Vir MS Removal Tool

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
Fers
Návštěvník
Návštěvník
Příspěvky: 22
Registrován: 28 Lis 2005 15:10
Kontaktovat uživatele:

Re: Vir MS Removal Tool

#16 Příspěvek od Fers »

Tady je log:

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\1C4551A64743409391E41477CD655043.TMP folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1D90.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1E78.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP252C.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2867.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3BE7.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP66DE.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP869D.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP988A.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9B74.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPA2E3.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPF269.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPFBF1.tmp folder moved successfully.
C:\WINDOWS\System32\~.tmp moved successfully.
C:\WINDOWS\twain_32\hpqgnds2.tmp moved successfully.
C:\Program Files\DAEMON Tools Toolbar\Resources folder moved successfully.
C:\Program Files\DAEMON Tools Toolbar folder moved successfully.
File/Folder C:\Program Files\pdfforge Toolbar not found.
C:\Users\josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup folder moved successfully.
File/Folder setup_9.0.0.722_10.05.2011_11-39.lnk not found.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\temp scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\sounds scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\vi scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\tur scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\tch scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\sv scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\sch\skin\loc scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\sch\skin\layout scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\sch\skin scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\sch\images scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\sch scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\ru\images scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\ru scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\pt scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\pl scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\nor scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\nl scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\la scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\kor\skin\loc scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\kor\skin scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\kor scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\jp\skin\sounds scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\jp\skin\loc scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\jp\skin\layout scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\jp\skin\images\wtb scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\jp\skin\images\vkbd scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\jp\skin\images\tray scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\jp\skin\images\tasks scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\jp\skin\images\radar scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\jp\skin\images scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\jp\skin scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\jp scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\it scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\id scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\hu scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\fr scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\fi scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\esp scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\en scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\el scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\de_ab scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\de scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\da scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\cz scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\br scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\ar\skin scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc\ar scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\loc scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\layout scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\images\tasks scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\images\radar scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin\images scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\skin scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\report\0C scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\report\0B scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\report\0A scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\report\09 scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\report\08 scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\report\07 scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\report\06 scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\report\05 scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\report\04 scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\report\03 scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\report\02 scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\report\01 scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\report\00 scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\report scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\qb scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\drivers\2 scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\drivers\1 scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\drivers scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\tur scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\sv scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\sch scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\ru scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\pt scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\pl scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\nl scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\la scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\kor scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\it scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\hu scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\fr scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\esp scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\en scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\el scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\de scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\da scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\cz scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc\br scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\Doc scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\data scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\bases\Stat scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\bases scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39 scheduled to be moved on reboot.
Folder move failed. C:\Users\josef\Desktop\Virus Removal Tool scheduled to be moved on reboot.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56502 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Desktop
->Temp folder emptied: 0 bytes

User: josef
->Temp folder emptied: 59560919 bytes
->Temporary Internet Files folder emptied: 25267330 bytes
->Java cache emptied: 126538455 bytes
->FireFox cache emptied: 268810865 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 6826 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 142167 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 366042 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 743 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 458,00 mb


OTM by OldTimer - Version 3.1.17.2 log created on 05112011_222530

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Vir MS Removal Tool

#17 Příspěvek od motji »

Poprosím o nový log ze rsitu.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Fers
Návštěvník
Návštěvník
Příspěvky: 22
Registrován: 28 Lis 2005 15:10
Kontaktovat uživatele:

Re: Vir MS Removal Tool

#18 Příspěvek od Fers »

Tady je :) :

Logfile of random's system information tool 1.08 (written by random/random)
Run by josef at 2011-05-11 23:17:13
Microsoft® Windows Vista™ Enterprise Service Pack 2
System drive C: has 8 GB (13%) free of 60 GB
Total RAM: 3069 MB (56% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:17:18, on 11.5.2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\conime.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Users\josef\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Mouse Driver\StartAutorun.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Mouse Driver\KMConfig.exe
C:\Program Files\Mouse Driver\KMProcess.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\setup_9.0.0.722_10.05.2011_11-39.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Altap Salamander 2.5\SALAMAND.exe
C:\Users\josef\Desktop\RSIT.exe
C:\Program Files\trend micro\josef.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [KMCONFIG] C:\Program Files\Mouse Driver\StartAutorun.exe KMConfig.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
O4 - HKLM\..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - Startup: Logitech . Registrace produktu.lnk = C:\Program Files\Common Files\Logishrd\eReg\SetPoint\eReg.exe
O4 - Startup: setup_9.0.0.722_10.05.2011_11-39.lnk = C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\startup.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Stáhnout Free Download Managerem - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Stáhnout video Free Download Managerem - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Stáhnout vybrané Free Download Managerem - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Stáhnout vše Free Download Managerem - file://C:\Program Files\Free Download Manager\dlall.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Autodesk Data Management Job Dispatch - Autodesk - C:\Program Files\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
O23 - Service: Autodesk EDM Server - Autodesk - C:\Program Files\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files\Mouse Driver\KMWDSrv.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Správce úloh aplikace Autodesk Moldflow Inventor Tool Suite Integration 2011 (mitsijm2011) - Unknown owner - D:\Programy\Autodesk\Autodesk Inventor 2011\Moldflow\bin\mitsijm.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vfsFPService.exe

--
End of file - 10706 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-901558432-514748668-1761453714-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-901558432-514748668-1761453714-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08 202144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre6\bin\ssv.dll [2011-01-05 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
FDMIECookiesBHO Class - C:\Program Files\Free Download Manager\iefdm2.dll [2008-12-30 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-01-05 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21 509496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08 1619352]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-03-11 5296128]
"PLFSetI"=C:\Windows\PLFSetI.exe [2007-10-23 200704]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-01-18 1033512]
"ePower_DMC"=C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [2008-09-23 413696]
"LManager"=C:\PROGRA~1\LAUNCH~1\LManager.exe [2008-03-13 805384]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"KMCONFIG"=C:\Program Files\Mouse Driver\StartAutorun.exe [2007-03-06 212992]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"SearchSettings"=C:\Program Files\pdfforge Toolbar\SearchSettings.exe []
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-05-27 13781536]
"LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2006-04-13 49152]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-11-29 421888]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-10 932288]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2010-07-25 2569616]
"CanonSolutionMenuEx"=C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [2010-09-14 1213848]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2010-10-29 1352272]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Rainlendar2"=C:\Program Files\Rainlendar2\Rainlendar2.exe [2009-02-21 4333568]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2008-12-08 54576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2009-04-02 342312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2010-11-29 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2005-12-07 30208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TO2SSM_McciTrayApp]
C:\Program Files\TO2SSM\McciTrayApp.exe [2008-08-15 1473536]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2008-08-04 36352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\Hp\DIGITA~1\bin\hpqtra08.exe [2009-05-21 275768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^josef^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
C:\PROGRA~1\MICROS~1\Office12\ONENOTEM.EXE [2008-10-25 98696]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\_OTM\MovedFiles\05112011_222530\C_Users\josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Logitech . Registrace produktu.lnk - C:\Program Files\Common Files\Logishrd\eReg\SetPoint\eReg.exe
setup_9.0.0.722_10.05.2011_11-39.lnk - C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\startup.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll [2008-03-18 233888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\FlashGet Network\FlashGet universal\FlashGet.exe"="C:\Program Files\FlashGet Network\FlashGet universal\FlashGet.exe:*:Enabled:Flashget2"
"C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdate.exe"="C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdate.exe:*:Enabled:FGLiveUpdate"
"C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdateEx.exe"="C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdateEx.exe:*:Enabled:FGLiveUpdateEx"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit -
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2011-05-11 22:25:30 ----D---- C:\_OTM
2011-05-11 17:21:58 ----D---- C:\Users\josef\AppData\Roaming\Leadertech
2011-05-11 17:20:53 ----D---- C:\ProgramData\Logishrd
2011-05-11 17:20:51 ----D---- C:\Program Files\Logitech
2011-05-11 17:13:49 ----D---- C:\Program Files\Common Files\Logishrd
2011-05-11 17:11:42 ----D---- C:\Users\josef\AppData\Roaming\Logitech
2011-05-11 17:11:42 ----D---- C:\Users\josef\AppData\Roaming\Logishrd
2011-05-10 22:46:01 ----D---- C:\Program Files\trend micro
2011-05-10 22:46:00 ----D---- C:\rsit
2011-05-10 11:21:44 ----D---- C:\ProgramData\Kaspersky Lab
2011-05-10 11:20:42 ----A---- C:\Windows\system32\drivers\25645022.sys
2011-05-10 11:20:42 ----A---- C:\Windows\system32\drivers\25645021.sys
2011-05-10 11:20:42 ----A---- C:\Windows\system32\drivers\2564502.sys
2011-05-09 23:19:02 ----D---- C:\Windows\temp
2011-05-09 23:11:19 ----SHD---- C:\$RECYCLE.BIN
2011-05-09 18:28:24 ----D---- C:\Downloads
2011-05-09 16:31:07 ----D---- C:\cokoliv
2011-05-08 15:25:01 ----D---- C:\Users\josef\AppData\Roaming\Malwarebytes
2011-05-08 15:24:45 ----D---- C:\ProgramData\Malwarebytes
2011-05-08 15:24:45 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2011-05-08 15:24:42 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-05-08 15:24:42 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-05-08 14:32:59 ----ASH---- C:\hiberfil.sys
2011-05-08 12:42:15 ----D---- C:\ProgramData\fK32001NlLaL32001
2011-04-29 15:40:19 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-04-29 15:39:27 ----D---- C:\Program Files\DAEMON Tools Lite
2011-04-27 10:50:22 ----A---- C:\Windows\system32\Apphlpdm.dll
2011-04-27 10:50:21 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2011-04-27 10:50:18 ----A---- C:\Windows\system32\XpsPrint.dll
2011-04-21 19:27:17 ----HD---- C:\ProgramData\CanonIJScan
2011-04-21 19:27:16 ----D---- C:\Users\josef\AppData\Roaming\Canon
2011-04-13 08:52:31 ----A---- C:\Windows\system32\atmlib.dll
2011-04-13 08:52:31 ----A---- C:\Windows\system32\atmfd.dll
2011-04-13 08:52:29 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-04-13 08:52:28 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-04-13 08:52:28 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-04-13 08:52:28 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-04-13 08:52:23 ----A---- C:\Windows\system32\mfc42u.dll
2011-04-13 08:52:23 ----A---- C:\Windows\system32\mfc42.dll
2011-04-13 08:52:20 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-04-13 08:52:20 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-04-13 08:52:20 ----A---- C:\Windows\system32\drivers\srv.sys
2011-04-13 08:52:17 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-04-13 08:52:17 ----A---- C:\Windows\system32\dnscacheugc.exe
2011-04-13 08:52:17 ----A---- C:\Windows\system32\dnsapi.dll
2011-04-13 08:52:12 ----A---- C:\Windows\system32\mshtml.dll
2011-04-13 08:52:11 ----A---- C:\Windows\system32\urlmon.dll
2011-04-13 08:52:11 ----A---- C:\Windows\system32\mshtmled.dll
2011-04-13 08:52:10 ----A---- C:\Windows\system32\wininet.dll
2011-04-13 08:52:10 ----A---- C:\Windows\system32\ieframe.dll
2011-04-13 08:52:09 ----A---- C:\Windows\system32\mstime.dll
2011-04-13 08:52:09 ----A---- C:\Windows\system32\msfeeds.dll
2011-04-13 08:52:09 ----A---- C:\Windows\system32\iepeers.dll
2011-04-13 08:52:09 ----A---- C:\Windows\system32\ieencode.dll
2011-04-13 08:52:08 ----A---- C:\Windows\system32\ieapfltr.dll
2011-04-13 08:51:50 ----A---- C:\Windows\system32\win32k.sys
2011-04-13 08:51:48 ----A---- C:\Windows\system32\vbscript.dll
2011-04-13 08:51:48 ----A---- C:\Windows\system32\jscript.dll
2011-04-13 08:51:45 ----A---- C:\Windows\system32\inetcomm.dll
2011-04-12 19:17:25 ----HD---- C:\ProgramData\CanonIJEPPEX2
2011-04-12 19:17:25 ----HD---- C:\ProgramData\CanonEPP
2011-04-12 19:15:13 ----HD---- C:\ProgramData\CanonIJFAX
2011-04-12 19:10:26 ----D---- C:\Program Files\Common Files\CANON
2011-04-12 19:10:19 ----D---- C:\ProgramData\CanonIJWSpt
2011-04-12 19:06:25 ----HD---- C:\ProgramData\CanonBJ
2011-04-12 19:05:51 ----HD---- C:\Windows\system32\CanonIJ Uninstaller Information
2011-04-12 19:04:44 ----A---- C:\Windows\system32\CNHMCA.dll
2011-04-12 19:04:44 ----A---- C:\Windows\system32\CNC420U.dll
2011-04-12 19:04:44 ----A---- C:\Windows\system32\CNC420L.dll
2011-04-12 19:04:44 ----A---- C:\Windows\system32\CNC420I.dll
2011-04-12 19:04:44 ----A---- C:\Windows\system32\CNC420C.dll
2011-04-12 19:03:24 ----A---- C:\Windows\system32\CNMLMAM.DLL
2011-04-12 19:02:43 ----A---- C:\Windows\system32\CNCALAM.DLL
2011-04-12 19:02:37 ----A---- C:\Windows\system32\CNC420O.dll
2011-04-12 19:02:30 ----A---- C:\Windows\system32\CNMIUAM.DLL
2011-04-12 19:02:15 ----HD---- C:\Program Files\CanonBJ
2011-04-12 19:02:01 ----D---- C:\Windows\system32\STRING
2011-04-12 19:02:01 ----A---- C:\Windows\system32\CNMNPUI.DLL
2011-04-12 18:59:53 ----D---- C:\Program Files\Canon

======List of files/folders modified in the last 1 months======

2011-05-11 22:40:25 ----SHD---- C:\System Volume Information
2011-05-11 22:40:14 ----D---- C:\Windows\Prefetch
2011-05-11 22:38:52 ----D---- C:\Windows\system32\Tasks
2011-05-11 22:28:08 ----D---- C:\Windows\system32\drivers\etc
2011-05-11 22:27:19 ----RD---- C:\Program Files
2011-05-11 22:26:05 ----D---- C:\Windows\twain_32
2011-05-11 22:26:03 ----D---- C:\Windows\System32
2011-05-11 22:25:44 ----D---- C:\Windows
2011-05-11 18:20:24 ----D---- C:\Windows\winsxs
2011-05-11 18:04:38 ----SHD---- C:\Windows\Installer
2011-05-11 18:02:43 ----D---- C:\Windows\inf
2011-05-11 18:02:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-05-11 18:02:11 ----D---- C:\Windows\Debug
2011-05-11 18:02:09 ----A---- C:\Windows\system32\mrt.exe
2011-05-11 18:02:02 ----D---- C:\Windows\system32\catroot
2011-05-11 18:01:55 ----D---- C:\Program Files\Windows Mail
2011-05-11 17:21:58 ----D---- C:\Config.Msi
2011-05-11 17:20:53 ----D---- C:\ProgramData
2011-05-11 17:13:49 ----D---- C:\Program Files\Common Files
2011-05-10 22:29:26 ----D---- C:\Program Files\Mozilla Firefox
2011-05-10 22:24:47 ----D---- C:\Windows\system32\drivers
2011-05-10 21:52:28 ----D---- C:\Users\josef\AppData\Roaming\PrimoPDF
2011-05-10 10:52:32 ----D---- C:\Users\josef\AppData\Roaming\Free Download Manager
2011-05-10 10:52:30 ----D---- C:\Windows\Minidump
2011-05-09 23:11:07 ----A---- C:\Windows\system.ini
2011-05-09 23:09:37 ----D---- C:\Windows\system32\config
2011-05-09 23:05:15 ----D---- C:\Windows\AppPatch
2011-05-09 19:53:45 ----D---- C:\Users\josef\AppData\Roaming\GHISLER
2011-05-09 16:45:15 ----SD---- C:\Windows\Downloaded Program Files
2011-05-09 16:34:56 ----D---- C:\Windows\system32\catroot2
2011-05-09 16:28:31 ----D---- C:\Program Files\Common Files\Akamai
2011-05-09 16:26:43 ----D---- C:\ProgramData\avg8
2011-05-08 18:38:16 ----D---- C:\Users\josef\AppData\Roaming\Winamp
2011-05-08 18:38:16 ----D---- C:\Users\josef\AppData\Roaming\Media Player Classic
2011-05-08 18:38:15 ----D---- C:\Users\josef\AppData\Roaming\uTorrent
2011-05-08 18:38:15 ----D---- C:\Users\josef\AppData\Roaming\BitTorrent
2011-05-08 18:27:25 ----D---- C:\Program Files\CCleaner
2011-05-08 18:03:16 ----D---- C:\Windows\Provisioning
2011-05-05 09:20:13 ----D---- C:\$AVG8.VAULT$
2011-05-01 09:39:10 ----A---- C:\Windows\MAILTRAN.INI
2011-04-29 15:39:14 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-04-15 15:54:55 ----D---- C:\Windows\Microsoft.NET
2011-04-15 15:53:15 ----RSD---- C:\Windows\assembly
2011-04-12 19:13:35 ----RSD---- C:\Windows\Media

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 25645022;25645022 Boot Guard Driver; C:\Windows\system32\DRIVERS\25645022.sys [2009-10-22 37392]
R0 fvevol;BitLocker Drive Encryption Filter Driver; C:\Windows\System32\DRIVERS\fvevol.sys [2009-04-11 143848]
R0 giveio;giveio; C:\Windows\system32\giveio.sys [1996-04-03 5248]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2005-11-17 20640]
R0 speedfan;speedfan; C:\Windows\system32\speedfan.sys [2006-09-24 5248]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-06-07 721904]
R1 25645021;25645021; C:\Windows\system32\DRIVERS\25645021.sys [2009-09-25 128016]
R1 DritekPortIO;Dritek General Port I/O; \??\C:\PROGRA~1\LAUNCH~1\DPortIO.sys [2006-11-02 20112]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-04-29 218688]
R1 setup_9.0.0.722_10.05.2011_11-39drv;setup_9.0.0.722_10.05.2011_11-39drv; C:\Windows\system32\DRIVERS\2564502.sys [2009-10-09 311312]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2009-10-30 229208]
R2 cvintdrv;cvintdrv; C:\Windows\system32\drivers\cvintdrv.sys [2007-02-21 4096]
R2 Int15;int15; \??\C:\Windows\System32\drivers\int15.sys [2008-08-19 15392]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
R3 i8042HDR;Keyboard Filter Driver; C:\Windows\system32\DRIVERS\i8042HDR.sys [2006-10-20 13224]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-03-11 2077080]
R3 itecir;ITECIR Infrared Receiver; C:\Windows\system32\DRIVERS\itecir.sys [2007-12-18 54784]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1E60x86.sys [2009-08-05 48640]
R3 NETw4v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-09-26 2251776]
R3 NfsRdr;@%windir%\system32\nfsrc.dll,-5003; C:\Windows\system32\drivers\nfsrdr.sys [2009-04-10 195584]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-05-27 9850240]
R3 RpcXdr;@%windir%\system32\nfsrc.dll,-5011; C:\Windows\system32\drivers\rpcxdr.sys [2009-04-10 76800]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-01-18 196784]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 vfs101x;vfs101x; C:\Windows\system32\drivers\vfs101x.sys [2008-02-15 40752]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 59280]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-10 22528]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-04-10 507904]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-10 29696]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2007-03-30 79664]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2007-02-27 81200]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-02-27 16432]
S3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2006-11-02 21264]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2008-03-13 80912]
S3 KMWDFilter;KMWDFilter; \??\C:\Windows\System32\Drivers\KMWDFilter.SYS [2008-03-22 17024]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2008-03-29 21248]
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2008-03-29 20096]
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NPF;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2005-08-02 32512]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver; \??\C:\Windows\system32\NSNDIS5.SYS [2004-03-24 17280]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-10 148992]
S3 RT73;RT73 USB Wireless LAN Card Driver; C:\Windows\system32\DRIVERS\rt73.sys []
S3 s115bus;Sony Ericsson Device 115 driver (WDM); C:\Windows\system32\DRIVERS\s115bus.sys [2007-04-23 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s115mdfl.sys [2007-04-23 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s115mdm.sys [2007-04-23 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s115mgmt.sys [2007-04-23 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s115obex.sys [2007-04-23 98568]
S3 TVICHW32;TVICHW32; \??\C:\Windows\system32\DRIVERS\TVICHW32.SYS [2009-05-28 23600]
S3 USBNUMP;USBNUMP; C:\Windows\system32\DRIVERS\USBNUMP.sys [2006-10-20 10760]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-10-16 37664]
R2 Autodesk Data Management Job Dispatch;Autodesk Data Management Job Dispatch; C:\Program Files\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe [2008-02-18 32768]
R2 Autodesk EDM Server;Autodesk EDM Server; C:\Program Files\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe [2008-02-18 57344]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-10-07 345376]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-08-19 24576]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2008-01-09 823296]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 KMWDSERVICE;Keyboard And Mouse Communication Service; C:\Program Files\Mouse Driver\KMWDSrv.exe [2008-03-28 208896]
R2 LPDSVC;@%systemroot%\system32\lpdsvc.dll,-500; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 McciCMService;McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [2007-10-15 303104]
R2 mitsijm2011;Správce úloh aplikace Autodesk Moldflow Inventor Tool Suite Integration 2011; D:\Programy\Autodesk\Autodesk Inventor 2011\Moldflow\bin\mitsijm.exe [2010-01-23 462336]
R2 MobilityService;MobilityService; C:\Acer\Mobility Center\MobilityService.exe [2007-12-06 110592]
R2 MSSQL$AUTODESKVAULT;SQL Server (AUTODESKVAULT); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-11-24 29263712]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 NfsClnt;@%windir%\system32\nfsrc.dll,-5001; C:\Windows\system32\nfsclnt.exe [2009-04-11 50688]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-05-27 211488]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2008-01-09 483328]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2005-08-08 167936]
R2 simptcp;@%SystemRoot%\system32\simptcp.dll,-200; C:\Windows\System32\tcpsvcs.exe [2009-08-14 9728]
R2 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
R2 vfsFPService;Validity Fingerprint Service; C:\Windows\system32\vfsFPService.exe [2008-02-15 595248]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2009-05-04 85096]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-08-13 1045256]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-04-02 656168]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2010-10-28 293456]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2005-08-02 86016]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Vir MS Removal Tool

#19 Příspěvek od motji »

:arrow:Otevřete znovu Otm a klikněte na tlačítko CleanUp,potvrďte ok


Pokud nejsou problémy, je to vše.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Fers
Návštěvník
Návštěvník
Příspěvky: 22
Registrován: 28 Lis 2005 15:10
Kontaktovat uživatele:

Re: Vir MS Removal Tool

#20 Příspěvek od Fers »

Dobře, děkuji mnohokrát za pomoc :worship:

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Vir MS Removal Tool

#21 Příspěvek od motji »

Není zač :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět