pročišťovat registry, defragmentovat disk, ale nic z toho nepomohlo.

Logfile of random's system information tool 1.08 (written by random/random)
Run by Roman at 2011-04-25 17:45:46
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 23 GB (41%) free of 56 GB
Total RAM: 3070 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:46:00, on 25.4.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
C:\Windows\AsScrPro.exe
C:\Users\Roman\AppData\Local\Seznam.cz\postak.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
C:\QIP 2010\qip.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe
C:\Users\Roman\Desktop\quietHDD.exe
C:\Program Files\trend micro\Roman.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\SnagIt 9\SnagItBHO.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll
O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\SnagIt 9\SnagItIEAddin.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
O4 - HKCU\..\Run: [Seznam Postak] "C:\Users\Roman\AppData\Local\Seznam.cz\postak.exe" -s
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: FancyStart daemon.lnk = ?
O4 - Global Startup: SRS Premium Sound.lnk = ?
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout s IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Stáhnout s IDM obsah FLV videa - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Stáhnout s IDM všechny odkazy - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\Skype4COM.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AMD Reservation Manager - Advanced Micro Devices - C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: O&O Defrag - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11762 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE 0x2fc
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
"C:\Program Files\Sandboxie\SbieSvc.exe"
"C:\Windows\system32\FBAgent.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe"
"C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files\OO Software\Defrag\oodag.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
C:\Windows\system32\svchost.exe -k bthsvcs
"taskhost.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
taskeng.exe {0FFB467A-B08B-44B0-A7AE-00B37633F8E7}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe"
"C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe"
"C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
WLIDSvcM.exe 1544
"C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe"
ATKOSD.exe
"C:\Windows\AsScrPro.exe"
"C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
"C:\Users\Roman\AppData\Local\Seznam.cz\postak.exe" -s
WDC.exe
"C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe" /f=srs_premium_sound_nopreset.zip /h
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\QIP 2010\qip.exe" /isolated
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Opera\opera.exe"
"C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Users\Roman\Desktop\quietHDD.exe"
"C:\Users\Roman\AppData\Local\Opera\Opera\temporary_downloads\RSITx64.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup

======Scheduled tasks folder======

C:\Windows\tasks\GlaryInitialize.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3496903114-3669578777-545992414-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3496903114-3669578777-545992414-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2011-03-17 357216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00C6482D-C502-44C8-8409-FCE54AD9C208}]
SnagIt Toolbar Loader - C:\Program Files (x86)\TechSmith\SnagIt 9\DLLx64\SnagItBHO64.dll [2008-05-15 62280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll [2011-03-22 241464]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2011-03-17 210352]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00C6482D-C502-44C8-8409-FCE54AD9C208}]
SnagIt Toolbar Loader - C:\Program Files (x86)\TechSmith\SnagIt 9\SnagItBHO.dll [2008-05-15 66888]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files (x86)\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll [2011-01-28 726016]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
uTorrentBar Toolbar - C:\Program Files (x86)\uTorrentBar\tbuTor.dll [2010-12-09 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-02-09 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - uTorrentBar Toolbar - C:\Program Files (x86)\uTorrentBar\tbuTor.dll [2010-12-09 3911776]
{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - SnagIt - C:\Program Files (x86)\TechSmith\SnagIt 9\SnagItIEAddin.dll [2008-05-15 161096]
{C55BBCD6-41AD-48AD-9953-3609C48EACC7} - Grab Pro - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll [2011-03-22 687808]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files (x86)\pdfforge Toolbar\IE\4.3\pdfforgeToolbarIE.dll [2011-01-28 726016]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2010-04-13 649608]
"RivaTunerStartupDaemon"=C:\Program Files (x86)\RivaTuner v2.24\RivaTunerWrapper.exe [2009-08-22 24576]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2011-01-18 8866120]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"=C:\Users\Roman\AppData\Local\Seznam.cz\postak.exe [2010-10-06 488728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray]
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [2009-06-24 272952]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe -automount []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2011-01-30 3054136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe [2010-05-04 311296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 112512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe /startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Roman\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-30 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
C:\Program Files\OO Software\Defrag\oodtray.exe [2009-09-12 3832064]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe [2010-12-21 1483264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-05-13 10810912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
C:\Program Files\Sandboxie\SbieCtrl.exe [2011-01-12 592616]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe [2011-01-28 526336]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler]
C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2008-04-04 120328]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-06-24 6806144]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2010-05-03 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"Wireless Console 3"=C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2010-07-02 1597440]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-10-29 249064]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-03-09 336384]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe [2005-07-15 479232]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
FancyStart daemon.lnk - C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe
SRS Premium Sound.lnk - C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\Windows\system32\guard64.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\Orbitdownloader\orbitdm.exe"="C:\Program Files (x86)\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit"
"C:\Program Files (x86)\Orbitdownloader\orbitnet.exe"="C:\Program Files (x86)\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit"
"C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 2 months======

2011-04-25 17:45:47 ----D---- C:\Program Files\trend micro
2011-04-25 17:45:46 ----D---- C:\rsit
2011-04-24 10:49:03 ----D---- C:\downloads
2011-04-23 19:09:52 ----D---- C:\Program Files (x86)\pdfforge Toolbar
2011-04-23 19:09:52 ----D---- C:\Program Files (x86)\Application Updater
2011-04-22 19:10:02 ----D---- C:\Program Files (x86)\Activision Value
2011-04-19 20:37:24 ----D---- C:\Users\Roman\AppData\Roaming\Opera
2011-04-19 20:37:19 ----D---- C:\Program Files (x86)\Opera
2011-04-14 18:45:19 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-04-14 18:45:19 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-04-14 18:45:10 ----A---- C:\Windows\system32\mfc42u.dll
2011-04-14 18:45:09 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2011-04-14 18:45:09 ----A---- C:\Windows\system32\mfc42.dll
2011-04-14 18:45:08 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2011-04-14 18:45:07 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-04-14 18:45:07 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-04-14 18:45:07 ----A---- C:\Windows\system32\drivers\srv.sys
2011-04-14 18:45:05 ----A---- C:\Windows\system32\win32k.sys
2011-04-14 18:45:04 ----A---- C:\Windows\system32\winresume.exe
2011-04-14 18:45:04 ----A---- C:\Windows\system32\winload.exe
2011-04-14 18:45:03 ----A---- C:\Windows\system32\kdusb.dll
2011-04-14 18:45:03 ----A---- C:\Windows\system32\kdcom.dll
2011-04-14 18:45:03 ----A---- C:\Windows\system32\kd1394.dll
2011-04-14 18:45:02 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2011-04-14 18:45:02 ----A---- C:\Windows\system32\dnsapi.dll
2011-04-14 18:45:01 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2011-04-14 18:45:01 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-04-14 18:45:01 ----A---- C:\Windows\system32\dnscacheugc.exe
2011-04-14 18:45:00 ----A---- C:\Windows\system32\FXSCOVER.exe
2011-04-14 18:44:59 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-04-14 18:44:59 ----A---- C:\Windows\system32\atmfd.dll
2011-04-14 18:44:58 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-04-14 18:44:58 ----A---- C:\Windows\system32\atmlib.dll
2011-04-14 18:44:56 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-04-14 18:44:56 ----A---- C:\Windows\system32\inetcomm.dll
2011-04-14 18:44:55 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-04-14 18:44:54 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-04-14 18:44:54 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-04-14 18:44:54 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-04-10 23:51:13 ----D---- C:\Users\Roman\AppData\Roaming\Gmail Notifier Plus
2011-04-06 09:57:45 ----A---- C:\Windows\SYSWOW64\msvcr71.dll
2011-04-06 09:57:45 ----A---- C:\Windows\SYSWOW64\msvcr70.dll
2011-04-06 09:57:45 ----A---- C:\Windows\SYSWOW64\msvcp71.dll
2011-04-06 09:57:26 ----D---- C:\Miranda Micro 1.5
2011-04-05 12:04:13 ----D---- C:\ProgramData\Spybot - Search & Destroy
2011-04-05 12:04:13 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy
2011-04-02 13:08:45 ----D---- C:\Program Files (x86)\Opera Mobile
2011-03-30 11:05:37 ----D---- C:\ProgramData\config
2011-03-30 11:04:58 ----D---- C:\qutIM JadrisPack
2011-03-29 20:52:34 ----D---- C:\ProgramData\ATI
2011-03-29 20:52:29 ----D---- C:\Program Files (x86)\AMD APP
2011-03-29 20:47:36 ----A---- C:\Windows\SYSWOW64\Oemdspif.dll
2011-03-29 20:47:36 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2011-03-29 20:47:36 ----A---- C:\Windows\SYSWOW64\atiumdmv.dll
2011-03-29 20:47:35 ----A---- C:\Windows\SYSWOW64\atipdlxx.dll
2011-03-29 20:47:35 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2011-03-29 20:47:35 ----A---- C:\Windows\system32\atiumd6v.dll
2011-03-29 20:47:35 ----A---- C:\Windows\system32\atitmm64.dll
2011-03-29 20:47:35 ----A---- C:\Windows\system32\ATIODE.exe
2011-03-29 20:47:35 ----A---- C:\Windows\system32\ATIODCLI.exe
2011-03-29 20:47:34 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2011-03-29 20:47:34 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2011-03-29 20:47:34 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2011-03-29 20:47:34 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2011-03-29 20:47:34 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2011-03-29 20:47:34 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2011-03-29 20:47:34 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2011-03-29 20:47:34 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2011-03-29 20:47:34 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2011-03-29 20:47:34 ----A---- C:\Windows\system32\atio6axx.dll
2011-03-29 20:47:34 ----A---- C:\Windows\system32\atimuixx.dll
2011-03-29 20:47:34 ----A---- C:\Windows\system32\atimpc64.dll
2011-03-29 20:47:34 ----A---- C:\Windows\system32\atiglpxx.dll
2011-03-29 20:47:34 ----A---- C:\Windows\system32\atig6txx.dll
2011-03-29 20:47:34 ----A---- C:\Windows\system32\atig6pxx.dll
2011-03-29 20:47:34 ----A---- C:\Windows\system32\atiesrxx.exe
2011-03-29 20:47:34 ----A---- C:\Windows\system32\atiedu64.dll
2011-03-29 20:47:34 ----A---- C:\Windows\system32\atieclxx.exe
2011-03-29 20:47:34 ----A---- C:\Windows\system32\aticalrt64.dll
2011-03-29 20:47:34 ----A---- C:\Windows\system32\amdpcom64.dll
2011-03-29 20:47:33 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2011-03-29 20:47:33 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2011-03-29 20:47:33 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2011-03-29 20:47:33 ----A---- C:\Windows\SYSWOW64\ati2edxx.dll
2011-03-29 20:47:33 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2011-03-29 20:47:33 ----A---- C:\Windows\system32\aticaldd64.dll
2011-03-29 20:47:33 ----A---- C:\Windows\system32\aticalcl64.dll
2011-03-29 20:47:33 ----A---- C:\Windows\system32\atiapfxx.exe
2011-03-28 18:19:58 ----D---- C:\Users\Roman\AppData\Roaming\IDM
2011-03-28 18:19:56 ----D---- C:\Users\Roman\AppData\Roaming\DMCache
2011-03-28 18:18:14 ----D---- C:\Program Files (x86)\Internet Download Manager
2011-03-28 18:06:33 ----A---- C:\Windows\SYSWOW64\EasyHook32.dll
2011-03-28 18:06:18 ----D---- C:\ProgramData\SpeedBit
2011-03-28 17:42:17 ----A---- C:\Windows\libem.INI
2011-03-28 17:42:01 ----D---- C:\Users\Roman\AppData\Roaming\BITS
2011-03-28 17:42:00 ----D---- C:\Users\Roman\AppData\Roaming\FlashGet
2011-03-28 17:41:55 ----D---- C:\Users\Roman\AppData\Roaming\FlashGetBHO
2011-03-28 17:41:53 ----D---- C:\Program Files (x86)\FlashGet Network
2011-03-28 17:15:20 ----D---- C:\Users\Roman\AppData\Roaming\Orbit
2011-03-28 17:15:20 ----D---- C:\Program Files (x86)\Orbitdownloader
2011-03-28 17:10:59 ----SHD---- C:\Config.Msi
2011-03-27 15:20:25 ----D---- C:\ProgramData\Real
2011-03-27 15:20:25 ----D---- C:\Program Files (x86)\Real
2011-03-27 15:20:17 ----D---- C:\Users\Roman\AppData\Roaming\Real
2011-03-25 17:04:41 ----A---- C:\wepkeys.txt
2011-03-25 14:53:02 ----D---- C:\ProgramData\TamoSoft
2011-03-25 14:52:53 ----D---- C:\Program Files (x86)\CommViewWiFi
2011-03-23 20:23:10 ----D---- C:\Program Files (x86)\DreamCom
2011-03-21 19:56:26 ----A---- C:\Windows\system32\OVDecode64.dll
2011-03-21 19:56:22 ----A---- C:\Windows\SYSWOW64\OVDecode.dll
2011-03-21 19:56:10 ----A---- C:\Windows\system32\OpenCL.dll
2011-03-21 19:56:06 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2011-03-21 19:55:58 ----A---- C:\Windows\system32\amdocl64.dll
2011-03-21 19:55:46 ----A---- C:\Windows\SYSWOW64\amdocl.dll
2011-03-20 16:21:46 ----A---- C:\Windows\SYSWOW64\msvcr90.dll
2011-03-18 22:07:47 ----D---- C:\Users\Roman\AppData\Roaming\skypePM
2011-03-18 22:06:59 ----D---- C:\Users\Roman\AppData\Roaming\Skype
2011-03-18 22:06:46 ----RD---- C:\Program Files (x86)\Skype
2011-03-18 22:06:35 ----D---- C:\ProgramData\Skype
2011-03-18 21:14:22 ----D---- C:\Users\Roman\AppData\Roaming\Trillian
2011-03-18 21:13:53 ----D---- C:\Program Files (x86)\Trillian
2011-03-18 20:51:48 ----D---- C:\qutIM
2011-03-18 20:50:49 ----D---- C:\Program Files (x86)\ICQ6Toolbar
2011-03-18 20:50:42 ----D---- C:\ProgramData\ICQ
2011-03-18 20:50:16 ----D---- C:\Users\Roman\AppData\Roaming\ICQ
2011-03-18 20:50:05 ----D---- C:\Program Files (x86)\ICQ7.4
2011-03-18 20:19:28 ----D---- C:\Users\Roman\AppData\Roaming\qutim
2011-03-18 09:12:51 ----D---- C:\Users\Roman\AppData\Roaming\Media Player Classic
2011-03-18 00:45:02 ----D---- C:\QIP Infium
2011-03-17 17:55:45 ----A---- C:\Windows\system32\drivers\idmwfp.sys
2011-03-16 23:08:14 ----D---- C:\Users\Roman\AppData\Roaming\Broad Intelligence
2011-03-16 23:08:11 ----D---- C:\Program Files\MediaCoder
2011-03-15 11:03:22 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-03-15 11:03:22 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-03-15 11:03:22 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2011-03-15 11:03:22 ----A---- C:\Windows\SYSWOW64\msls31.dll
2011-03-15 11:03:22 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-03-15 11:03:21 ----A---- C:\Windows\SYSWOW64\msrating.dll
2011-03-15 11:03:21 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-03-15 11:03:21 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-03-15 11:03:21 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-03-15 11:03:21 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-03-15 11:03:21 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-03-15 11:03:21 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-03-15 11:03:20 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2011-03-15 11:03:20 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2011-03-15 11:03:20 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-03-15 11:03:20 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2011-03-15 11:03:20 ----A---- C:\Windows\SYSWOW64\ieakeng.dll
2011-03-15 11:03:20 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2011-03-15 11:03:19 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-03-15 11:03:19 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2011-03-15 11:03:19 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2011-03-15 11:03:18 ----A---- C:\Windows\SYSWOW64\url.dll
2011-03-15 11:03:18 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-03-15 11:03:18 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2011-03-15 11:03:18 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2011-03-15 11:03:18 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-03-15 11:03:18 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2011-03-15 11:03:18 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2011-03-15 11:03:18 ----A---- C:\Windows\SYSWOW64\icardie.dll
2011-03-15 11:03:17 ----A---- C:\Windows\SYSWOW64\wextract.exe
2011-03-15 11:03:17 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2011-03-15 11:03:17 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-03-15 11:03:17 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-03-15 11:03:17 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-03-15 11:03:17 ----A---- C:\Windows\SYSWOW64\inseng.dll
2011-03-15 11:03:17 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2011-03-15 11:03:16 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2011-03-15 11:03:16 ----A---- C:\Windows\SYSWOW64\occache.dll
2011-03-15 11:03:16 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-03-15 11:03:16 ----A---- C:\Windows\SYSWOW64\mshta.exe
2011-03-15 11:03:16 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2011-03-15 11:03:15 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2011-03-15 11:03:15 ----A---- C:\Windows\SYSWOW64\ieakui.dll
2011-03-15 11:03:15 ----A---- C:\Windows\SYSWOW64\ieaksie.dll
2011-03-15 11:03:15 ----A---- C:\Windows\SYSWOW64\admparse.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\wininet.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\wextract.exe
2011-03-15 11:03:14 ----A---- C:\Windows\system32\webcheck.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\vbscript.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\urlmon.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\url.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-03-15 11:03:14 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-03-15 11:03:14 ----A---- C:\Windows\system32\pngfilt.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\occache.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\msrating.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\msls31.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\mshtmler.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\mshtmled.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\mshtml.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\mshta.exe
2011-03-15 11:03:14 ----A---- C:\Windows\system32\msfeedssync.exe
2011-03-15 11:03:14 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\msfeeds.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\licmgr10.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\jsproxy.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\jscript9.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\jscript.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\inseng.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\imgutil.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\iexpress.exe
2011-03-15 11:03:14 ----A---- C:\Windows\system32\ieUnatt.exe
2011-03-15 11:03:14 ----A---- C:\Windows\system32\ieui.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\iesysprep.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\iesetup.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\iertutil.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\iernonce.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\iepeers.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\ieframe.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\iedkcs32.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\ieapfltr.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\ieakui.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\ieaksie.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\ieakeng.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\IEAdvpack.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\ie4uinit.exe
2011-03-15 11:03:14 ----A---- C:\Windows\system32\icardie.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\dxtrans.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\dxtmsft.dll
2011-03-15 11:03:14 ----A---- C:\Windows\system32\admparse.dll
2011-03-13 17:50:31 ----D---- C:\Users\Roman\AppData\Roaming\Zoner
2011-03-13 17:50:07 ----D---- C:\Program Files (x86)\Zoner
2011-03-13 10:29:35 ----D---- C:\Windows\SYSWOW64\Wat
2011-03-13 10:29:35 ----D---- C:\Windows\system32\Wat
2011-03-12 12:04:20 ----D---- C:\Program Files (x86)\Pal Microsystems
2011-03-12 12:04:20 ----D---- C:\Program Files (x86)\Kerigwa
2011-03-12 12:04:20 ----D---- C:\PerfLogs
2011-03-12 12:04:19 ----D---- C:\ProgramData\AVAST Software
2011-03-12 12:04:19 ----AD---- C:\ProgramData\TEMP
2011-03-12 00:14:07 ----D---- C:\Users\Roman\AppData\Roaming\GlarySoft
2011-03-12 00:04:47 ----D---- C:\Program Files (x86)\Glary Utilities
2011-03-11 13:15:13 ----D---- C:\Program Files\7-Zip
2011-03-11 08:37:53 ----D---- C:\Users\Roman\AppData\Roaming\Funambol
2011-03-11 00:40:51 ----D---- C:\Users\Roman\AppData\Roaming\Maxthon3
2011-03-11 00:40:37 ----D---- C:\Program Files (x86)\Maxthon3
2011-03-10 09:21:36 ----A---- C:\Windows\system32\FntCache.dll
2011-03-10 09:21:35 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-03-10 09:21:35 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-03-10 09:21:35 ----A---- C:\Windows\system32\DWrite.dll
2011-03-10 09:21:35 ----A---- C:\Windows\system32\d2d1.dll
2011-03-09 20:37:41 ----A---- C:\Windows\system32\EncDec.dll
2011-03-09 20:37:41 ----A---- C:\Windows\system32\CPFilters.dll
2011-03-09 20:37:40 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-03-09 20:37:40 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-03-09 20:37:39 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-03-09 20:37:39 ----A---- C:\Windows\system32\sbe.dll
2011-03-08 16:08:22 ----D---- C:\Windows\pss
2011-03-08 15:04:28 ----HD---- C:\VritualRoot
2011-03-08 11:42:11 ----D---- C:\Program Files (x86)\Comodo
2011-03-06 21:34:34 ----D---- C:\totalcmd
2011-03-06 20:40:11 ----D---- C:\Program Files (x86)\Lonely Cat Games
2011-03-06 00:52:00 ----D---- C:\Windows\system32\Macromed
2011-03-05 21:34:37 ----D---- C:\Program Files (x86)\Feedback Tool
2011-03-05 18:45:09 ----D---- C:\ProgramData\Viper
2011-03-04 21:27:03 ----D---- C:\Program Files\COMODO
2011-03-04 21:27:02 ----A---- C:\Windows\SYSWOW64\mfc71.dll
2011-03-04 21:11:40 ----D---- C:\ProgramData\Comodo
2011-03-04 12:16:24 ----A---- C:\Windows\system32\aswBoot.exe
2011-03-04 12:15:17 ----D---- C:\Program Files\AVAST Software
2011-03-04 11:53:05 ----RD---- C:\Sandbox
2011-03-04 11:52:39 ----A---- C:\Windows\Sandboxie.ini
2011-03-04 11:52:33 ----D---- C:\Program Files\Sandboxie
2011-03-03 17:12:22 ----D---- C:\ProgramData\Trymedia
2011-03-03 14:29:26 ----D---- C:\Users\Roman\AppData\Roaming\TrueCrypt
2011-03-03 14:28:23 ----A---- C:\Windows\system32\drivers\truecrypt.sys
2011-03-03 14:27:51 ----D---- C:\Program Files\TrueCrypt
2011-03-03 14:11:17 ----D---- C:\Windows\Minidump
2011-03-01 15:33:57 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-03-01 15:33:57 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-03-01 15:33:57 ----A---- C:\Windows\SYSWOW64\java.exe
2011-03-01 15:32:26 ----D---- C:\ProgramData\McAfee
2011-03-01 13:20:22 ----D---- C:\Program Files\Recuva
2011-02-27 11:41:45 ----A---- C:\Windows\SYSWOW64\winver.exe
2011-02-27 11:41:45 ----A---- C:\Windows\SYSWOW64\user32.dll.old
2011-02-27 11:41:45 ----A---- C:\Windows\SYSWOW64\user32.dll
2011-02-27 11:41:45 ----A---- C:\Windows\SYSWOW64\systemcpl.dll
2011-02-27 11:41:45 ----A---- C:\Windows\SYSWOW64\slmgr.vbs
2011-02-26 20:49:36 ----D---- C:\Program Files (x86)\LitexMedia

======List of files/folders modified in the last 2 months======

2011-04-25 17:46:00 ----D---- C:\Windows\Prefetch
2011-04-25 17:45:47 ----RD---- C:\Program Files
2011-04-25 17:16:10 ----D---- C:\Windows\Temp
2011-04-25 17:15:10 ----D---- C:\Windows\system32\Tasks
2011-04-25 14:46:55 ----D---- C:\Windows\system32\config
2011-04-25 12:26:36 ----D---- C:\Windows\inf
2011-04-25 12:26:36 ----AD---- C:\Windows\System32
2011-04-25 12:26:36 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-04-24 23:00:03 ----D---- C:\Windows
2011-04-24 22:59:54 ----D---- C:\Program Files (x86)\Google
2011-04-24 22:59:53 ----RD---- C:\Program Files (x86)
2011-04-24 22:57:27 ----D---- C:\Users\Roman\AppData\Roaming\Winamp
2011-04-24 14:17:08 ----SHD---- C:\Windows\Installer
2011-04-24 14:16:52 ----SHD---- C:\System Volume Information
2011-04-24 10:53:14 ----D---- C:\Windows\SysWOW64
2011-04-23 20:15:25 ----A---- C:\Windows\system32\ServiceFilter.ini
2011-04-23 20:15:24 ----A---- C:\Windows\system32\AutoRunFilter.ini
2011-04-23 19:10:03 ----D---- C:\Windows\winsxs
2011-04-23 19:09:52 ----D---- C:\Program Files (x86)\Common Files
2011-04-22 15:56:52 ----D---- C:\Users\Roman\AppData\Roaming\uTorrent
2011-04-21 09:46:43 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-04-17 15:10:15 ----D---- C:\Users\Roman\AppData\Roaming\vlc
2011-04-15 22:57:08 ----D---- C:\Windows\debug
2011-04-15 19:48:25 ----D---- C:\Windows\Microsoft.NET
2011-04-15 19:48:23 ----RSD---- C:\Windows\assembly
2011-04-15 00:26:00 ----D---- C:\Windows\system32\drivers
2011-04-15 00:25:55 ----D---- C:\Windows\system32\Boot
2011-04-14 19:04:14 ----D---- C:\ProgramData\Microsoft Help
2011-04-14 19:02:57 ----D---- C:\Windows\system32\catroot
2011-04-14 18:56:18 ----A---- C:\Windows\system32\MRT.exe
2011-04-14 18:44:43 ----D---- C:\Windows\system32\catroot2
2011-04-10 23:42:12 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-04-08 14:27:42 ----D---- C:\Windows\system32\DriverStore
2011-04-06 09:57:45 ----RSD---- C:\Windows\Fonts
2011-04-05 12:04:13 ----HD---- C:\ProgramData
2011-04-04 14:49:35 ----D---- C:\Windows\system32\wdi
2011-04-02 20:18:31 ----D---- C:\Windows\SYSWOW64\directx
2011-04-02 12:46:49 ----D---- C:\QIP 2010
2011-03-31 13:10:09 ----SD---- C:\Users\Roman\AppData\Roaming\Microsoft
2011-03-29 21:00:30 ----D---- C:\Program Files (x86)\uTorrent
2011-03-29 20:51:54 ----D---- C:\Program Files\ATI Technologies
2011-03-28 17:13:29 ----D---- C:\Users\Roman\AppData\Roaming\_Orbit
2011-03-27 19:56:23 ----D---- C:\Program Files (x86)\K-Lite Codec Pack
2011-03-27 17:13:57 ----D---- C:\Users\Roman\AppData\Roaming\Mozilla
2011-03-25 14:41:09 ----D---- C:\ProgramData\TechSmith
2011-03-25 14:41:08 ----D---- C:\Program Files (x86)\TechSmith
2011-03-18 20:50:46 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-03-16 11:12:33 ----D---- C:\Users\Roman\AppData\Roaming\GHISLER
2011-03-15 22:18:28 ----D---- C:\Windows\rescache
2011-03-15 17:08:14 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-03-15 16:57:43 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-03-15 16:57:43 ----D---- C:\Program Files\Internet Explorer
2011-03-15 16:57:43 ----D---- C:\Program Files (x86)\Internet Explorer
2011-03-15 16:57:40 ----D---- C:\Windows\system32\cs-CZ
2011-03-15 16:57:38 ----D---- C:\Windows\SYSWOW64\migration
2011-03-15 16:57:35 ----D---- C:\Windows\SYSWOW64\en-US
2011-03-15 16:57:07 ----D---- C:\Windows\system32\migration
2011-03-15 16:57:07 ----D---- C:\Windows\PolicyDefinitions
2011-03-15 16:57:06 ----D---- C:\Windows\system32\en-US
2011-03-15 11:05:12 ----D---- C:\Windows\Logs
2011-03-13 10:28:37 ----D---- C:\Windows\SoftwareDistribution
2011-03-12 12:04:20 ----D---- C:\Program Files (x86)\GameSpy Arcade
2011-03-12 12:04:20 ----D---- C:\Program Files (x86)\Adobe
2011-03-12 12:04:19 ----SD---- C:\ProgramData\Microsoft
2011-03-12 12:04:19 ----D---- C:\ProgramData\PopCap Games
2011-03-12 12:04:19 ----D---- C:\ProgramData\PC Suite
2011-03-12 12:04:19 ----D---- C:\ProgramData\MumboJumbo
2011-03-12 12:04:19 ----D---- C:\ProgramData\Adobe
2011-03-12 12:04:19 ----D---- C:\Program Files\Windows Sidebar
2011-03-12 12:04:19 ----D---- C:\Program Files\Windows Media Player
2011-03-12 12:04:19 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-03-12 12:04:19 ----D---- C:\Program Files (x86)\Windows Media Player
2011-03-12 00:05:05 ----D---- C:\Windows\Tasks
2011-03-11 08:09:29 ----D---- C:\Program Files\WinRAR
2011-03-09 06:55:52 ----A---- C:\Windows\system32\aticfx64.dll
2011-03-09 06:53:44 ----A---- C:\Windows\system32\ATIDEMGX.dll
2011-03-09 06:51:48 ----A---- C:\Windows\system32\atipdl64.dll
2011-03-09 06:40:22 ----A---- C:\Windows\system32\atidxx64.dll
2011-03-09 06:30:30 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2011-03-09 06:24:48 ----A---- C:\Windows\system32\atiumd64.dll
2011-03-09 06:18:16 ----A---- C:\Windows\system32\atiadlxx.dll
2011-03-09 06:17:04 ----A---- C:\Windows\system32\atiuxp64.dll
2011-03-09 06:16:54 ----A---- C:\Windows\system32\atiu9p64.dll
2011-03-09 06:16:48 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2011-03-09 06:11:06 ----A---- C:\Windows\system32\coinst.dll
2011-03-09 05:41:52 ----A---- C:\Windows\system32\atiumd6a.dll
2011-03-09 05:34:12 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2011-03-08 19:03:41 ----D---- C:\Users\Roman\AppData\Roaming\Adobe
2011-03-08 11:21:42 ----D---- C:\Windows\system32\oodag
2011-03-06 18:53:01 ----D---- C:\Users\Roman\AppData\Roaming\Nokia
2011-03-04 20:16:34 ----D---- C:\Program Files\CCleaner
2011-03-04 13:45:08 ----D---- C:\Windows\system32\wbem
2011-03-04 13:44:29 ----D---- C:\Users\Roman\AppData\Roaming\IrfanView
2011-03-04 13:44:29 ----D---- C:\ProgramData\P4G
2011-03-04 13:44:28 ----D---- C:\Windows\registration
2011-03-04 13:39:42 ----D---- C:\Windows\system32\LogFiles
2011-03-04 10:04:34 ----D---- C:\Windows\ModemLogs
2011-03-03 14:10:01 ----D---- C:\Windows\LiveKernelReports
2011-03-01 15:33:43 ----D---- C:\Program Files (x86)\Java
2011-02-28 10:00:00 ----A---- C:\Windows\SYSWOW64\ff_vfw.dll
2011-02-27 11:41:22 ----A---- C:\Windows\system32\hale.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2011-01-30 35384]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 lullaby;lullaby; C:\Windows\system32\DRIVERS\lullaby.sys [2009-06-18 15928]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-01-30 503352]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2011-01-06 14184]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2011-01-06 250008]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2011-01-06 39888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2011-01-06 89840]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [2007-11-07 104912]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2011-03-03 230352]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 17464]
R2 IDMWFP;IDMWFP; C:\Windows\system32\DRIVERS\idmwfp.sys [2011-03-17 146568]
R3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-03-09 9258496]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-03-09 300544]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2010-03-02 1594368]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2010-11-17 115216]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2010-04-13 135560]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-05-13 2368160]
R3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2009-08-18 143472]
R3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits); C:\Windows\system32\DRIVERS\JME.sys [2010-02-25 115312]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928]
R3 RivaTuner64;RivaTuner64; \??\C:\Program Files (x86)\RivaTuner v2.24\RivaTuner64.sys [2011-01-30 19952]
R3 SbieDrv;SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys [2011-01-12 147048]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-08-20 1800192]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2008-01-24 22024]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2008-01-24 57352]
S1 ASPI32;ASPI32; C:\Windows\system32\drivers\ASPI32.sys []
S3 AODDriver4.0;AODDriver4.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys []
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-04-08 124944]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2010-11-20 552448]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2010-11-20 80384]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-01-15 98344]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2010-01-15 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-01-15 21288]
S3 ipswuio;ipswuio; C:\Windows\System32\DRIVERS\ipswuio.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2010-07-30 19456]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2010-07-30 26624]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TS_AR5416;[CommView] Atheros AR5008 Wireless Network Adapter Service 7.7; C:\Windows\system32\DRIVERS\ts_athwx.sys [2011-01-06 2156968]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2010-07-30 9216]
S3 usbser;USB Modem Driver; C:\Windows\system32\DRIVERS\usbser.sys [2010-11-20 32768]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-23 154168]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2008-01-24 32776]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2008-01-24 15752]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2010-06-22 379520]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-03-09 203776]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-03-09 365568]
R2 AMD Reservation Manager;AMD Reservation Manager; C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [2010-06-17 194496]
R2 Application Updater;Application Updater; C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe [2011-01-28 387072]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-15 84536]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-12-15 96896]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2010-03-11 873248]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2011-01-18 2466032]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 O&O Defrag;O&O Defrag; C:\Program Files\OO Software\Defrag\oodag.exe [2009-09-12 2287360]
R2 SbieSvc;Sandboxie Service; C:\Program Files\Sandboxie\SbieSvc.exe [2011-01-12 91368]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 ADSMService;ADSM Service; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-02-06 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2010-12-08 628736]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-03-13 1255736]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Totálně zasekaný notes

#2 Příspěvek od Rudy »

Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Roman47cz
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 23 srp 2006 17:12

Re: Totálně zasekaný notes

#3 Příspěvek od Roman47cz »

Zde to je, ale trvalo to více než půl hodiny.

ComboFix 11-04-24.06 - Roman 25.04.2011 18:04:22.1.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3070.1481 [GMT 2:00]
Spuštěný z: c:\users\Roman\Desktop\ComboFix.exe
AV: COMODO Antivirus *Disabled/Updated* {675CEE69-9702-A524-3989-6D7CC8BF3695}
FW: COMODO Firewall *Enabled* {5F676F4C-DD6D-A47C-12D6-C449366C71EE}
SP: COMODO Defense+ *Disabled/Updated* {DC3D0F8D-B138-AAAA-0339-560EB3387C28}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\ESET\MiNODLogin
c:\program files (x86)\ESET\MiNODLogin\MiNODLogin.exe
c:\program files (x86)\ESET\MiNODLogin\MiNODLogin.jar
c:\program files (x86)\ESET\MiNODLogin\MiNODLoginLib.dll
c:\program files (x86)\ESET\MiNODLogin\MiNODLoginUninst.exe
c:\program files (x86)\ESET\MiNODLogin\servidores.xml
c:\program files (x86)\pdfforge Toolbar\IE\4.3\pdFForgetoolbarie.dll
c:\programdata\Config
c:\programdata\Config\qutim\qutim.prednastaveny_profil\fmtune.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-03-25 do 2011-04-25 )))))))))))))))))))))))))))))))
.
.
2011-04-25 16:18 . 2011-04-25 16:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-25 15:45 . 2011-04-25 15:45 -------- d-----w- c:\program files\trend micro
2011-04-25 15:45 . 2011-04-25 15:46 -------- d-----w- C:\rsit
2011-04-24 11:38 . 2011-04-24 11:38 -------- d-----w- c:\users\Roman\AppData\Local\Weather forecast
2011-04-24 11:30 . 2011-04-24 11:30 -------- d-----w- c:\users\Roman\AppData\Local\eBook Reader
2011-04-24 08:49 . 2011-04-24 08:49 -------- d-----w- C:\downloads
2011-04-23 17:09 . 2011-04-23 17:09 -------- d-----w- c:\program files (x86)\Application Updater
2011-04-23 17:09 . 2011-04-23 17:09 -------- d-----w- c:\program files (x86)\pdfforge Toolbar
2011-04-23 17:09 . 2011-04-23 17:09 -------- d-----w- c:\program files (x86)\Common Files\Spigot
2011-04-22 17:10 . 2011-04-22 17:10 -------- d-----w- c:\program files (x86)\Activision Value
2011-04-21 19:09 . 2011-04-21 19:09 -------- d-----w- c:\users\Roman\AppData\Local\PlanetWerks
2011-04-21 19:06 . 2011-04-21 19:06 -------- d-----w- c:\users\Roman\AppData\Local\Artist's Sketchbook 1.65
2011-04-21 19:00 . 2011-04-21 19:00 -------- d-----w- c:\users\Roman\AppData\Local\Functions 3D
2011-04-21 18:51 . 2011-04-21 18:51 -------- d-----w- c:\users\Roman\AppData\Local\Airfield Mayhem
2011-04-20 08:44 . 2011-04-20 08:44 -------- d-----w- c:\users\Roman\AppData\Local\Seesu
2011-04-20 08:13 . 2011-04-20 08:13 -------- d-----w- c:\users\Roman\AppData\Local\Arkadion-X
2011-04-19 19:11 . 2011-04-19 19:11 -------- d-----w- c:\users\Roman\AppData\Local\Typing Speed Test
2011-04-19 19:06 . 2011-04-19 19:06 -------- d-----w- c:\users\Roman\AppData\Local\The Text mirror
2011-04-19 18:37 . 2011-04-24 11:37 -------- d-----w- c:\users\Roman\AppData\Local\Opera
2011-04-19 18:37 . 2011-04-19 18:37 -------- d-----w- c:\program files (x86)\Opera
2011-04-14 16:44 . 2011-02-19 09:00 367616 ----a-w- c:\windows\system32\atmfd.dll
2011-04-14 16:44 . 2011-02-19 04:34 294912 ----a-w- c:\windows\SysWow64\atmfd.dll
2011-04-14 16:44 . 2011-02-19 12:03 46080 ----a-w- c:\windows\system32\atmlib.dll
2011-04-14 16:44 . 2011-02-19 06:30 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2011-04-14 16:44 . 2011-03-08 06:29 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-14 16:44 . 2011-03-08 05:28 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-04-14 16:44 . 2011-02-23 04:56 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-14 16:44 . 2011-02-23 04:55 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-14 16:44 . 2011-02-23 04:55 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-14 16:44 . 2011-02-23 04:55 90624 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-04-10 21:51 . 2011-04-10 21:51 -------- d-----w- c:\users\Roman\AppData\Roaming\Gmail Notifier Plus
2011-04-06 07:57 . 2004-01-11 21:00 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2011-04-06 07:57 . 2003-03-19 00:14 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2011-04-06 07:57 . 2000-11-29 00:07 307200 ----a-w- c:\windows\SysWow64\msvcr70.dll
2011-04-06 07:57 . 2011-04-06 07:57 -------- d-----w- C:\Miranda Micro 1.5
2011-04-05 10:04 . 2011-04-24 19:00 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-04-05 10:04 . 2011-04-05 10:06 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2011-04-03 09:16 . 2011-04-03 09:16 -------- d-----w- c:\users\Roman\AppData\Local\Radek Chalupa
2011-04-02 11:08 . 2011-04-02 11:08 -------- d-----w- c:\program files (x86)\Opera Mobile
2011-03-30 09:04 . 2011-03-30 09:05 -------- d-----w- C:\qutIM JadrisPack
2011-03-29 19:19 . 2011-03-29 19:19 -------- d-----w- c:\users\Roman\AppData\Local\SKIDROW
2011-03-29 18:52 . 2011-03-29 18:52 -------- d-----w- c:\programdata\ATI
2011-03-29 18:52 . 2011-03-29 18:52 -------- d-----w- c:\program files (x86)\AMD APP
2011-03-28 16:19 . 2011-04-01 16:23 -------- d-----w- c:\users\Roman\AppData\Roaming\IDM
2011-03-28 16:19 . 2011-04-24 11:07 -------- d-----w- c:\users\Roman\AppData\Roaming\DMCache
2011-03-28 16:18 . 2011-03-28 16:43 -------- d-----w- c:\program files (x86)\Internet Download Manager
2011-03-28 16:06 . 2011-03-28 16:06 84480 ----a-w- c:\windows\SysWow64\EasyHook32.dll
2011-03-28 16:06 . 2011-03-28 16:16 -------- d-----w- c:\programdata\SpeedBit
2011-03-28 16:06 . 1998-12-05 11:18 172032 ----a-w- c:\windows\SysWow64\AniGIF.ocx
2011-03-28 15:42 . 2011-03-28 15:47 -------- d-----w- c:\users\Roman\AppData\Roaming\BITS
2011-03-28 15:42 . 2011-03-28 15:42 -------- d-----w- c:\users\Roman\AppData\Roaming\FlashGet
2011-03-28 15:41 . 2011-03-28 15:41 -------- d-----w- c:\program files (x86)\FlashGet Network
2011-03-28 15:15 . 2011-04-23 21:39 -------- d-----w- c:\users\Roman\AppData\Roaming\Orbit
2011-03-28 15:15 . 2011-03-28 15:15 -------- d-----w- c:\program files (x86)\Orbitdownloader
2011-03-27 13:20 . 2011-03-28 15:11 -------- d-----w- c:\program files (x86)\Real
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-21 17:56 . 2011-03-21 17:56 61952 ----a-w- c:\windows\system32\OVDecode64.dll
2011-03-21 17:56 . 2011-03-21 17:56 59904 ----a-w- c:\windows\SysWow64\OVDecode.dll
2011-03-21 17:56 . 2011-03-21 17:56 53760 ----a-w- c:\windows\system32\OpenCL.dll
2011-03-21 17:56 . 2011-03-21 17:56 51712 ----a-w- c:\windows\SysWow64\OpenCL.dll
2011-03-21 17:55 . 2011-03-21 17:55 16115712 ----a-w- c:\windows\system32\amdocl64.dll
2011-03-21 17:55 . 2011-03-21 17:55 12385792 ----a-w- c:\windows\SysWow64\amdocl.dll
2011-03-17 15:52 . 2011-03-17 15:55 146568 ----a-w- c:\windows\system32\drivers\idmwfp.sys
2011-03-15 09:03 . 2011-03-15 09:03 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-03-15 09:03 . 2011-03-15 09:03 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-03-15 09:03 . 2011-03-15 09:03 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-03-15 09:03 . 2011-03-15 09:03 1797632 ----a-w- c:\windows\SysWow64\jscript9.dll
2011-03-15 09:03 . 2011-03-15 09:03 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-03-15 09:03 . 2011-03-15 09:03 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-03-15 09:03 . 2011-03-15 09:03 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-03-15 09:03 . 2011-03-15 09:03 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-03-15 09:03 . 2011-03-15 09:03 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-03-15 09:03 . 2011-03-15 09:03 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-03-15 09:03 . 2011-03-15 09:03 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-03-15 09:03 . 2011-03-15 09:03 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-03-15 09:03 . 2011-03-15 09:03 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-03-15 09:03 . 2011-03-15 09:03 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-03-15 09:03 . 2011-03-15 09:03 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-03-15 09:03 . 2011-03-15 09:03 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-03-15 09:03 . 2011-03-15 09:03 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-03-15 09:03 . 2011-03-15 09:03 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-03-15 09:03 . 2011-03-15 09:03 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-03-15 09:03 . 2011-03-15 09:03 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-03-15 09:03 . 2011-03-15 09:03 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-03-15 09:03 . 2011-03-15 09:03 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-03-15 09:03 . 2011-03-15 09:03 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-03-15 09:03 . 2011-03-15 09:03 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-03-15 09:03 . 2011-03-15 09:03 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-03-15 09:03 . 2011-03-15 09:03 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-03-15 09:03 . 2011-03-15 09:03 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-03-15 09:03 . 2011-03-15 09:03 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-03-15 09:03 . 2011-03-15 09:03 448512 ----a-w- c:\windows\system32\html.iec
2011-03-15 09:03 . 2011-03-15 09:03 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-03-15 09:03 . 2011-03-15 09:03 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-03-15 09:03 . 2011-03-15 09:03 2303488 ----a-w- c:\windows\system32\jscript9.dll
2011-03-15 09:03 . 2011-03-15 09:03 222208 ----a-w- c:\windows\system32\msls31.dll
2011-03-15 09:03 . 2011-03-15 09:03 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-03-15 09:03 . 2011-03-15 09:03 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-03-15 09:03 . 2011-03-15 09:03 160256 ----a-w- c:\windows\system32\wextract.exe
2011-03-15 09:03 . 2011-03-15 09:03 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-03-15 09:03 . 2011-03-15 09:03 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-03-15 09:03 . 2011-03-15 09:03 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-03-15 09:03 . 2011-03-15 09:03 12288 ----a-w- c:\windows\system32\mshta.exe
2011-03-15 09:03 . 2011-03-15 09:03 114176 ----a-w- c:\windows\system32\admparse.dll
2011-03-15 09:03 . 2011-03-15 09:03 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-03-09 04:55 . 2010-04-06 14:15 795136 ----a-w- c:\windows\system32\aticfx64.dll
2011-03-09 04:53 . 2011-01-30 09:04 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-03-09 04:51 . 2010-04-06 14:10 423424 ----a-w- c:\windows\system32\atipdl64.dll
2011-03-09 04:40 . 2010-04-06 13:54 5044224 ----a-w- c:\windows\system32\atidxx64.dll
2011-03-09 04:30 . 2010-04-06 13:40 4294656 ----a-w- c:\windows\SysWow64\atiumdag.dll
2011-03-09 04:24 . 2010-04-06 13:32 5438976 ----a-w- c:\windows\system32\atiumd64.dll
2011-03-09 04:18 . 2011-01-26 22:14 360448 ----a-w- c:\windows\system32\atiadlxx.dll
2011-03-09 04:17 . 2010-04-06 13:22 39936 ----a-w- c:\windows\system32\atiuxp64.dll
2011-03-09 04:16 . 2010-04-06 13:22 38400 ----a-w- c:\windows\system32\atiu9p64.dll
2011-03-09 04:16 . 2010-04-06 13:22 28672 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2011-03-09 04:11 . 2011-01-30 09:04 58880 ----a-w- c:\windows\system32\coinst.dll
2011-03-09 03:41 . 2010-04-06 13:27 3239936 ----a-w- c:\windows\system32\atiumd6a.dll
2011-03-09 03:34 . 2010-04-06 13:21 3471872 ----a-w- c:\windows\SysWow64\atiumdva.dll
2011-03-04 19:27 . 2011-03-04 19:27 1060864 ----a-w- c:\windows\SysWow64\mfc71.dll
2011-03-03 12:28 . 2011-03-03 12:28 230352 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2011-02-28 08:00 . 2011-02-22 10:34 80896 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2011-02-27 09:41 . 2011-02-27 09:41 79872 ----a-w- c:\windows\SysWow64\winver.exe
2011-02-27 09:41 . 2011-02-27 09:41 833024 ----a-w- c:\windows\SysWow64\user32.dll.old
2011-02-27 09:41 . 2011-02-27 09:41 410624 ----a-w- c:\windows\SysWow64\systemcpl.dll
2011-02-27 09:41 . 2011-02-11 16:29 2169856 ----a-w- c:\windows\system32\hale.exe
2011-02-23 20:27 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-02-23 20:27 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-02-23 15:04 . 2011-03-04 10:16 238968 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-19 12:05 . 2011-03-10 07:21 1139200 ----a-w- c:\windows\system32\FntCache.dll
2011-02-19 12:04 . 2011-03-10 07:21 1544192 ----a-w- c:\windows\system32\DWrite.dll
2011-02-19 12:04 . 2011-03-10 07:21 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-02-19 06:30 . 2011-03-10 07:21 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-02-19 06:30 . 2011-03-10 07:21 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-02-11 07:30 . 2011-03-08 08:13 7947600 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8E164A40-0E55-405B-8D7F-D7CD205F7FF8}\mpengine.dll
2011-02-09 15:45 . 2011-02-09 15:45 419840 ----a-w- c:\windows\system32\wrap_oal.dll
2011-02-09 15:45 . 2011-02-09 15:45 413696 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2011-02-09 15:45 . 2011-02-09 15:45 133632 ----a-w- c:\windows\system32\OpenAL32.dll
2011-02-09 15:45 . 2011-02-09 15:45 110592 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2011-02-02 20:40 . 2011-01-30 12:16 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-02-02 16:11 . 2011-01-30 09:44 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-02-02 15:25 . 2011-02-02 15:25 49152 ----a-r- c:\users\Roman\AppData\Roaming\Microsoft\Installer\{C37A0BC1-52EE-4F97-8223-5CA9FC0357B0}\ARPPRODUCTICON.exe
2011-01-30 18:29 . 2009-08-18 11:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2011-01-30 18:29 . 2009-08-18 10:24 17816 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-01-30 09:24 . 2011-01-30 09:24 520192 ----a-w- c:\windows\SysWow64\K_Series_ScreenSaver_EN.scr
2011-01-30 09:24 . 2011-01-30 09:24 3054136 ----a-w- c:\windows\AsScrPro.exe
2011-01-30 09:22 . 2011-01-30 09:22 35384 ----a-w- c:\windows\system32\drivers\AsDsm.sys
2011-01-30 08:58 . 2011-02-27 09:41 833024 ----a-w- c:\windows\SysWow64\user32.dll
2011-01-30 08:58 . 2011-02-27 09:41 113543 ----a-w- c:\windows\SysWow64\slmgr.vbs
2009-04-08 09:31 . 2009-04-08 09:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-11 20:45 . 2008-08-11 20:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
------- Sigcheck -------
.
[7] 2010-11-20 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2009-07-14 . E573BD9AB55C8E333C202B9E255F972E . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
[-] 2011-01-30 . 2C9CC9F492CA596B1B9FC1AE5E916356 . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-20 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-12-09 11:51 3911776 ----a-w- c:\program files (x86)\uTorrentBar\tbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 16:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"="c:\users\Roman\AppData\Local\Seznam.cz\postak.exe" [2010-10-06 488728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-06-24 6806144]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-05-03 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-07-02 1597440]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 932288]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-08 336384]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files (x86)\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2011-1-30 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2011-1-30 156952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\guard32.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-06 136176]
R3 AODDriver4.0;AODDriver4.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 TS_AR5416;[CommView] Atheros AR5008 Wireless Network Adapter Service 7.7;c:\windows\system32\DRIVERS\ts_athwx.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys [x]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [x]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-03-08 365568]
S2 AMD Reservation Manager;AMD Reservation Manager;c:\program files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [2010-06-17 194496]
S2 Application Updater;Application Updater;c:\program files (x86)\Application Updater\ApplicationUpdater.exe [2011-01-28 387072]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys [x]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24\RivaTuner64.sys [2011-01-30 19952]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}]
2010-11-20 12:17 302592 ----a-w- c:\windows\System32\cmd.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-04-25 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2011-03-11 16:24]
.
2011-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-06 18:03]
.
2011-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-06 18:03]
.
2011-04-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3496903114-3669578777-545992414-1000Core.job
- c:\users\Roman\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-30 11:48]
.
2011-04-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3496903114-3669578777-545992414-1000UA.job
- c:\users\Roman\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-30 11:48]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 15:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2011-03-02 16:23 85232 ----a-w- c:\program files (x86)\Internet Download Manager\IDMShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RivaTunerStartupDaemon"="c:\program files (x86)\RivaTuner v2.24\RivaTunerWrapper.exe" [2009-08-22 24576]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-01-17 8866120]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\guard64.dll
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://start.icq.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: &Download by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/204
IE: ????3??
IE: ????3??????
IE: Do&wnload selected by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/202
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Stáhnout s IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm
IE: Stáhnout s IDM obsah FLV videa - c:\program files (x86)\Internet Download Manager\IEGetVL.htm
IE: Stáhnout s IDM všechny odkazy - c:\program files (x86)\Internet Download Manager\IEGetAll.htm
IE: ????3?? - c:\users\Roman\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - c:\users\Roman\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files (x86)\ICQ7.4\ICQ.exe
FF - ProfilePath - c:\users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\dnh4ogxv.default\
FF - prefs.js: browser.startup.homepage - chrome://speeddial/content/speeddial.xul
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=827316&p=
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{FF6C3CF0-4B15-11D1-ABED-709549C10000} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-ETDWare - %ProgramFiles%\Elantech\ETDCtrl.exe
AddRemove-K_Series_ScreenSaver_EN - c:\windows\system32\K_Series_ScreenSaver_EN.scr
AddRemove-MiNODLogin - c:\program files (x86)\ESET\MiNODLogin\MiNODLoginUninst.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3496903114-3669578777-545992414-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}Ź]
@="c:\\Users\\Roman\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-3496903114-3669578777-545992414-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}ŹhQčţ”Ąc]
@="c:\\Users\\Roman\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_10_3_162_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_10_3_162_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG14.00.00.01PROFESSIONAL"="B1640E30FEFED3C87830A6D606FE7C2502E7ECEB7505639EB475D779DB46C3FADA9E956D7AF628262020BC14BCD15859109E83EC4C6CE11832DF89C6B0D625732E57B2B2F796FBA4820312C678E86A77FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98089DB7CE019D40AA5CBA7FD869164D6794C038D530D6EB3452AB8E05A277B4B958FC3CBED359F17D279C9F75836B6F9DDB29BF805E9C052707C49EA159CBC8C56ED10D73F9874D776DB9DBDED95F394EB03FDAAD91BEAC463F6B1F1CE55CF22254FBA30BC83B8B6482F0B534A6B6764B339F2E790C1D62E6E75984BA13E99A3E5A2322C6A1F54F7CDD7D18CE81D0A6B39D331575B81BA2B5214CB4683EF2D7EE26781C0AF8F76F5CC99E652B93537C1081EC5CD8155C1EBF5F858CB45C41F8E8B12D995C57CA77846598F16A17276048C0C146FCB3C9B9F6EB4BD7D074DC7FC9CB7716E95737A45A2334865261F5ED2994290ADF3A910DB3E366DC9421939F8F14140282ABCE6924493B6149D53273650821CE23E325E5AE3825D1FA13F8C39F02BEC09996636D0F73FEB25E6D0E75917BA9B68D7FB8C207ACD960A30CE20ABEDE3CABC7718B8A2D105120C2B583ABA72146CF876CC55BBE5AD829CFE36A431BC8D20EC828244E70E28BC049504E01848280231F240915BC2FFC3FE7866F744231CDA87D3A4B7D338109A36D726D16E9FA66A887AF840ECA6AA2A7757212D8275E7A2D673EE30D315628494A65A53CFD3A064F96ACFC9697A0AC5F29BA3ADBA2E82B46AFD916A789224E2720857FFDC844F679444E7BB2B6BC8055D40811A1EFBFB78FA3CACB2C437561A556C5471437F04EFC31DA4C1C9CF907EA6F1405FC2E24FA17B061352DC438CE21F32A0CEF9DEA2CA29C2C03BD24E82E79132FC8795F2CD2E2EC81C470DA24846CA64CA334ADB22FAA6E31F1390DEEE7C900BBD153ECC0A26B0F2332F0364A774BBED82438049C7C4530EAB463F7C42A1D98315AFCA1A1CF1A72D3F85EEA0B9E76B1136B881BCFBC190E702644ECF66DA4E31C609B2E5E465198B1D619711FF59B18CD1A6357481DBF5C6C699755E5B0088C1A278823DD73E3A4F2503AA60F7DDBAEF3123DFA554DC88F1DE24FFE487462625F33D079D9CB1B5E5EAB0A4BBB384CD6027DBCB21B82354254BA0F9DA4BFC2D633CF370C5FC4B13152F40802572EF5150AC6BE8991F4F932F7DF2FC7589B2C01F00AB01CD1D8582EBCF9E554E76AD412319FD272846203C08203BD761515159C86B566CA65873208A44F8BAFC97DDA9C2F7B3A41930B2D7404187809DDBDE9097868B62024D2D8979FCB92622AF9EDA2D292EEB032B24A769BD957C10E2C0947DDFA3288EC41D659D90A49A20B78E4BBFCE01B5D2922A19682447F4750"
"OODEFRAG12.00.00.01PROFESSIONAL"="906A1593EF1855F08A7EF9759ED64A3ED07D07B58BEB5E5B80440084AA596A177C33A6E09CEB7810D001CD79FC566B9EE39F232AF8DE84D6FE2E6478C014B0132079D1B5431DAA97218FF29CB7116B3EA763BA8B7F626CB2707CE2CA4A58B2C65C3E2FDF9D1C354AD8B46C7C974F0AFE17FAD1EA11BA68150BAC25FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98089DB7CE019D40AA5CBA7FD869164D6794C038D530D6EB34526DA132BCD9302245426386532DFEBE16EA45B5F51145904E64EE7EDA1E992C21B768BFDB4598DF2AF5BD2AFDCF70A121B969F13EE8AA12CA418C9F35405E0D431002668138195198AC34131022A63031605182A60DA9CD8492BE2EC8297AF5222B6D46E4ADDF008F8B73DCD3DE913E6996769C309A0B03E2416A99ECF235AF89C11FA750E2D4DCDE3E1BC5AA87530641964518EE71D0D1A43B6AF20C818BE21B13FCF4A4DA90B8ADF23EB3095C42A18220A0F20D34AE41D6EE0CEF2478AE1F4B5FE23D545BE04C75DB662E7766E992CA795C4D48CB0A395FD211EA47C08256636D1F34E66E473303AF0FE090F008BC1066C1EC7166808774DDAFE01B081FDEFE8674AE78E2F86DF9A9271B070B8F6A16358DB96DF0DFDCA28E13745B4052738EF71AA8364AE0DCCE0993519C8625457AB570C03722AD5048E4D7EB561D9BB1D813BB4265F999C9CB8EAD9B2BFA26DEA9BA10B459F020D99BE411306B982F9CF52EF7BB5C8D77608E033FB61F4420ACE69B85677719A2D72217444F946FF59AD12361FE86E27FAE092F89007781D386C8B35D54C59BD40CB8096BFCDA238DF5AD4F0094629B692800E2C0FC4A953AA6BBE319960DBC0B1A8F4BF38C5B7945DC1E944EAC859EA4250F718CD6BDA77C317C8FACF02C04CB8C2AF1C1F8497AA1628B58BA1A9416D1E0A22F09568F22F9A71F1D0347133D5450DE9629616BF25CFCB4042AD24CEEC7F9FC78456E10B5C4F30AF978A2477A11385C55F3069B76608528057072FBDB8EF4342C47B0A354A2E1F794DC2EE20D28771F4D62CCC7D650BCCB4E5CB88653E3B630AB05D6C0B51022F66176BD9210F0297D2624C0F1307DC258542A076310B90F325F6C3C76D5B848EBD67DC417DD75491E86DF0F31DC739F5A110EE41D0FB5A9C82F5C60E2F103CD8BF1A05CC696F63BFB1CAF09AF016DBCB2822F7DD413B01BDA0DA866BA8E818E61B2FD420A1F68426916A226AB005C6995A9A81FBB22B9DAA2699A18467101CA4C9A2ED5DE9FEF8987AAB9FE778264578C0D873E198610442D3BEC60E2A77F28FD33B61CD583EA9D4F116B527877DD1DF33651EECACEAB975D7E50CE7FFE2F2D7F8797BE147BE7EF8C07A181A90F5634FCB1FC6EBDCBB376E7AFE718228BF7C6A927BF0B537B"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-04-25 18:41:57
ComboFix-quarantined-files.txt 2011-04-25 16:41
.
Před spuštěním: Volných bajtů: 24 220 278 784
Po spuštění: Volných bajtů: 23 861 645 312
.
- - End Of File - - 67C4D54FC8002EC508D2F5AB0DF60E33

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Totálně zasekaný notes

#4 Příspěvek od Rudy »

Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
Folder::
c:\program files (x86)\pdfforge Toolbar
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkaz ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Roman47cz
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 23 srp 2006 17:12

Re: Totálně zasekaný notes

#5 Příspěvek od Roman47cz »

Provedeno

ComboFix 11-04-24.06 - Roman 25.04.2011 19:35:11.2.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3070.1518 [GMT 2:00]
Spuštěný z: c:\users\Roman\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Roman\Desktop\CFScript.txt
AV: COMODO Antivirus *Disabled/Updated* {675CEE69-9702-A524-3989-6D7CC8BF3695}
FW: COMODO Firewall *Enabled* {5F676F4C-DD6D-A47C-12D6-C449366C71EE}
SP: COMODO Defense+ *Disabled/Updated* {DC3D0F8D-B138-AAAA-0339-560EB3387C28}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\pdfforge Toolbar
c:\program files (x86)\pdfforge Toolbar\FF\chrome.manifest
c:\program files (x86)\pdfforge Toolbar\FF\chrome\content\chevron.js
c:\program files (x86)\pdfforge Toolbar\FF\chrome\content\chevron.xul
c:\program files (x86)\pdfforge Toolbar\FF\chrome\content\login.js
c:\program files (x86)\pdfforge Toolbar\FF\chrome\content\login.xul
c:\program files (x86)\pdfforge Toolbar\FF\chrome\content\parser.js
c:\program files (x86)\pdfforge Toolbar\FF\chrome\content\RssTickerWidget.js
c:\program files (x86)\pdfforge Toolbar\FF\chrome\content\searchbox.js
c:\program files (x86)\pdfforge Toolbar\FF\chrome\content\searchbox.xul
c:\program files (x86)\pdfforge Toolbar\FF\chrome\content\utils.js
c:\program files (x86)\pdfforge Toolbar\FF\chrome\content\widgicomm.js
c:\program files (x86)\pdfforge Toolbar\FF\chrome\content\widgihandling.js
c:\program files (x86)\pdfforge Toolbar\FF\chrome\content\widgichevron.js
c:\program files (x86)\pdfforge Toolbar\FF\chrome\content\widgilisteners.js
c:\program files (x86)\pdfforge Toolbar\FF\chrome\content\widgitoolbarplugin.js
c:\program files (x86)\pdfforge Toolbar\FF\chrome\content\widgitoolbarplugin.xul
c:\program files (x86)\pdfforge Toolbar\FF\chrome\content\widgiui.js
c:\program files (x86)\pdfforge Toolbar\FF\chrome\locale\EN-US\searchbox.dtd
c:\program files (x86)\pdfforge Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.dtd
c:\program files (x86)\pdfforge Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.properties
c:\program files (x86)\pdfforge Toolbar\FF\chrome\locale\EN-US\yahoo-search.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\amazon.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\ebay.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\chevron.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\icon_settings.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\pdfc_branding.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\pdfc_branding_hover.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\pdfc_icon.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\pdfc_portal_logo.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\search-button-hover.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\search-button.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\search-chevron-hover.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\search-chevron.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\search_amazon.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\search_ebay.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\search_yahoo.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\searchbox.css
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\splitter.gif
c:\program files (x86)\pdfforge Toolbar\FF\chrome\skin\widgitoolbarplugin.css
c:\program files (x86)\pdfforge Toolbar\FF\install.rdf
c:\program files (x86)\pdfforge Toolbar\IE\4.3\config.ini
c:\program files (x86)\pdfforge Toolbar\Res\amazon.gif
c:\program files (x86)\pdfforge Toolbar\Res\ebay.gif
c:\program files (x86)\pdfforge Toolbar\Res\icon_settings.gif
c:\program files (x86)\pdfforge Toolbar\Res\pdfc_branding.gif
c:\program files (x86)\pdfforge Toolbar\Res\pdfc_branding_hover.gif
c:\program files (x86)\pdfforge Toolbar\Res\pdfc_icon.gif
c:\program files (x86)\pdfforge Toolbar\Res\pdfc_portal_logo.gif
c:\program files (x86)\pdfforge Toolbar\Res\search-button-hover.gif
c:\program files (x86)\pdfforge Toolbar\Res\search-button.gif
c:\program files (x86)\pdfforge Toolbar\Res\search-chevron-hover.gif
c:\program files (x86)\pdfforge Toolbar\Res\search-chevron.gif
c:\program files (x86)\pdfforge Toolbar\Res\search_amazon.gif
c:\program files (x86)\pdfforge Toolbar\Res\search_ebay.gif
c:\program files (x86)\pdfforge Toolbar\Res\search_yahoo.gif
c:\program files (x86)\pdfforge Toolbar\Res\widgets.xml
c:\program files (x86)\pdfforge Toolbar\WidgiHelper.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-03-25 do 2011-04-25 )))))))))))))))))))))))))))))))
.
.
2011-04-25 17:43 . 2011-04-25 17:43 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-25 15:45 . 2011-04-25 15:45 -------- d-----w- c:\program files\trend micro
2011-04-25 15:45 . 2011-04-25 15:46 -------- d-----w- C:\rsit
2011-04-24 11:38 . 2011-04-24 11:38 -------- d-----w- c:\users\Roman\AppData\Local\Weather forecast
2011-04-24 11:30 . 2011-04-24 11:30 -------- d-----w- c:\users\Roman\AppData\Local\eBook Reader
2011-04-24 08:49 . 2011-04-24 08:49 -------- d-----w- C:\downloads
2011-04-23 17:09 . 2011-04-23 17:09 -------- d-----w- c:\program files (x86)\Application Updater
2011-04-23 17:09 . 2011-04-23 17:09 -------- d-----w- c:\program files (x86)\Common Files\Spigot
2011-04-22 17:10 . 2011-04-22 17:10 -------- d-----w- c:\program files (x86)\Activision Value
2011-04-21 19:09 . 2011-04-21 19:09 -------- d-----w- c:\users\Roman\AppData\Local\PlanetWerks
2011-04-21 19:06 . 2011-04-21 19:06 -------- d-----w- c:\users\Roman\AppData\Local\Artist's Sketchbook 1.65
2011-04-21 19:00 . 2011-04-21 19:00 -------- d-----w- c:\users\Roman\AppData\Local\Functions 3D
2011-04-21 18:51 . 2011-04-21 18:51 -------- d-----w- c:\users\Roman\AppData\Local\Airfield Mayhem
2011-04-20 08:44 . 2011-04-20 08:44 -------- d-----w- c:\users\Roman\AppData\Local\Seesu
2011-04-20 08:13 . 2011-04-20 08:13 -------- d-----w- c:\users\Roman\AppData\Local\Arkadion-X
2011-04-19 19:11 . 2011-04-19 19:11 -------- d-----w- c:\users\Roman\AppData\Local\Typing Speed Test
2011-04-19 19:06 . 2011-04-19 19:06 -------- d-----w- c:\users\Roman\AppData\Local\The Text mirror
2011-04-19 18:37 . 2011-04-24 11:37 -------- d-----w- c:\users\Roman\AppData\Local\Opera
2011-04-19 18:37 . 2011-04-19 18:37 -------- d-----w- c:\program files (x86)\Opera
2011-04-14 16:44 . 2011-02-19 09:00 367616 ----a-w- c:\windows\system32\atmfd.dll
2011-04-14 16:44 . 2011-02-19 04:34 294912 ----a-w- c:\windows\SysWow64\atmfd.dll
2011-04-14 16:44 . 2011-02-19 12:03 46080 ----a-w- c:\windows\system32\atmlib.dll
2011-04-14 16:44 . 2011-02-19 06:30 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2011-04-14 16:44 . 2011-03-08 06:29 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-14 16:44 . 2011-03-08 05:28 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-04-14 16:44 . 2011-02-23 04:56 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-14 16:44 . 2011-02-23 04:55 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-14 16:44 . 2011-02-23 04:55 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-14 16:44 . 2011-02-23 04:55 90624 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-04-10 21:51 . 2011-04-10 21:51 -------- d-----w- c:\users\Roman\AppData\Roaming\Gmail Notifier Plus
2011-04-06 07:57 . 2004-01-11 21:00 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll
2011-04-06 07:57 . 2003-03-19 00:14 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll
2011-04-06 07:57 . 2000-11-29 00:07 307200 ----a-w- c:\windows\SysWow64\msvcr70.dll
2011-04-06 07:57 . 2011-04-06 07:57 -------- d-----w- C:\Miranda Micro 1.5
2011-04-05 10:04 . 2011-04-24 19:00 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-04-05 10:04 . 2011-04-05 10:06 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2011-04-03 09:16 . 2011-04-03 09:16 -------- d-----w- c:\users\Roman\AppData\Local\Radek Chalupa
2011-04-02 11:08 . 2011-04-02 11:08 -------- d-----w- c:\program files (x86)\Opera Mobile
2011-03-30 09:04 . 2011-03-30 09:05 -------- d-----w- C:\qutIM JadrisPack
2011-03-29 19:19 . 2011-03-29 19:19 -------- d-----w- c:\users\Roman\AppData\Local\SKIDROW
2011-03-29 18:52 . 2011-03-29 18:52 -------- d-----w- c:\programdata\ATI
2011-03-29 18:52 . 2011-03-29 18:52 -------- d-----w- c:\program files (x86)\AMD APP
2011-03-28 16:19 . 2011-04-01 16:23 -------- d-----w- c:\users\Roman\AppData\Roaming\IDM
2011-03-28 16:19 . 2011-04-24 11:07 -------- d-----w- c:\users\Roman\AppData\Roaming\DMCache
2011-03-28 16:18 . 2011-03-28 16:43 -------- d-----w- c:\program files (x86)\Internet Download Manager
2011-03-28 16:06 . 2011-03-28 16:06 84480 ----a-w- c:\windows\SysWow64\EasyHook32.dll
2011-03-28 16:06 . 2011-03-28 16:16 -------- d-----w- c:\programdata\SpeedBit
2011-03-28 16:06 . 1998-12-05 11:18 172032 ----a-w- c:\windows\SysWow64\AniGIF.ocx
2011-03-28 15:42 . 2011-03-28 15:47 -------- d-----w- c:\users\Roman\AppData\Roaming\BITS
2011-03-28 15:42 . 2011-03-28 15:42 -------- d-----w- c:\users\Roman\AppData\Roaming\FlashGet
2011-03-28 15:41 . 2011-03-28 15:41 -------- d-----w- c:\program files (x86)\FlashGet Network
2011-03-28 15:15 . 2011-04-23 21:39 -------- d-----w- c:\users\Roman\AppData\Roaming\Orbit
2011-03-28 15:15 . 2011-03-28 15:15 -------- d-----w- c:\program files (x86)\Orbitdownloader
2011-03-27 13:20 . 2011-03-28 15:11 -------- d-----w- c:\program files (x86)\Real
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-21 17:56 . 2011-03-21 17:56 61952 ----a-w- c:\windows\system32\OVDecode64.dll
2011-03-21 17:56 . 2011-03-21 17:56 59904 ----a-w- c:\windows\SysWow64\OVDecode.dll
2011-03-21 17:56 . 2011-03-21 17:56 53760 ----a-w- c:\windows\system32\OpenCL.dll
2011-03-21 17:56 . 2011-03-21 17:56 51712 ----a-w- c:\windows\SysWow64\OpenCL.dll
2011-03-21 17:55 . 2011-03-21 17:55 16115712 ----a-w- c:\windows\system32\amdocl64.dll
2011-03-21 17:55 . 2011-03-21 17:55 12385792 ----a-w- c:\windows\SysWow64\amdocl.dll
2011-03-17 15:52 . 2011-03-17 15:55 146568 ----a-w- c:\windows\system32\drivers\idmwfp.sys
2011-03-15 09:03 . 2011-03-15 09:03 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-03-15 09:03 . 2011-03-15 09:03 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-03-15 09:03 . 2011-03-15 09:03 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-03-15 09:03 . 2011-03-15 09:03 1797632 ----a-w- c:\windows\SysWow64\jscript9.dll
2011-03-15 09:03 . 2011-03-15 09:03 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-03-15 09:03 . 2011-03-15 09:03 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-03-15 09:03 . 2011-03-15 09:03 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-03-15 09:03 . 2011-03-15 09:03 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-03-15 09:03 . 2011-03-15 09:03 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-03-15 09:03 . 2011-03-15 09:03 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-03-15 09:03 . 2011-03-15 09:03 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-03-15 09:03 . 2011-03-15 09:03 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-03-15 09:03 . 2011-03-15 09:03 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-03-15 09:03 . 2011-03-15 09:03 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-03-15 09:03 . 2011-03-15 09:03 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-03-15 09:03 . 2011-03-15 09:03 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-03-15 09:03 . 2011-03-15 09:03 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-03-15 09:03 . 2011-03-15 09:03 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-03-15 09:03 . 2011-03-15 09:03 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-03-15 09:03 . 2011-03-15 09:03 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-03-15 09:03 . 2011-03-15 09:03 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-03-15 09:03 . 2011-03-15 09:03 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-03-15 09:03 . 2011-03-15 09:03 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-03-15 09:03 . 2011-03-15 09:03 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-03-15 09:03 . 2011-03-15 09:03 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-03-15 09:03 . 2011-03-15 09:03 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-03-15 09:03 . 2011-03-15 09:03 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-03-15 09:03 . 2011-03-15 09:03 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-03-15 09:03 . 2011-03-15 09:03 448512 ----a-w- c:\windows\system32\html.iec
2011-03-15 09:03 . 2011-03-15 09:03 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-03-15 09:03 . 2011-03-15 09:03 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-03-15 09:03 . 2011-03-15 09:03 2303488 ----a-w- c:\windows\system32\jscript9.dll
2011-03-15 09:03 . 2011-03-15 09:03 222208 ----a-w- c:\windows\system32\msls31.dll
2011-03-15 09:03 . 2011-03-15 09:03 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-03-15 09:03 . 2011-03-15 09:03 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-03-15 09:03 . 2011-03-15 09:03 160256 ----a-w- c:\windows\system32\wextract.exe
2011-03-15 09:03 . 2011-03-15 09:03 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-03-15 09:03 . 2011-03-15 09:03 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-03-15 09:03 . 2011-03-15 09:03 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-03-15 09:03 . 2011-03-15 09:03 12288 ----a-w- c:\windows\system32\mshta.exe
2011-03-15 09:03 . 2011-03-15 09:03 114176 ----a-w- c:\windows\system32\admparse.dll
2011-03-15 09:03 . 2011-03-15 09:03 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-03-09 04:55 . 2010-04-06 14:15 795136 ----a-w- c:\windows\system32\aticfx64.dll
2011-03-09 04:53 . 2011-01-30 09:04 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-03-09 04:51 . 2010-04-06 14:10 423424 ----a-w- c:\windows\system32\atipdl64.dll
2011-03-09 04:40 . 2010-04-06 13:54 5044224 ----a-w- c:\windows\system32\atidxx64.dll
2011-03-09 04:30 . 2010-04-06 13:40 4294656 ----a-w- c:\windows\SysWow64\atiumdag.dll
2011-03-09 04:24 . 2010-04-06 13:32 5438976 ----a-w- c:\windows\system32\atiumd64.dll
2011-03-09 04:18 . 2011-01-26 22:14 360448 ----a-w- c:\windows\system32\atiadlxx.dll
2011-03-09 04:17 . 2010-04-06 13:22 39936 ----a-w- c:\windows\system32\atiuxp64.dll
2011-03-09 04:16 . 2010-04-06 13:22 38400 ----a-w- c:\windows\system32\atiu9p64.dll
2011-03-09 04:16 . 2010-04-06 13:22 28672 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2011-03-09 04:11 . 2011-01-30 09:04 58880 ----a-w- c:\windows\system32\coinst.dll
2011-03-09 03:41 . 2010-04-06 13:27 3239936 ----a-w- c:\windows\system32\atiumd6a.dll
2011-03-09 03:34 . 2010-04-06 13:21 3471872 ----a-w- c:\windows\SysWow64\atiumdva.dll
2011-03-04 19:27 . 2011-03-04 19:27 1060864 ----a-w- c:\windows\SysWow64\mfc71.dll
2011-03-03 12:28 . 2011-03-03 12:28 230352 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2011-02-28 08:00 . 2011-02-22 10:34 80896 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2011-02-27 09:41 . 2011-02-27 09:41 79872 ----a-w- c:\windows\SysWow64\winver.exe
2011-02-27 09:41 . 2011-02-27 09:41 833024 ----a-w- c:\windows\SysWow64\user32.dll.old
2011-02-27 09:41 . 2011-02-27 09:41 410624 ----a-w- c:\windows\SysWow64\systemcpl.dll
2011-02-27 09:41 . 2011-02-11 16:29 2169856 ----a-w- c:\windows\system32\hale.exe
2011-02-23 20:27 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-02-23 20:27 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-02-23 15:04 . 2011-03-04 10:16 238968 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-19 12:05 . 2011-03-10 07:21 1139200 ----a-w- c:\windows\system32\FntCache.dll
2011-02-19 12:04 . 2011-03-10 07:21 1544192 ----a-w- c:\windows\system32\DWrite.dll
2011-02-19 12:04 . 2011-03-10 07:21 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-02-19 06:30 . 2011-03-10 07:21 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-02-19 06:30 . 2011-03-10 07:21 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-02-11 07:30 . 2011-03-08 08:13 7947600 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8E164A40-0E55-405B-8D7F-D7CD205F7FF8}\mpengine.dll
2011-02-09 15:45 . 2011-02-09 15:45 419840 ----a-w- c:\windows\system32\wrap_oal.dll
2011-02-09 15:45 . 2011-02-09 15:45 413696 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2011-02-09 15:45 . 2011-02-09 15:45 133632 ----a-w- c:\windows\system32\OpenAL32.dll
2011-02-09 15:45 . 2011-02-09 15:45 110592 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2011-02-02 20:40 . 2011-01-30 12:16 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-02-02 16:11 . 2011-01-30 09:44 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-02-02 15:25 . 2011-02-02 15:25 49152 ----a-r- c:\users\Roman\AppData\Roaming\Microsoft\Installer\{C37A0BC1-52EE-4F97-8223-5CA9FC0357B0}\ARPPRODUCTICON.exe
2011-01-30 18:29 . 2009-08-18 11:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2011-01-30 18:29 . 2009-08-18 10:24 17816 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-01-30 09:24 . 2011-01-30 09:24 520192 ----a-w- c:\windows\SysWow64\K_Series_ScreenSaver_EN.scr
2011-01-30 09:24 . 2011-01-30 09:24 3054136 ----a-w- c:\windows\AsScrPro.exe
2011-01-30 09:22 . 2011-01-30 09:22 35384 ----a-w- c:\windows\system32\drivers\AsDsm.sys
2011-01-30 08:58 . 2011-02-27 09:41 833024 ----a-w- c:\windows\SysWow64\user32.dll
2011-01-30 08:58 . 2011-02-27 09:41 113543 ----a-w- c:\windows\SysWow64\slmgr.vbs
2009-04-08 09:31 . 2009-04-08 09:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-11 20:45 . 2008-08-11 20:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
------- Sigcheck -------
.
[7] 2010-11-20 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2009-07-14 . E573BD9AB55C8E333C202B9E255F972E . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
[-] 2011-01-30 . 2C9CC9F492CA596B1B9FC1AE5E916356 . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-20 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-12-09 11:51 3911776 ----a-w- c:\program files (x86)\uTorrentBar\tbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 16:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"="c:\users\Roman\AppData\Local\Seznam.cz\postak.exe" [2010-10-06 488728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-06-24 6806144]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-05-03 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-07-02 1597440]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 932288]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-08 336384]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files (x86)\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2011-1-30 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2011-1-30 156952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\guard32.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-06 136176]
R3 AODDriver4.0;AODDriver4.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 TS_AR5416;[CommView] Atheros AR5008 Wireless Network Adapter Service 7.7;c:\windows\system32\DRIVERS\ts_athwx.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys [x]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [x]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-03-08 365568]
S2 AMD Reservation Manager;AMD Reservation Manager;c:\program files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [2010-06-17 194496]
S2 Application Updater;Application Updater;c:\program files (x86)\Application Updater\ApplicationUpdater.exe [2011-01-28 387072]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys [x]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24\RivaTuner64.sys [2011-01-30 19952]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}]
2010-11-20 12:17 302592 ----a-w- c:\windows\System32\cmd.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-04-25 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2011-03-11 16:24]
.
2011-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-06 18:03]
.
2011-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-06 18:03]
.
2011-04-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3496903114-3669578777-545992414-1000Core.job
- c:\users\Roman\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-30 11:48]
.
2011-04-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3496903114-3669578777-545992414-1000UA.job
- c:\users\Roman\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-30 11:48]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 15:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2011-03-02 16:23 85232 ----a-w- c:\program files (x86)\Internet Download Manager\IDMShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"="%ProgramFiles%\Elantech\ETDCtrl.exe" [BU]
"RivaTunerStartupDaemon"="c:\program files (x86)\RivaTuner v2.24\RivaTunerWrapper.exe" [2009-08-22 24576]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-01-17 8866120]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\guard64.dll
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://start.icq.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: &Download by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/204
IE: ????3??
IE: ????3??????
IE: Do&wnload selected by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files (x86)\Orbitdownloader\orbitmxt.dll/202
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Stáhnout s IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm
IE: Stáhnout s IDM obsah FLV videa - c:\program files (x86)\Internet Download Manager\IEGetVL.htm
IE: Stáhnout s IDM všechny odkazy - c:\program files (x86)\Internet Download Manager\IEGetAll.htm
IE: ????3?? - c:\users\Roman\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - c:\users\Roman\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files (x86)\ICQ7.4\ICQ.exe
FF - ProfilePath - c:\users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\dnh4ogxv.default\
FF - prefs.js: browser.startup.homepage - chrome://speeddial/content/speeddial.xul
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=827316&p=
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{FF6C3CF0-4B15-11D1-ABED-709549C10000} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3496903114-3669578777-545992414-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}Ź]
@="c:\\Users\\Roman\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-3496903114-3669578777-545992414-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}ŹhQčţ”Ąc]
@="c:\\Users\\Roman\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_10_3_162_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_10_3_162_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG14.00.00.01PROFESSIONAL"="B1640E30FEFED3C87830A6D606FE7C2502E7ECEB7505639EB475D779DB46C3FADA9E956D7AF628262020BC14BCD15859109E83EC4C6CE11832DF89C6B0D625732E57B2B2F796FBA4820312C678E86A77FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98089DB7CE019D40AA5CBA7FD869164D6794C038D530D6EB3452AB8E05A277B4B958FC3CBED359F17D279C9F75836B6F9DDB29BF805E9C052707C49EA159CBC8C56ED10D73F9874D776DB9DBDED95F394EB03FDAAD91BEAC463F6B1F1CE55CF22254FBA30BC83B8B6482F0B534A6B6764B339F2E790C1D62E6E75984BA13E99A3E5A2322C6A1F54F7CDD7D18CE81D0A6B39D331575B81BA2B5214CB4683EF2D7EE26781C0AF8F76F5CC99E652B93537C1081EC5CD8155C1EBF5F858CB45C41F8E8B12D995C57CA77846598F16A17276048C0C146FCB3C9B9F6EB4BD7D074DC7FC9CB7716E95737A45A2334865261F5ED2994290ADF3A910DB3E366DC9421939F8F14140282ABCE6924493B6149D53273650821CE23E325E5AE3825D1FA13F8C39F02BEC09996636D0F73FEB25E6D0E75917BA9B68D7FB8C207ACD960A30CE20ABEDE3CABC7718B8A2D105120C2B583ABA72146CF876CC55BBE5AD829CFE36A431BC8D20EC828244E70E28BC049504E01848280231F240915BC2FFC3FE7866F744231CDA87D3A4B7D338109A36D726D16E9FA66A887AF840ECA6AA2A7757212D8275E7A2D673EE30D315628494A65A53CFD3A064F96ACFC9697A0AC5F29BA3ADBA2E82B46AFD916A789224E2720857FFDC844F679444E7BB2B6BC8055D40811A1EFBFB78FA3CACB2C437561A556C5471437F04EFC31DA4C1C9CF907EA6F1405FC2E24FA17B061352DC438CE21F32A0CEF9DEA2CA29C2C03BD24E82E79132FC8795F2CD2E2EC81C470DA24846CA64CA334ADB22FAA6E31F1390DEEE7C900BBD153ECC0A26B0F2332F0364A774BBED82438049C7C4530EAB463F7C42A1D98315AFCA1A1CF1A72D3F85EEA0B9E76B1136B881BCFBC190E702644ECF66DA4E31C609B2E5E465198B1D619711FF59B18CD1A6357481DBF5C6C699755E5B0088C1A278823DD73E3A4F2503AA60F7DDBAEF3123DFA554DC88F1DE24FFE487462625F33D079D9CB1B5E5EAB0A4BBB384CD6027DBCB21B82354254BA0F9DA4BFC2D633CF370C5FC4B13152F40802572EF5150AC6BE8991F4F932F7DF2FC7589B2C01F00AB01CD1D8582EBCF9E554E76AD412319FD272846203C08203BD761515159C86B566CA65873208A44F8BAFC97DDA9C2F7B3A41930B2D7404187809DDBDE9097868B62024D2D8979FCB92622AF9EDA2D292EEB032B24A769BD957C10E2C0947DDFA3288EC41D659D90A49A20B78E4BBFCE01B5D2922A19682447F4750"
"OODEFRAG12.00.00.01PROFESSIONAL"="906A1593EF1855F08A7EF9759ED64A3ED07D07B58BEB5E5B80440084AA596A177C33A6E09CEB7810D001CD79FC566B9EE39F232AF8DE84D6FE2E6478C014B0132079D1B5431DAA97218FF29CB7116B3EA763BA8B7F626CB2707CE2CA4A58B2C65C3E2FDF9D1C354AD8B46C7C974F0AFE17FAD1EA11BA68150BAC25FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98089DB7CE019D40AA5CBA7FD869164D6794C038D530D6EB34526DA132BCD9302245426386532DFEBE16EA45B5F51145904E64EE7EDA1E992C21B768BFDB4598DF2AF5BD2AFDCF70A121B969F13EE8AA12CA418C9F35405E0D431002668138195198AC34131022A63031605182A60DA9CD8492BE2EC8297AF5222B6D46E4ADDF008F8B73DCD3DE913E6996769C309A0B03E2416A99ECF235AF89C11FA750E2D4DCDE3E1BC5AA87530641964518EE71D0D1A43B6AF20C818BE21B13FCF4A4DA90B8ADF23EB3095C42A18220A0F20D34AE41D6EE0CEF2478AE1F4B5FE23D545BE04C75DB662E7766E992CA795C4D48CB0A395FD211EA47C08256636D1F34E66E473303AF0FE090F008BC1066C1EC7166808774DDAFE01B081FDEFE8674AE78E2F86DF9A9271B070B8F6A16358DB96DF0DFDCA28E13745B4052738EF71AA8364AE0DCCE0993519C8625457AB570C03722AD5048E4D7EB561D9BB1D813BB4265F999C9CB8EAD9B2BFA26DEA9BA10B459F020D99BE411306B982F9CF52EF7BB5C8D77608E033FB61F4420ACE69B85677719A2D72217444F946FF59AD12361FE86E27FAE092F89007781D386C8B35D54C59BD40CB8096BFCDA238DF5AD4F0094629B692800E2C0FC4A953AA6BBE319960DBC0B1A8F4BF38C5B7945DC1E944EAC859EA4250F718CD6BDA77C317C8FACF02C04CB8C2AF1C1F8497AA1628B58BA1A9416D1E0A22F09568F22F9A71F1D0347133D5450DE9629616BF25CFCB4042AD24CEEC7F9FC78456E10B5C4F30AF978A2477A11385C55F3069B76608528057072FBDB8EF4342C47B0A354A2E1F794DC2EE20D28771F4D62CCC7D650BCCB4E5CB88653E3B630AB05D6C0B51022F66176BD9210F0297D2624C0F1307DC258542A076310B90F325F6C3C76D5B848EBD67DC417DD75491E86DF0F31DC739F5A110EE41D0FB5A9C82F5C60E2F103CD8BF1A05CC696F63BFB1CAF09AF016DBCB2822F7DD413B01BDA0DA866BA8E818E61B2FD420A1F68426916A226AB005C6995A9A81FBB22B9DAA2699A18467101CA4C9A2ED5DE9FEF8987AAB9FE778264578C0D873E198610442D3BEC60E2A77F28FD33B61CD583EA9D4F116B527877DD1DF33651EECACEAB975D7E50CE7FFE2F2D7F8797BE147BE7EF8C07A181A90F5634FCB1FC6EBDCBB376E7AFE718228BF7C6A927BF0B537B"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-04-25 19:46:05
ComboFix-quarantined-files.txt 2011-04-25 17:46
ComboFix2.txt 2011-04-25 16:42
.
Před spuštěním: Volných bajtů: 23 919 845 376
Po spuštění: Volných bajtů: 23 859 412 992
.
- - End Of File - - B760D4993429E705A6F70C8C2687EA6D

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Totálně zasekaný notes

#6 Příspěvek od Rudy »

Log již vypadá čistý. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Roman47cz
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 23 srp 2006 17:12

Re: Totálně zasekaný notes

#7 Příspěvek od Roman47cz »

Uvidím během práce, jestli to bude zamrzat, snad ne. Ale přihlašování do Windows stále trvá neúměrně dlouho, takže po státnicích počítám s opětovným přeinstalováním OS. Zatím díky za pomoc.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Totálně zasekaný notes

#8 Příspěvek od Rudy »

Přes startmenu>přík. řádek (napište) msconfig>OK. V otevřeném okně vypněte vše, co nemusí bezpodmínečně startovat automaticky, tj. takové aplikace, které si v případě potřeby spustíte ručně. Start by se měl zrychlit. Zatím nemáte zač!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět