Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu (zpomalené pc, chyby)

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
kulma
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 23 črc 2009 20:48
Kontaktovat uživatele:

Prosím o kontrolu (zpomalené pc, chyby)

#1 Příspěvek od kulma »

Zdravím.
Prosím o konrolu. PC zpomalené, po startu NOD hlásí zablokované stránky www.csafer.net/domain/yepp@musiccity.xml
Dále různé stažené soubory větších velikostí z internetu jsou některé vadné a hlásí i chyby při dekomprimaci či kopírování na síťový disk.
LOG z RSIT:

Logfile of random's system information tool 1.08 (written by random/random)
Run by rhorsak at 2011-04-28 13:09:45
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 67 GB (67%) free of 100 GB
Total RAM: 2046 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:09:54, on 28.4.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Canon\DIAS\CnxDIAS.exe
C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwisam.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\windows\system32\FsUsbExService.Exe
C:\windows\system32\svchost.exe
C:\windows\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\windows\system32\ctfmon.exe
C:\Program Files\TeamViewer\Version6\TeamViewer.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\MEDIAK~1\MagicKey.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwida.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\TC UP\TC UP.exe
C:\Program Files\Acronis\OnlineBackupStandalone\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\TC UP\totalcmd.exe
C:\Program Files\Clip2Net\clip2net.exe
C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\Seznam.cz\postak.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwism.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\windows\System32\svchost.exe
C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\Seznam.cz\MiniBrowser.exe
C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\Seznam.cz\MiniBrowser.exe
C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Downloads\RSIT.exe
C:\Program Files\trend micro\rhorsak.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://search13.net/search.php?clid=486&q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: ˙ţ1
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: DIALux 3.1 ULDBrowserHelper Class - {69AB812A-8CE4-4BF3-B49B-3B60A9F31FB2} - C:\Program Files\DIALux\DLXShellExtension.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [MagicKey] C:\PROGRA~1\MEDIAK~1\MagicKey.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CnwiDeviceAgent] C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwida.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\program files\real\realplayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TC UP] "C:\Program Files\TC UP\TC UP.exe" /wnd=min
O4 - HKLM\..\Run: [SAOB Monitor] C:\Program Files\Acronis\OnlineBackupStandalone\TrueImageMonitor.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] "C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [Clip2Net] C:\Program Files\Clip2Net\clip2net.exe
O4 - HKCU\..\Run: [Seznam Postak] "C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe /s
O4 - HKCU\..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: [Sony Ericsson PC Companion] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: imagePROGRAF Status Monitor.lnk = C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwism.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://cam-km.nwt.cz/activex/AxisCamControl.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ehv-projekt.cz
O17 - HKLM\Software\..\Telephony: DomainName = ehv-projekt.cz
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ehv-projekt.cz
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ehv-projekt.cz
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = ehv-projekt.cz
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/html - {574940E0-1B7A-4881-8FA3-1E809714B156} - (no file)
O20 - AppInit_DLLs: acaptuser32.dll C:\WINDOWS\system32\guard32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\windows\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\windows\system32\browseui.dll
O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Acronis Nonstop Backup service (afcdpsrv) - Acronis - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Canon Driver Information Assist Service - CANON INC. - C:\Program Files\Canon\DIAS\CnxDIAS.exe
O23 - Service: Canon imagePROGRAF Status Monitor - CANON INC - C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwisam.exe
O23 - Service: DIAL Communication Service (DialComService) - Unknown owner - C:\Program Files\DIAL GmbH\DIAL Communication Framework\DialComService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FsUsbExService - Teruten - C:\windows\system32\FsUsbExService.Exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe

--
End of file - 13249 bytes

======Scheduled tasks folder======

C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651790719-4201147004-1817147730-1138Core.job
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651790719-4201147004-1817147730-1138UA.job
C:\windows\tasks\RealUpgradeLogonTaskS-1-5-21-1651790719-4201147004-1817147730-1138.job
C:\windows\tasks\RealUpgradeScheduledTaskS-1-5-21-1651790719-4201147004-1817147730-1138.job
C:\windows\tasks\User_Feed_Synchronization-{2B4E2C57-8533-46BC-BE6D-BD765062400A}.job
C:\windows\tasks\User_Feed_Synchronization-{6CD4EB02-F798-4B09-9389-69E4B92B2FA7}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-01-27 382720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{69AB812A-8CE4-4BF3-B49B-3B60A9F31FB2}]
DIALux 3.1 ULDBrowserHelper Class - C:\Program Files\DIALux\DLXShellExtension.dll [2011-02-14 542720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-02-27 349576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-22 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-04-22 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-02-27 349576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-02-27 349576]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-12-10 49152]
"MagicKey"=C:\PROGRA~1\MEDIAK~1\MagicKey.exe [2007-01-09 167936]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-02-10 61440]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2215064]
"REGSHAVE"=C:\Program Files\REGSHAVE\REGSHAVE.EXE [2002-02-04 53248]
"SystemTray"=C:\windows\system32\SysTray.Exe [2008-04-14 3072]
"Adobe Acrobat Speed Launcher"=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [2009-10-03 38768]
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [2009-10-03 640376]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"CnwiDeviceAgent"=C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwida.exe [2009-06-10 64272]
"TkBellExe"=C:\program files\real\realplayer\update\realsched.exe [2011-01-27 274608]
"NeroFilterCheck"=C:\windows\system32\NeroCheck.exe [2006-01-12 155648]
"TC UP"=C:\Program Files\TC UP\TC UP.exe [2010-12-26 615936]
"SAOB Monitor"=C:\Program Files\Acronis\OnlineBackupStandalone\TrueImageMonitor.exe [2010-08-20 2536448]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2010-08-21 5458848]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2010-08-21 390736]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\windows\system32\ctfmon.exe [2008-04-14 15360]
"Clip2Net"=C:\Program Files\Clip2Net\clip2net.exe [2009-10-08 1635328]
"Seznam Postak"=C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\Seznam.cz\postak.exe [2010-10-06 488728]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-01-26 15026056]
"KiesHelper"=C:\Program Files\Samsung\Kies\KiesHelper.exe [2011-03-17 896912]
"KiesTrayAgent"=C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [2011-01-30 3372856]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"KiesPDLR"=C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [2011-04-11 13824]
"Sony Ericsson PC Companion"=C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [2011-02-28 427008]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Služba Plánovač2]
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2010-08-21 390736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2010-08-21 5458848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Windows Search.lnk]
C:\PROGRA~1\WINDOW~2\WINDOW~1.EXE [2010-01-14 123904]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
imagePROGRAF Status Monitor.lnk - C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwism.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="acaptuser32.dll C:\WINDOWS\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\windows\system32\Ati2evxx.dll [2010-02-11 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\windows\system32\WgaLogon.dll [2010-01-14 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\windows\system32\WPDShServiceObj.dll [2009-01-30 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll [2009-10-02 128360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2010-01-14 304128]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoWelcomeScreen"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:*:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:*:Enabled:ActiveSync Application"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\QIP Infium\infium.exe"="C:\Program Files\QIP Infium\infium.exe:*:Enabled:QIP Infium"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"E:\QIP 2010\qip.exe"="E:\QIP 2010\qip.exe:*:Enabled:QIP 2010"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Documents and Settings\rhorsak\Local Settings\Temp\7zS7C9.tmp\setup\HPZnui01.exe"="C:\Documents and Settings\rhorsak\Local Settings\Temp\7zS7C9.tmp\setup\HPZnui01.exe:*:Enabled:hpznui01.exe"
"C:\Documents and Settings\rhorsak\Local Settings\Temp\7zS7C9.tmp\setup\hponicifs01.exe"="C:\Documents and Settings\rhorsak\Local Settings\Temp\7zS7C9.tmp\setup\hponicifs01.exe:*:Enabled:hponicifs01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\Canon\DIAS\CnxDIAS.exe"="C:\Program Files\Canon\DIAS\CnxDIAS.exe:*:Enabled:Canon Driver Information Assist Service"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\QIP Infium\infium.exe"="C:\Program Files\QIP Infium\infium.exe:*:Enabled:QIP Infium"
"C:\Program Files\TC UP\TOTALCMD.EXE"="C:\Program Files\TC UP\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"C:\WINDOWS\system32\muzapp.exe"="C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player"
"C:\Program Files\Samsung\Kies\Kies.exe"="C:\Program Files\Samsung\Kies\Kies.exe:*:Enabled:Samsung Kies"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Documents and Settings\rhorsak\Local Settings\Temp\Rar$EX00.546\WinOnJET.exe"="C:\Documents and Settings\rhorsak\Local Settings\Temp\Rar$EX00.546\WinOnJET.exe:*:Enabled:WinOnJET Client"
"C:\Program Files\MOBILedit!\WebVideoDownloader.exe"="C:\Program Files\MOBILedit!\WebVideoDownloader.exe:*:Enabled:MobilEdit! Web Video Downloader Proxy"
"C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwism.exe"="C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwism.exe:*:Enabled:imagePROGRAF Status Monitor"
"C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwida.exe"="C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwida.exe:*:Enabled:imagePROGRAF Device Agent"
"\\01ehvsbs\Install\ovladače\Canon iPF750\32bit\iPFSetup.exe"="\\01ehvsbs\Install\ovladače\Canon iPF750\32bit\iPFSetup.exe:*:Enabled:iPFSetup"
"C:\Program Files\Samsung Electronics\Snap N' Go\MonitorLauncher.exe"="C:\Program Files\Samsung Electronics\Snap N' Go\MonitorLauncher.exe:*:Enabled:Snap N' Go"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\TeamViewer\Version6\TeamViewer.exe"="C:\Program Files\TeamViewer\Version6\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe"="C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service"
"C:\Documents and Settings\rhorsak\Local Settings\Temp\Rar$EX45.192\Kamera.exe"="C:\Documents and Settings\rhorsak\Local Settings\Temp\Rar$EX45.192\Kamera.exe:*:Enabled:Kamera 4"
"C:\Program Files\Sony Ericsson\Update Service\Update Service.exe"="C:\Program Files\Sony Ericsson\Update Service\Update Service.exe:*:Enabled:Update Service"

======File associations======

.scr - open - C:\WINDOWS\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2011-04-28 13:03:22 ----D---- C:\Program Files\trend micro
2011-04-28 13:03:21 ----D---- C:\rsit
2011-04-28 12:51:38 ----HDC---- C:\windows\$NtUninstallKB2492386$
2011-04-27 13:18:00 ----A---- C:\windows\system32\drivers\mbamswissarmy.sys
2011-04-27 13:17:56 ----A---- C:\windows\system32\drivers\mbam.sys
2011-04-27 10:03:15 ----D---- C:\OEZ
2011-04-21 09:55:45 ----D---- C:\Program Files\Western Digital Corporation
2011-04-21 08:47:22 ----D---- C:\Program Files\Astra 92
2011-04-20 10:30:59 ----N---- C:\windows\system32\spmsgXP_2k3.dll
2011-04-20 10:30:54 ----HDC---- C:\windows\$NtUninstallWdf01007$
2011-04-20 10:27:15 ----A---- C:\windows\system32\WdfCoInstaller01007.dll
2011-04-20 10:27:15 ----A---- C:\windows\system32\drivers\ggsemc.sys
2011-04-20 10:27:15 ----A---- C:\windows\system32\drivers\ggflt.sys
2011-04-20 10:18:58 ----D---- C:\Program Files\Avanquest update
2011-04-20 10:18:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avanquest
2011-04-20 10:18:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\BVRP Software
2011-04-20 10:17:40 ----A---- C:\windows\system32\drivers\s1018unic.sys
2011-04-20 10:17:40 ----A---- C:\windows\system32\drivers\s1018obex.sys
2011-04-20 10:17:40 ----A---- C:\windows\system32\drivers\s1018mgmt.sys
2011-04-20 10:17:40 ----A---- C:\windows\system32\drivers\s1018cr.sys
2011-04-20 10:17:39 ----A---- C:\windows\system32\drivers\s1018whnt.sys
2011-04-20 10:17:39 ----A---- C:\windows\system32\drivers\s1018wh.sys
2011-04-20 10:17:39 ----A---- C:\windows\system32\drivers\s1018nd5.sys
2011-04-20 10:17:39 ----A---- C:\windows\system32\drivers\s1018mdm.sys
2011-04-20 10:17:39 ----A---- C:\windows\system32\drivers\s1018mdfl.sys
2011-04-20 10:17:39 ----A---- C:\windows\system32\drivers\s1018cmnt.sys
2011-04-20 10:17:39 ----A---- C:\windows\system32\drivers\s1018cm.sys
2011-04-20 10:17:39 ----A---- C:\windows\system32\drivers\s1018bus.sys
2011-04-20 10:17:21 ----D---- C:\Program Files\Sony Ericsson
2011-04-20 10:17:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sony Ericsson
2011-04-20 10:10:15 ----D---- C:\Documents and Settings\rhorsak\Data aplikací\MyPhoneExplorer
2011-04-20 10:09:52 ----D---- C:\Program Files\MyPhoneExplorer
2011-04-18 13:55:09 ----A---- C:\BadaSI_Installer.exe
2011-04-14 14:10:01 ----D---- C:\Program Files\SoftSoft
2011-04-14 13:31:26 ----D---- C:\Program Files\Img2CAD
2011-04-14 09:47:41 ----D---- C:\Program Files\Creative
2011-04-13 03:13:53 ----HDC---- C:\windows\$NtUninstallKB2485663$
2011-04-13 03:13:49 ----HDC---- C:\windows\$NtUninstallKB2506223$
2011-04-13 03:12:38 ----HDC---- C:\windows\$NtUninstallKB2412687$
2011-04-13 03:09:50 ----HDC---- C:\windows\$NtUninstallKB2508272$
2011-04-13 03:09:45 ----HDC---- C:\windows\$NtUninstallKB2503658$
2011-04-13 03:05:06 ----HDC---- C:\windows\$NtUninstallKB2507618$
2011-04-13 03:05:02 ----HDC---- C:\windows\$NtUninstallKB2508429$
2011-04-13 03:04:58 ----HDC---- C:\windows\$NtUninstallKB2511455$
2011-04-13 03:04:25 ----HDC---- C:\windows\$NtUninstallKB2506212$
2011-04-13 03:01:45 ----HDC---- C:\windows\$NtUninstallKB2509553$
2011-04-12 10:41:46 ----D---- C:\Program Files\Akeeba
2011-04-11 14:13:22 ----HDC---- C:\windows\$NtUninstallKB967715$
2011-04-11 13:37:21 ----D---- C:\Temp
2011-04-11 13:30:02 ----A---- C:\windows\ReplacerUndo.txt
2011-04-11 13:28:36 ----A---- C:\windows\system32\Replacer.cmd
2011-04-11 12:58:09 ----D---- C:\Program Files\FileSubmit
2011-04-07 12:57:00 ----D---- C:\Documents and Settings\rhorsak\Data aplikací\BizIcom
2011-04-07 12:56:12 ----D---- C:\Program Files\iDwgTab
2011-04-06 11:36:44 ----A---- C:\windows\system32\drivers\afcdp.sys
2011-04-06 11:36:40 ----A---- C:\windows\system32\drivers\tdrpm273.sys
2011-04-06 11:36:30 ----A---- C:\windows\system32\drivers\snapman.sys
2011-04-06 11:36:06 ----D---- C:\Program Files\Acronis
2011-04-06 08:38:24 ----ASH---- C:\pagefile.sys
2011-03-30 12:13:36 ----D---- C:\Documents and Settings\rhorsak\Data aplikací\Canon
2011-03-30 12:12:12 ----RASH---- C:\MSDOS.SYS
2011-03-30 12:12:12 ----RASH---- C:\IO.SYS
2011-03-29 11:40:14 ----D---- C:\Program Files\OEZ

======List of files/folders modified in the last 1 months======

2011-04-28 13:09:46 ----D---- C:\windows\Temp
2011-04-28 13:03:22 ----RD---- C:\Program Files
2011-04-28 12:56:09 ----D---- C:\Documents and Settings\rhorsak\Data aplikací\Skype
2011-04-28 12:54:50 ----SD---- C:\windows\Tasks
2011-04-28 12:54:38 ----D---- C:\WINDOWS
2011-04-28 12:54:29 ----SHD---- C:\windows\CSC
2011-04-28 12:53:47 ----D---- C:\windows\system32\CatRoot2
2011-04-28 12:53:01 ----D---- C:\windows\AppPatch
2011-04-28 12:51:40 ----RSHDC---- C:\windows\system32\dllcache
2011-04-28 12:51:40 ----D---- C:\windows\system32
2011-04-28 12:51:38 ----HD---- C:\windows\inf
2011-04-28 12:51:34 ----HD---- C:\windows\$hf_mig$
2011-04-28 12:51:32 ----A---- C:\windows\imsins.BAK
2011-04-28 12:51:27 ----D---- C:\Program Files\Internet Explorer
2011-04-28 12:51:26 ----D---- C:\windows\ie8updates
2011-04-28 12:49:31 ----D---- C:\Program Files\QIP Infium
2011-04-28 12:39:23 ----A---- C:\windows\SchedLgU.Txt
2011-04-28 12:13:13 ----D---- C:\windows\Minidump
2011-04-28 11:00:05 ----D---- C:\Documents and Settings\rhorsak\Data aplikací\skypePM
2011-04-28 10:32:07 ----D---- C:\Documents and Settings\rhorsak\Data aplikací\esmska
2011-04-28 10:29:27 ----D---- C:\windows\Prefetch
2011-04-28 10:11:39 ----D---- C:\Pošta
2011-04-28 08:45:28 ----D---- C:\Program Files\JDownloader
2011-04-28 05:22:00 ----D---- C:\windows\security
2011-04-27 15:51:51 ----D---- C:\Documents and Settings\rhorsak\Data aplikací\AIMP
2011-04-27 13:28:39 ----D---- C:\windows\system32\drivers
2011-04-27 13:18:00 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-04-27 06:12:12 ----D---- C:\windows\system32\config
2011-04-21 06:49:18 ----SHD---- C:\windows\Installer
2011-04-20 10:27:22 ----DC---- C:\windows\system32\DRVSTORE
2011-04-20 10:24:01 ----HD---- C:\Program Files\InstallShield Installation Information
2011-04-20 09:50:48 ----HD---- C:\Config.Msi
2011-04-18 15:46:44 ----A---- C:\windows\system32\MRT.exe
2011-04-14 14:05:15 ----D---- C:\Documents and Settings\rhorsak\Data aplikací\Thinstall
2011-04-14 13:40:24 ----A---- C:\windows\NeroDigital.ini
2011-04-13 03:24:21 ----RSD---- C:\windows\assembly
2011-04-13 03:16:08 ----D---- C:\windows\Microsoft.NET
2011-04-13 03:15:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2011-04-13 03:14:06 ----D---- C:\windows\WinSxS
2011-04-13 03:12:11 ----A---- C:\windows\system32\PerfStringBackup.INI
2011-04-13 03:02:25 ----D---- C:\windows\Debug
2011-04-12 11:44:15 ----D---- C:\Documents and Settings\rhorsak\Data aplikací\FileZilla
2011-04-12 07:57:00 ----D---- C:\windows\system32\CatRoot
2011-04-11 17:22:50 ----D---- C:\Program Files\Oce
2011-04-11 11:02:18 ----D---- C:\windows\Cursors
2011-04-11 11:02:17 ----D---- C:\windows\Media
2011-04-08 07:26:04 ----SD---- C:\windows\Downloaded Program Files
2011-04-06 13:58:42 ----D---- C:\Documents and Settings\All Users\Data aplikací\Acronis
2011-04-06 13:27:18 ----D---- C:\Documents and Settings\rhorsak\Data aplikací\Acronis
2011-04-06 11:36:44 ----D---- C:\Program Files\Common Files\Acronis
2011-04-06 10:49:05 ----D---- C:\Program Files\Common Files\ACD Systems
2011-04-06 10:49:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\ACD Systems
2011-04-06 08:50:00 ----D---- C:\Program Files\Common Files\Adobe
2011-04-06 08:49:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-04-06 08:49:04 ----D---- C:\Documents and Settings\rhorsak\Data aplikací\Adobe
2011-04-06 08:48:58 ----D---- C:\Program Files\Adobe
2011-04-06 08:38:21 ----D---- C:\Program Files\ResultUrl
2011-04-06 08:38:21 ----D---- C:\Program Files\7-Zip
2011-04-06 08:01:49 ----D---- C:\Program Files\ASUS
2011-04-06 08:00:42 ----D---- C:\Program Files\Mozilla Firefox
2011-04-06 08:00:41 ----D---- C:\Documents and Settings\rhorsak\Data aplikací\Mozilla
2011-04-06 08:00:06 ----D---- C:\Program Files\GeoGet
2011-04-06 07:59:34 ----D---- C:\Documents and Settings\rhorsak\Data aplikací\FreeCommanderXE
2011-04-06 07:51:40 ----D---- C:\Program Files\CCleaner
2011-04-04 07:52:58 ----RSD---- C:\windows\Fonts
2011-04-02 20:21:49 ----D---- C:\Documents and Settings\rhorsak\Data aplikací\TeamViewer
2011-03-31 08:22:20 ----D---- C:\Program Files\TC UP
2011-03-30 14:53:41 ----A---- C:\windows\Dialux.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 imagedrv;imagedrv; C:\windows\System32\Drivers\imagedrv.sys [2005-09-01 5888]
R0 imagesrv;imagesrv; C:\windows\system32\DRIVERS\imagesrv.sys [2005-09-01 127488]
R0 nvata;nvata; C:\windows\system32\DRIVERS\nvata.sys [2010-04-22 93568]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\windows\system32\DRIVERS\ohci1394.sys [2010-01-14 61824]
R0 snapman;Acronis Snapshots Manager; C:\windows\system32\DRIVERS\snapman.sys [2011-04-06 170464]
R0 sptd;sptd; C:\windows\System32\Drivers\sptd.sys [2011-03-08 691696]
R0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273); C:\windows\system32\DRIVERS\tdrpm273.sys [2011-04-06 752128]
R0 timounter;Acronis Backup Archive Explorer; C:\windows\system32\DRIVERS\timntr.sys [2011-04-06 600928]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\windows\system32\DRIVERS\WudfPf.sys [2010-01-14 77568]
R1 AmdPPM;Ovladač procesoru HwPState AMD; C:\windows\system32\DRIVERS\AmdPPM.sys [2007-04-16 33792]
R1 AsIO;AsIO; C:\windows\system32\drivers\AsIO.sys [2006-10-19 12664]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
R1 epfwtdir;epfwtdir; C:\windows\system32\DRIVERS\epfwtdir.sys [2010-08-03 95896]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\windows\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 VD_FileDisk;VD_FileDisk; C:\windows\system32\drivers\VD_FileDisk.sys [2011-01-26 24680]
R2 Aspi32;Aspi32; C:\windows\System32\drivers\aspi32.sys [2008-05-06 16512]
R2 eamon;eamon; C:\windows\system32\DRIVERS\eamon.sys [2010-08-04 140752]
R2 MaVctrl;MaVctrl; C:\windows\system32\DRIVERS\MaVc2K.sys [2007-01-16 11986]
R2 rspndr;Odpovídající zařízení zjišťování topologie linkové vrstvy; C:\windows\system32\DRIVERS\rspndr.sys [2010-01-14 62848]
R3 afcdp;afcdp; C:\windows\system32\DRIVERS\afcdp.sys [2011-04-06 163232]
R3 Arp1394;Protokol 1394 ARP Client; C:\windows\system32\DRIVERS\arp1394.sys [2010-01-14 60800]
R3 ati2mtag;ati2mtag; C:\windows\system32\DRIVERS\ati2mtag.sys [2010-02-11 3565056]
R3 c65013264;C-Media CM6501 Like Sound UDAX Interface; C:\windows\system32\drivers\c6501.sys [2007-01-25 1305600]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\windows\system32\FsUsbExDisk.SYS []
R3 hidusb;Ovladač třídy standardu HID; C:\windows\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\windows\system32\DRIVERS\mouhid.sys [2010-01-14 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; C:\windows\system32\DRIVERS\nic1394.sys [2010-01-14 61824]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\windows\system32\DRIVERS\NVENETFD.sys [2010-04-22 34048]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\windows\system32\DRIVERS\nvnetbus.sys [2010-04-22 13056]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\windows\system32\DRIVERS\serscan.sys [2008-05-30 7296]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\windows\system32\DRIVERS\usbccgp.sys [2010-01-14 32384]
R3 V0260VID;Live! Cam Vista IM; C:\windows\system32\DRIVERS\V0260Vid.sys [2006-11-04 178913]
S1 AmdK8;Ovladač procesoru AMD; C:\windows\system32\DRIVERS\AmdK8.sys [2006-07-01 43008]
S1 DumpDrv;Crash Dump Driver; C:\windows\system32\drivers\DumpDrv.sys [2010-01-14 9472]
S3 azcf8wt0;azcf8wt0; C:\windows\system32\drivers\azcf8wt0.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\windows\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 cm102u32;C-Media CM6501 Like Sound Interface; C:\windows\system32\drivers\c6501.sys [2007-01-25 1305600]
S3 dgderdrv;dgderdrv; C:\windows\System32\drivers\dgderdrv.sys [2011-01-29 20032]
S3 ggflt;SEMC USB Flash Driver Filter; C:\windows\system32\DRIVERS\ggflt.sys [2011-04-20 13224]
S3 ggsemc;SEMC USB Flash Driver; C:\windows\system32\DRIVERS\ggsemc.sys [2011-04-20 25512]
S3 GVCplDrv;GVCplDrv; C:\windows\system32\drivers\GVCplDrv.sys [2004-05-02 23040]
S3 mak810c;mak810c; C:\windows\System32\Drivers\mak810c.sys [2005-06-16 24784]
S3 mak810m;mak810m; C:\windows\System32\Drivers\mak810m.sys [2005-06-16 25044]
S3 mak810u;mak810u; C:\windows\System32\Drivers\mak810u.sys [2007-06-07 52693]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\windows\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\windows\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\windows\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 RimUsb;zařízení BlackBerry Smartphone; C:\windows\System32\Drivers\RimUsb.sys []
S3 RimVSerPort;RIM Virtual Serial Port v2; C:\windows\system32\DRIVERS\RimSerial.sys [2009-01-09 27136]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\windows\System32\Drivers\RootMdm.sys [2008-04-14 5888]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM); C:\windows\system32\DRIVERS\s1018bus.sys [2009-03-25 86824]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter; C:\windows\system32\DRIVERS\s1018mdfl.sys [2009-03-25 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver; C:\windows\system32\DRIVERS\s1018mdm.sys [2009-03-25 114728]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM); C:\windows\system32\DRIVERS\s1018mgmt.sys [2009-03-25 106208]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS); C:\windows\system32\DRIVERS\s1018nd5.sys [2009-03-25 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface; C:\windows\system32\DRIVERS\s1018obex.sys [2009-03-25 104744]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM); C:\windows\system32\DRIVERS\s1018unic.sys [2009-03-25 109864]
S3 SLIP;BDA Slip De-Framer; C:\windows\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM); C:\windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter; C:\windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers; C:\windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648]
S3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM); C:\windows\system32\DRIVERS\ssceserd.sys [2010-04-27 100352]
S3 StarOpen;StarOpen; C:\windows\system32\drivers\StarOpen.sys []
S3 streamip;BDA IPSink; C:\windows\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\windows\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 usbprint;Třída USB Printer; C:\windows\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\windows\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač paměťového zařízení USB; C:\windows\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\windows\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WpdUsb;WpdUsb; C:\windows\system32\DRIVERS\wpdusb.sys [2009-01-30 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\windows\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\windows\system32\DRIVERS\wudfrd.sys [2010-01-14 82944]
S4 exFat;exFat; C:\windows\system32\drivers\exFat.sys [2010-01-14 133632]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2010-08-21 779960]
R2 afcdpsrv;Acronis Nonstop Backup service; C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe [2011-04-06 3975088]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\windows\system32\Ati2evxx.exe [2010-02-11 602112]
R2 bgsvcgen;B's Recorder GOLD Library General Service; C:\WINDOWS\system32\bgsvcgen.exe [2005-04-30 86016]
R2 Canon Driver Information Assist Service;Canon Driver Information Assist Service; C:\Program Files\Canon\DIAS\CnxDIAS.exe [2008-07-29 3405672]
R2 Canon imagePROGRAF Status Monitor;Canon imagePROGRAF Status Monitor; C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwisam.exe [2009-06-10 688912]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-08-12 810144]
R2 FsUsbExService;FsUsbExService; C:\windows\system32\FsUsbExService.Exe [2010-10-25 217088]
R2 hpqcxs08;hpqcxs08; C:\windows\system32\svchost.exe [2010-01-14 14848]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\windows\system32\svchost.exe [2010-01-14 14848]
R2 HPSLPSVC;HP Network Devices Support; C:\windows\system32\svchost.exe [2010-01-14 14848]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-04-22 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\windows\System32\svchost.exe [2010-01-14 14848]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\windows\System32\svchost.exe [2010-01-14 14848]
R2 TeamViewer6;TeamViewer 6; C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe [2011-03-18 2271608]
R2 WSearch;Windows Search; C:\windows\system32\SearchIndexer.exe [2010-01-14 439808]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\windows\system32\svchost.exe [2010-01-14 14848]
R3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2010-02-10 593920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 wscntfysvc;Windows Security Center Notification App; C:\Program Files\Common Files\MSSecurity\wscntfy.exe [2011-01-14 40960]
S3 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 DialComService;DIAL Communication Service; C:\Program Files\DIAL GmbH\DIAL Communication Framework\DialComService.exe [2011-02-13 1623552]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-08-12 33584]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-05-11 1045256]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-02-10 150528]
S3 WinRM;Windows Remote Management (WS-Management); C:\windows\system32\svchost.exe [2010-01-14 14848]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2009-02-04 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------
*kulma*

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu (zpomalené pc, chyby)

#2 Příspěvek od vyosek »

Zdravim a pekny den preji :)

:arrow: Poprosim i o druhy log z RSIT s nazvem info.txt, je ulozen v c:\rsit

:arrow: Predpokladam ze ten NOD32 mate legalni = zakoupena licence :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kulma
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 23 črc 2009 20:48
Kontaktovat uživatele:

Re: Prosím o kontrolu (zpomalené pc, chyby)

#3 Příspěvek od kulma »

Ano NOD business máme oficiálně koupený.
Zde je i ten druhý log v příloze:
Přílohy
info.zip
(10.36 KiB) Staženo 20 x
*kulma*

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu (zpomalené pc, chyby)

#4 Příspěvek od vyosek »

NOD Bussines je pro firemni uzivatele, tento PC je firemni :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kulma
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 23 črc 2009 20:48
Kontaktovat uživatele:

Re: Prosím o kontrolu (zpomalené pc, chyby)

#5 Příspěvek od kulma »

Ano
*kulma*

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu (zpomalené pc, chyby)

#6 Příspěvek od vyosek »

"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kulma
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 23 črc 2009 20:48
Kontaktovat uživatele:

Re: Prosím o kontrolu (zpomalené pc, chyby)

#7 Příspěvek od kulma »

:cry: No to je škoda, firmu si najímáme, ale chtěl jsem to pořešit lepší cestou, když vím , že už se mě tady pomohlo na svém domácí PC. škoda :cry:
*kulma*

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu (zpomalené pc, chyby)

#8 Příspěvek od vyosek »

Pokud firma nepracuje jak ma, taky je nejepsi jit k jine :wink:

Nehodlame tu delat praci za nekoho jineho...Soukroma PC tu resime bez problemu :wink:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kulma
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 23 črc 2009 20:48
Kontaktovat uživatele:

Re: Prosím o kontrolu (zpomalené pc, chyby)

#9 Příspěvek od kulma »

OK beru v potaz - Zamkněte tedy
*kulma*

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu (zpomalené pc, chyby)

#10 Příspěvek od vyosek »

Prosim tedy kolegy o :lock:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět