Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

preventivka pro Chodnik74

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Kuba55
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 03 čer 2011 19:33

preventivka pro Chodnik74

#1 Příspěvek od Kuba55 »

tady je log :) pls o kontrolu kamo


Logfile of random's system information tool 1.08 (written by random/random)
Run by Kuba at 2011-06-03 20:37:21
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 247 GB (52%) free of 477 GB
Total RAM: 3071 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:37:32, on 3.6.2011
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.19048)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Windows\PixArt\Pac207\Monitor.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Kuba\Desktop\RSIT.exe
C:\Program Files\trend micro\Kuba.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60341
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mydtzone.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (file missing)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [RemoteControl11] "C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (file missing)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS3\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS4\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS5\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS6\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS7\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS8\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS9\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS10\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: CLHNServiceForPowerDVD - Unknown owner - C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
O23 - Service: CyberLink PowerDVD 11.0 Monitor Service - CyberLink - C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
O23 - Service: CyberLink PowerDVD 11.0 Service - CyberLink - C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: Služba Google Update (gupdate1c9ea00b4bac978) (gupdate1c9ea00b4bac978) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (file missing)
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (file missing)
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Unknown owner - C:\Program Files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ServiceLayer - Unknown owner - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 13687 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\User_Feed_Synchronization-{117EE415-AC59-4170-8EB9-1FFA8FC45375}.job
C:\Windows\tasks\User_Feed_Synchronization-{9B42D2DF-3071-4FBD-B856-79594C08C035}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-15 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-01-28 1230288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll [2011-05-26 1007160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2011-04-21 1000768]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll []
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-01-28 1230288]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2008-09-24 6335008]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2007-03-14 71216]
"LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD\Language\Language.exe []
"LGODDFU"=C:\Program Files\lg_fwupdate\fwupdate.exe blrun []
"SecurDisc"=C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe [2008-02-18 1629480]
"InCD"=C:\Program Files\Nero\Nero 7\InCD\InCD.exe [2008-02-18 1057064]
"Monitor"=C:\Windows\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"ArcSoft Connection Service"=C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2007-07-03 64000]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"NPSStartup"= []
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-02-23 3451496]
"RemoteControl11"=C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe [2011-04-20 234792]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2010-11-15 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-11-29 421888]
"NvSvc"=C:\Windows\system32\nvsvc.dll [2007-12-05 86016]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2007-12-05 8530464]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2007-12-05 81920]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-21 1233920]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-06-17 2363392]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-06-10 39408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-12-29 687560]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-03-18 2166784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^ExifLauncher2.lnk]
C:\PROGRA~1\FINEPI~1\QUICKD~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Remote Control.lnk]
C:\PROGRA~1\KWORLD~1\TVTUNE~1\HMCP3X~1.EXE []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
Nikon Monitor.lnk - C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2011-06-03 20:37:22 ----D---- C:\Program Files\trend micro
2011-06-03 20:37:21 ----D---- C:\rsit
2011-06-03 20:20:10 ----D---- C:\Program Files\Microsoft Sync Framework
2011-06-03 20:19:53 ----D---- C:\Program Files\Microsoft
2011-06-03 20:19:17 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2011-06-03 20:18:46 ----D---- C:\Program Files\Windows Live SkyDrive
2011-06-03 20:18:30 ----D---- C:\Program Files\Windows Live
2011-06-03 20:14:38 ----A---- C:\Windows\system32\nvexpbar.dll
2011-06-03 20:14:17 ----D---- C:\Windows\LastGood.Tmp
2011-06-03 13:50:53 ----D---- C:\531fa313e61102992eb7ab72
2011-06-03 13:49:52 ----A---- C:\Windows\system32\mshtml.dll
2011-06-03 13:49:51 ----A---- C:\Windows\system32\wininet.dll
2011-06-03 13:49:51 ----A---- C:\Windows\system32\urlmon.dll
2011-06-03 13:49:51 ----A---- C:\Windows\system32\ieframe.dll
2011-06-03 13:49:48 ----A---- C:\Windows\system32\mstime.dll
2011-06-03 13:49:48 ----A---- C:\Windows\system32\msfeeds.dll
2011-06-03 13:49:48 ----A---- C:\Windows\system32\iertutil.dll
2011-06-03 13:49:48 ----A---- C:\Windows\system32\iedkcs32.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\occache.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\mshtmled.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\licmgr10.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\jsproxy.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\ieUnatt.exe
2011-06-03 13:49:47 ----A---- C:\Windows\system32\ieui.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\iesysprep.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\iesetup.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\iernonce.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\iepeers.dll
2011-06-03 13:49:45 ----A---- C:\Windows\system32\msfeedssync.exe
2011-06-03 13:49:45 ----A---- C:\Windows\system32\ie4uinit.exe
2011-06-03 13:49:39 ----A---- C:\Windows\system32\vbscript.dll
2011-06-03 13:49:39 ----A---- C:\Windows\system32\jscript.dll
2011-06-03 12:53:00 ----A---- C:\Windows\system32\msls31.dll
2011-06-03 12:53:00 ----A---- C:\Windows\system32\mshtmler.dll
2011-06-03 12:53:00 ----A---- C:\Windows\system32\icardie.dll
2011-06-03 12:53:00 ----A---- C:\Windows\system32\corpol.dll
2011-06-03 12:53:00 ----A---- C:\Windows\system32\admparse.dll
2011-06-03 12:52:59 ----A---- C:\Windows\system32\inseng.dll
2011-06-03 12:52:59 ----A---- C:\Windows\system32\imgutil.dll
2011-06-03 12:52:59 ----A---- C:\Windows\system32\ieakeng.dll
2011-06-03 12:52:59 ----A---- C:\Windows\system32\dxtrans.dll
2011-06-03 12:52:59 ----A---- C:\Windows\system32\dxtmsft.dll
2011-06-03 12:52:58 ----A---- C:\Windows\system32\WinFXDocObj.exe
2011-06-03 12:52:58 ----A---- C:\Windows\system32\wextract.exe
2011-06-03 12:52:58 ----A---- C:\Windows\system32\webcheck.dll
2011-06-03 12:52:58 ----A---- C:\Windows\system32\msrating.dll
2011-06-03 12:52:58 ----A---- C:\Windows\system32\ieakui.dll
2011-06-03 12:52:58 ----A---- C:\Windows\system32\ieaksie.dll
2011-06-03 12:52:57 ----A---- C:\Windows\system32\url.dll
2011-06-03 12:52:57 ----A---- C:\Windows\system32\pngfilt.dll
2011-06-03 12:52:57 ----A---- C:\Windows\system32\ieapfltr.dll
2011-06-03 12:52:57 ----A---- C:\Windows\system32\advpack.dll
2011-06-03 12:52:56 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-06-03 12:52:56 ----A---- C:\Windows\system32\SetDepNx.exe
2011-06-03 12:52:56 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-06-03 12:52:56 ----A---- C:\Windows\system32\PDMSetup.exe
2011-06-03 12:52:56 ----A---- C:\Windows\system32\mshta.exe
2011-06-03 12:52:56 ----A---- C:\Windows\system32\iexpress.exe
2011-06-02 19:32:08 ----D---- C:\Program Files\Common Files\Windows Live
2011-06-01 21:19:51 ----D---- C:\Users\Kuba\AppData\Roaming\Nikon
2011-06-01 21:16:36 ----D---- C:\Program Files\Common Files\muvee Technologies
2011-06-01 21:16:32 ----D---- C:\ProgramData\Nikon
2011-06-01 21:16:29 ----D---- C:\Program Files\Nikon
2011-06-01 19:37:46 ----D---- C:\Program Files\Ubisoft
2011-06-01 19:36:58 ----D---- C:\Users\Kuba\AppData\Roaming\Nero
2011-05-31 21:29:44 ----ASH---- C:\hiberfil.sys
2011-05-31 19:37:24 ----D---- C:\ProgramData\page
2011-05-30 19:27:21 ----D---- C:\Users\Kuba\AppData\Roaming\Ashampoo
2011-05-30 19:26:54 ----D---- C:\ProgramData\ashampoo
2011-05-30 19:26:42 ----D---- C:\Program Files\Ashampoo
2011-05-29 21:10:29 ----D---- C:\Program Files\FlatOut2
2011-05-29 20:29:21 ----D---- C:\Program Files\Common Files\LightScribe
2011-05-29 20:14:30 ----A---- C:\Windows\system32\msimsg.dll
2011-05-29 20:14:30 ----A---- C:\Windows\system32\msihnd.dll
2011-05-29 20:14:30 ----A---- C:\Windows\system32\msiexec.exe
2011-05-29 20:14:30 ----A---- C:\Windows\system32\msi.dll
2011-05-29 19:44:19 ----D---- C:\Program Files\DivX
2011-05-28 11:49:22 ----D---- C:\ProgramData\Apple Computer
2011-05-28 11:49:22 ----D---- C:\Program Files\QuickTime
2011-05-28 11:47:28 ----D---- C:\Program Files\Common Files\Apple
2011-05-28 11:47:14 ----D---- C:\Program Files\Apple Software Update
2011-05-28 11:47:13 ----D---- C:\ProgramData\Apple
2011-05-27 22:44:46 ----D---- C:\Program Files\Adobe
2011-05-27 22:36:53 ----D---- C:\ProgramData\PDVD
2011-05-27 22:33:46 ----D---- C:\ProgramData\Temp
2011-05-27 22:33:45 ----D---- C:\ProgramData\install_clap
2011-05-27 22:02:31 ----D---- C:\ProgramData\Skype Extras
2011-05-27 22:01:10 ----D---- C:\Program Files\Common Files\Skype
2011-05-27 21:44:12 ----D---- C:\Program Files\Common Files\DESIGNER
2011-05-27 21:43:58 ----D---- C:\Program Files\Microsoft Visual Studio
2011-05-27 21:23:28 ----D---- C:\Program Files\game
2011-05-27 21:23:28 ----D---- C:\Program Files\air
2011-05-27 21:09:59 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-05-27 21:09:58 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-05-27 21:09:57 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-05-17 21:01:20 ----D---- C:\Users\Kuba\AppData\Roaming\WinRAR

======List of files/folders modified in the last 1 months======

2011-06-03 20:37:29 ----D---- C:\Windows\Temp
2011-06-03 20:37:22 ----RD---- C:\Program Files
2011-06-03 20:31:56 ----SHD---- C:\System Volume Information
2011-06-03 20:27:33 ----SHD---- C:\Config.Msi
2011-06-03 20:27:33 ----D---- C:\Windows
2011-06-03 20:27:33 ----AD---- C:\Windows\System32
2011-06-03 20:21:21 ----SHD---- C:\Windows\Installer
2011-06-03 20:21:05 ----D---- C:\Windows\winsxs
2011-06-03 20:19:53 ----SD---- C:\ProgramData\Microsoft
2011-06-03 20:19:18 ----RSD---- C:\Windows\assembly
2011-06-03 20:18:52 ----SD---- C:\Users\Kuba\AppData\Roaming\Microsoft
2011-06-03 20:18:52 ----D---- C:\Program Files\Common Files\microsoft shared
2011-06-03 20:14:38 ----D---- C:\ProgramData\NVIDIA
2011-06-03 20:14:26 ----AD---- C:\Windows\system32\drivers
2011-06-03 20:14:25 ----D---- C:\Windows\system32\catroot
2011-06-03 20:14:17 ----D---- C:\Windows\inf
2011-06-03 19:08:56 ----D---- C:\Windows\system32\migration
2011-06-03 19:08:56 ----D---- C:\Program Files\Internet Explorer
2011-06-03 13:49:15 ----D---- C:\Windows\system32\catroot2
2011-06-03 13:18:54 ----D---- C:\Windows\rescache
2011-06-03 12:55:57 ----D---- C:\Windows\system32\en-US
2011-06-03 12:55:57 ----D---- C:\Windows\system32\cs-CZ
2011-06-03 12:55:57 ----D---- C:\Windows\PolicyDefinitions
2011-06-03 12:32:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-06-03 12:25:43 ----D---- C:\Program Files\WinRAR
2011-06-02 19:32:08 ----D---- C:\Program Files\Common Files
2011-06-01 21:16:34 ----D---- C:\Program Files\Common Files\Nikon
2011-06-01 21:16:32 ----HD---- C:\ProgramData
2011-06-01 21:16:03 ----A---- C:\Windows\system32\ATL71.DLL
2011-06-01 20:15:42 ----D---- C:\Program Files\Nero
2011-05-29 20:18:25 ----D---- C:\Windows\system32\zh-TW
2011-05-29 20:18:25 ----D---- C:\Windows\system32\uk-UA
2011-05-29 20:18:25 ----D---- C:\Windows\system32\tr-TR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\th-TH
2011-05-29 20:18:25 ----D---- C:\Windows\system32\sv-SE
2011-05-29 20:18:25 ----D---- C:\Windows\system32\sr-Latn-CS
2011-05-29 20:18:25 ----D---- C:\Windows\system32\sl-SI
2011-05-29 20:18:25 ----D---- C:\Windows\system32\sk-SK
2011-05-29 20:18:25 ----D---- C:\Windows\system32\pt-PT
2011-05-29 20:18:25 ----D---- C:\Windows\system32\pt-BR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\pl-PL
2011-05-29 20:18:25 ----D---- C:\Windows\system32\nl-NL
2011-05-29 20:18:25 ----D---- C:\Windows\system32\lv-LV
2011-05-29 20:18:25 ----D---- C:\Windows\system32\lt-LT
2011-05-29 20:18:25 ----D---- C:\Windows\system32\ko-KR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\it-IT
2011-05-29 20:18:25 ----D---- C:\Windows\system32\hu-HU
2011-05-29 20:18:25 ----D---- C:\Windows\system32\hr-HR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\he-IL
2011-05-29 20:18:25 ----D---- C:\Windows\system32\fr-FR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\fi-FI
2011-05-29 20:18:25 ----D---- C:\Windows\system32\et-EE
2011-05-29 20:18:25 ----D---- C:\Windows\system32\es-ES
2011-05-29 20:18:25 ----D---- C:\Windows\system32\el-GR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\de-DE
2011-05-29 20:18:25 ----D---- C:\Windows\system32\bg-BG
2011-05-29 20:18:24 ----D---- C:\Windows\system32\zh-CN
2011-05-29 20:18:24 ----D---- C:\Windows\system32\ru-RU
2011-05-29 20:18:24 ----D---- C:\Windows\system32\ro-RO
2011-05-29 20:18:24 ----D---- C:\Windows\system32\nb-NO
2011-05-29 20:18:24 ----D---- C:\Windows\system32\ja-JP
2011-05-29 20:18:24 ----D---- C:\Windows\system32\da-DK
2011-05-29 20:18:24 ----D---- C:\Windows\system32\ar-SA
2011-05-29 20:13:44 ----D---- C:\Windows\SoftwareDistribution
2011-05-29 20:09:50 ----D---- C:\Program Files\DAEMON Tools Toolbar
2011-05-29 20:09:50 ----D---- C:\Program Files\DAEMON Tools Lite
2011-05-29 20:09:04 ----D---- C:\Program Files\K-Lite Codec Pack
2011-05-29 20:04:31 ----A---- C:\Windows\Codec Pack - All In 1 Setup Log.txt
2011-05-29 19:39:30 ----D---- C:\Program Files\Microsoft Silverlight
2011-05-29 19:35:43 ----D---- C:\ProgramData\Adobe
2011-05-28 12:05:34 ----D---- C:\Users\Kuba\AppData\Roaming\Adobe
2011-05-28 11:47:16 ----D---- C:\Windows\system32\Tasks
2011-05-27 22:45:04 ----D---- C:\Program Files\Common Files\Adobe
2011-05-27 22:41:16 ----D---- C:\Users\Kuba\AppData\Roaming\CyberLink
2011-05-27 22:41:16 ----D---- C:\ProgramData\Cyberlink
2011-05-27 22:35:10 ----D---- C:\Program Files\CyberLink
2011-05-27 22:34:55 ----D---- C:\Windows\Prefetch
2011-05-27 22:33:45 ----HD---- C:\Program Files\InstallShield Installation Information
2011-05-27 22:13:04 ----D---- C:\Users\Kuba\AppData\Roaming\Skype
2011-05-27 22:07:59 ----D---- C:\Program Files\Mozilla Firefox
2011-05-27 22:07:15 ----D---- C:\Program Files\Spyware Terminator
2011-05-27 22:02:52 ----D---- C:\Users\Kuba\AppData\Roaming\skypePM
2011-05-27 22:01:10 ----RD---- C:\Program Files\Skype
2011-05-27 22:01:04 ----D---- C:\ProgramData\Skype
2011-05-27 21:58:24 ----D---- C:\Program Files\Electronic Arts
2011-05-27 21:47:21 ----D---- C:\ProgramData\Microsoft Help
2011-05-27 21:46:57 ----A---- C:\Windows\win.ini
2011-05-27 21:44:13 ----D---- C:\Program Files\Microsoft Office
2011-05-27 21:44:12 ----D---- C:\Program Files\Microsoft Works
2011-05-27 21:44:09 ----D---- C:\Program Files\MSBuild
2011-05-27 21:27:44 ----D---- C:\Program Files\Đ»đ¸ßÇĺµçÓ°
2011-05-27 21:27:30 ----D---- C:\Program Files\Windows Media Player
2011-05-27 21:27:30 ----D---- C:\Program Files\WinClamAVShield
2011-05-27 21:27:30 ----D---- C:\Program Files\Webcam 1200
2011-05-27 21:26:02 ----D---- C:\Program Files\Testy Autoškola
2011-05-27 21:26:02 ----D---- C:\Program Files\Temp
2011-05-27 21:25:52 ----D---- C:\Program Files\PC Connectivity Solution
2011-05-27 21:25:45 ----D---- C:\Program Files\Mumble
2011-05-27 21:25:44 ----D---- C:\Program Files\Movies
2011-05-27 21:25:31 ----D---- C:\Program Files\McAfee Security Scan
2011-05-27 21:25:31 ----D---- C:\Program Files\lg_fwupdate
2011-05-27 21:25:31 ----D---- C:\Program Files\LANGMaster Škola DNES
2011-05-27 21:25:30 ----D---- C:\Program Files\ICQ6Toolbar
2011-05-27 21:25:08 ----D---- C:\Program Files\ICQ6.5
2011-05-27 21:25:07 ----D---- C:\Program Files\HELP
2011-05-27 21:24:56 ----D---- C:\Program Files\Fraps
2011-05-27 21:24:55 ----D---- C:\Program Files\FinePixViewer
2011-05-27 21:24:55 ----D---- C:\Program Files\FelixNET_Demo
2011-05-27 21:23:55 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2011-05-27 21:23:54 ----D---- C:\Program Files\Common Files\Services
2011-05-27 21:23:52 ----D---- C:\Program Files\Common Files\GraphBoard 2.50
2011-05-27 21:23:46 ----D---- C:\Program Files\CCleaner
2011-05-27 21:23:43 ----D---- C:\Program Files\AGEIA Technologies
2011-05-27 21:23:34 ----D---- C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
2011-05-27 20:40:21 ----D---- C:\ProgramData\Spyware Terminator
2011-05-27 20:36:32 ----D---- C:\Windows\Tasks
2011-05-27 20:34:48 ----D---- C:\Users\Kuba\AppData\Roaming\Spyware Terminator
2011-05-26 20:25:29 ----D---- C:\Users\Kuba\AppData\Roaming\Mumble
2011-05-24 22:23:03 ----RD---- C:\Users
2011-05-14 12:26:28 ----RSD---- C:\Windows\Fonts
2011-05-14 12:24:29 ----D---- C:\Program Files\Common Files\System
2011-05-10 22:14:51 ----A---- C:\Windows\system32\mrt.exe
2011-05-10 22:14:38 ----D---- C:\Program Files\Windows Mail

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2008-12-25 717296]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-02-23 25432]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-02-23 371544]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-02-23 301528]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-02-23 49240]
R1 InCDPass;Nero InCDPass; C:\Windows\system32\drivers\InCDPass.sys [2008-02-18 36648]
R1 incdrm;Nero InCD MRW Remapper; C:\Windows\system32\drivers\InCDRm.sys [2008-02-18 38312]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\Windows\system32\drivers\sp_rsdrv2.sys [2010-03-18 142592]
R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2011/05/27 22:36:39]; \??\C:\Program Files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [2011-04-12 77296]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-02-23 19544]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-02-23 53592]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-12-28 278728]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-12-28 25416]
R2 ntk_PowerDVD;ntk_PowerDVD; \??\C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys [2011-04-20 71664]
R3 3xHybrid;3xHybrid service; C:\Windows\system32\DRIVERS\3xHybrid.sys [2007-04-20 674048]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-09-24 2171672]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-12-05 8238720]
R3 PAC207;Webcam 1200; C:\Windows\system32\DRIVERS\PFC027.SYS [2007-06-29 611584]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-02 44544]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
R4 InCDfs;Nero InCD File System; C:\Windows\system32\drivers\InCDFs.sys [2008-02-18 118952]
S3 a80jkr8k;a80jkr8k; C:\Windows\system32\drivers\a80jkr8k.sys []
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2011-02-07 483200]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 EagleNT;EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys []
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 GMSIPCI;GMSIPCI; \??\H:\INSTALL\GMSIPCI.SYS []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-05-11 25280]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm60x32.sys [2006-11-02 429056]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-02-23 42184]
R2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
R2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
R2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
R2 FsUsbExService;FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [2009-03-31 233472]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2008-10-19 222456]
R2 InCDsrv;InCD Helper; C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe [2008-02-18 1553704]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-06-17 73728]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-09-17 196608]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-12-18 66872]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-05-14 272024]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-03-18 488960]
S1 InCDrec;Nero InCD File System Recognizer; C:\Windows\system32\drivers\InCDRec.sys [2008-02-18 16040]
S2 gupdate1c9ea00b4bac978;Služba Google Update (gupdate1c9ea00b4bac978); C:\Program Files\Google\Update\GoogleUpdate.exe /svc []
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S2 NeroRegInCDSrv;Nero Registry InCD Service; C:\Program Files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe []
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-27 34312]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe /medsvc []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe []
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe []
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe []
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []

-----------------EOF-----------------

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: preventivka pro Chodnik74

#2 Příspěvek od chodnik74 »

Zdarec :welcome:
:arrow:Log vypadá čistý ;-) na pár drobností..
:arrow: Odinstalujte všechny toolbary,především ICQ toolbar + AVG Safe Search
:arrow: Co je obsahem této složky? C:\Program Files\Đ»đ¸ßÇĺµçÓ°


:arrow: Pokud budete chtít,mohu vám povypínat zbytečné programy a služby po startu počítače Obrázek
  • Urychlíme tím start systému
  • Uvolníme místo v RAM paměti
  • Nebude nás nic rušit a vytěžovat PC při práci
    :idea: Zde potřebuji vědět,zda na některých programech po startu trváte(například někdo má schválně spuštěné po startu ICQ,skype..nějaký prezentační program atd..)
Po splnění všechno bych poprosil nový log :)
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Kuba55
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 03 čer 2011 19:33

Re: preventivka pro Chodnik74

#3 Příspěvek od Kuba55 »

Děkuji ti mam teda další prosbu (nebo prosby)
1. Kde odinstaluju ty toolbary
2. tato slozka C:\Program Files\Đ»đ¸ßÇĺµçÓ° v PC ji nemohu najit takze ti neřeknu co je obsahem

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: preventivka pro Chodnik74

#4 Příspěvek od chodnik74 »

1) Ovládací panely - Přidat odebrat programy ;-)
2) :arrow: Stáhneme a spustíme SystemLook

http://jpshortstuff.247fixes.com/SystemLook.exe

Do okna vložíme následující script a stiskneme tlačítko Look

Kód: Vybrat vše

:dir
C:\Program Files\Đ»đ¸ßÇĺµçÓ° /s
:arrow: Po dokončení se nám otevře log,který mi zkopírujte sem
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Kuba55
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 03 čer 2011 19:33

Re: preventivka pro Chodnik74

#5 Příspěvek od Kuba55 »

takze Toolbary sem oddelal teda myslim az na ten
AVG Safe Search

ten sem nemohl najit neni tam a tady je ten log pro C:\Program Files\Đ»đ¸ßÇĺµçÓ°

SystemLook 04.09.10 by jpshortstuff
Log created at 21:15 on 03/06/2011 by Kuba
Administrator - Elevation successful

========== dir ==========

C:\Program Files\Đ»đ¸ßÇĺµçÓ° - Parameters: "/s"

---Files---
None found.

No folders found.

-= EOF =-

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: preventivka pro Chodnik74

#6 Příspěvek od chodnik74 »

Výborně..poprosím nový log z RSIT ;-)
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Kuba55
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 03 čer 2011 19:33

Re: preventivka pro Chodnik74

#7 Příspěvek od Kuba55 »

tady je ten log

Logfile of random's system information tool 1.08 (written by random/random)
Run by Kuba at 2011-06-03 21:24:13
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 245 GB (51%) free of 477 GB
Total RAM: 3071 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:24:17, on 3.6.2011
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.19048)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Windows\PixArt\Pac207\Monitor.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Kuba\Desktop\SystemLook.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\taskeng.exe
C:\Users\Kuba\Desktop\RSIT.exe
C:\Program Files\trend micro\Kuba.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60341
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mydtzone.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (file missing)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [RemoteControl11] "C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (file missing)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS3\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS4\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS5\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS6\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS7\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS8\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS9\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS10\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: CLHNServiceForPowerDVD - Unknown owner - C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
O23 - Service: CyberLink PowerDVD 11.0 Monitor Service - CyberLink - C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
O23 - Service: CyberLink PowerDVD 11.0 Service - CyberLink - C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: Služba Google Update (gupdate1c9ea00b4bac978) (gupdate1c9ea00b4bac978) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (file missing)
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (file missing)
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Unknown owner - C:\Program Files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ServiceLayer - Unknown owner - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 13551 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\User_Feed_Synchronization-{117EE415-AC59-4170-8EB9-1FFA8FC45375}.job
C:\Windows\tasks\User_Feed_Synchronization-{9B42D2DF-3071-4FBD-B856-79594C08C035}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-15 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-01-28 1230288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll [2011-05-26 1007160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll []
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-01-28 1230288]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2008-09-24 6335008]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2007-03-14 71216]
"LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD\Language\Language.exe []
"LGODDFU"=C:\Program Files\lg_fwupdate\fwupdate.exe blrun []
"SecurDisc"=C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe [2008-02-18 1629480]
"InCD"=C:\Program Files\Nero\Nero 7\InCD\InCD.exe [2008-02-18 1057064]
"Monitor"=C:\Windows\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"ArcSoft Connection Service"=C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2007-07-03 64000]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"NPSStartup"= []
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-02-23 3451496]
"RemoteControl11"=C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe [2011-04-20 234792]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2010-11-15 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-11-29 421888]
"NvSvc"=C:\Windows\system32\nvsvc.dll [2007-12-05 86016]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2007-12-05 8530464]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2007-12-05 81920]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-21 1233920]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-06-17 2363392]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-06-10 39408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-12-29 687560]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-03-18 2166784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^ExifLauncher2.lnk]
C:\PROGRA~1\FINEPI~1\QUICKD~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Remote Control.lnk]
C:\PROGRA~1\KWORLD~1\TVTUNE~1\HMCP3X~1.EXE []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
Nikon Monitor.lnk - C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2011-06-03 20:37:22 ----D---- C:\Program Files\trend micro
2011-06-03 20:37:21 ----D---- C:\rsit
2011-06-03 20:20:10 ----D---- C:\Program Files\Microsoft Sync Framework
2011-06-03 20:19:53 ----D---- C:\Program Files\Microsoft
2011-06-03 20:19:17 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2011-06-03 20:18:46 ----D---- C:\Program Files\Windows Live SkyDrive
2011-06-03 20:18:30 ----D---- C:\Program Files\Windows Live
2011-06-03 20:14:38 ----A---- C:\Windows\system32\nvexpbar.dll
2011-06-03 20:14:17 ----D---- C:\Windows\LastGood.Tmp
2011-06-03 13:50:53 ----D---- C:\531fa313e61102992eb7ab72
2011-06-03 13:49:52 ----A---- C:\Windows\system32\mshtml.dll
2011-06-03 13:49:51 ----A---- C:\Windows\system32\wininet.dll
2011-06-03 13:49:51 ----A---- C:\Windows\system32\urlmon.dll
2011-06-03 13:49:51 ----A---- C:\Windows\system32\ieframe.dll
2011-06-03 13:49:48 ----A---- C:\Windows\system32\mstime.dll
2011-06-03 13:49:48 ----A---- C:\Windows\system32\msfeeds.dll
2011-06-03 13:49:48 ----A---- C:\Windows\system32\iertutil.dll
2011-06-03 13:49:48 ----A---- C:\Windows\system32\iedkcs32.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\occache.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\mshtmled.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\licmgr10.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\jsproxy.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\ieUnatt.exe
2011-06-03 13:49:47 ----A---- C:\Windows\system32\ieui.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\iesysprep.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\iesetup.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\iernonce.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\iepeers.dll
2011-06-03 13:49:45 ----A---- C:\Windows\system32\msfeedssync.exe
2011-06-03 13:49:45 ----A---- C:\Windows\system32\ie4uinit.exe
2011-06-03 13:49:39 ----A---- C:\Windows\system32\vbscript.dll
2011-06-03 13:49:39 ----A---- C:\Windows\system32\jscript.dll
2011-06-03 12:53:00 ----A---- C:\Windows\system32\msls31.dll
2011-06-03 12:53:00 ----A---- C:\Windows\system32\mshtmler.dll
2011-06-03 12:53:00 ----A---- C:\Windows\system32\icardie.dll
2011-06-03 12:53:00 ----A---- C:\Windows\system32\corpol.dll
2011-06-03 12:53:00 ----A---- C:\Windows\system32\admparse.dll
2011-06-03 12:52:59 ----A---- C:\Windows\system32\inseng.dll
2011-06-03 12:52:59 ----A---- C:\Windows\system32\imgutil.dll
2011-06-03 12:52:59 ----A---- C:\Windows\system32\ieakeng.dll
2011-06-03 12:52:59 ----A---- C:\Windows\system32\dxtrans.dll
2011-06-03 12:52:59 ----A---- C:\Windows\system32\dxtmsft.dll
2011-06-03 12:52:58 ----A---- C:\Windows\system32\WinFXDocObj.exe
2011-06-03 12:52:58 ----A---- C:\Windows\system32\wextract.exe
2011-06-03 12:52:58 ----A---- C:\Windows\system32\webcheck.dll
2011-06-03 12:52:58 ----A---- C:\Windows\system32\msrating.dll
2011-06-03 12:52:58 ----A---- C:\Windows\system32\ieakui.dll
2011-06-03 12:52:58 ----A---- C:\Windows\system32\ieaksie.dll
2011-06-03 12:52:57 ----A---- C:\Windows\system32\url.dll
2011-06-03 12:52:57 ----A---- C:\Windows\system32\pngfilt.dll
2011-06-03 12:52:57 ----A---- C:\Windows\system32\ieapfltr.dll
2011-06-03 12:52:57 ----A---- C:\Windows\system32\advpack.dll
2011-06-03 12:52:56 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-06-03 12:52:56 ----A---- C:\Windows\system32\SetDepNx.exe
2011-06-03 12:52:56 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-06-03 12:52:56 ----A---- C:\Windows\system32\PDMSetup.exe
2011-06-03 12:52:56 ----A---- C:\Windows\system32\mshta.exe
2011-06-03 12:52:56 ----A---- C:\Windows\system32\iexpress.exe
2011-06-02 19:32:08 ----D---- C:\Program Files\Common Files\Windows Live
2011-06-01 21:19:51 ----D---- C:\Users\Kuba\AppData\Roaming\Nikon
2011-06-01 21:16:36 ----D---- C:\Program Files\Common Files\muvee Technologies
2011-06-01 21:16:32 ----D---- C:\ProgramData\Nikon
2011-06-01 21:16:29 ----D---- C:\Program Files\Nikon
2011-06-01 19:37:46 ----D---- C:\Program Files\Ubisoft
2011-06-01 19:36:58 ----D---- C:\Users\Kuba\AppData\Roaming\Nero
2011-05-31 21:29:44 ----ASH---- C:\hiberfil.sys
2011-05-31 19:37:24 ----D---- C:\ProgramData\page
2011-05-30 19:27:21 ----D---- C:\Users\Kuba\AppData\Roaming\Ashampoo
2011-05-30 19:26:54 ----D---- C:\ProgramData\ashampoo
2011-05-30 19:26:42 ----D---- C:\Program Files\Ashampoo
2011-05-29 21:10:29 ----D---- C:\Program Files\FlatOut2
2011-05-29 20:29:21 ----D---- C:\Program Files\Common Files\LightScribe
2011-05-29 20:14:30 ----A---- C:\Windows\system32\msimsg.dll
2011-05-29 20:14:30 ----A---- C:\Windows\system32\msihnd.dll
2011-05-29 20:14:30 ----A---- C:\Windows\system32\msiexec.exe
2011-05-29 20:14:30 ----A---- C:\Windows\system32\msi.dll
2011-05-29 19:44:19 ----D---- C:\Program Files\DivX
2011-05-28 11:49:22 ----D---- C:\ProgramData\Apple Computer
2011-05-28 11:49:22 ----D---- C:\Program Files\QuickTime
2011-05-28 11:47:28 ----D---- C:\Program Files\Common Files\Apple
2011-05-28 11:47:14 ----D---- C:\Program Files\Apple Software Update
2011-05-28 11:47:13 ----D---- C:\ProgramData\Apple
2011-05-27 22:44:46 ----D---- C:\Program Files\Adobe
2011-05-27 22:36:53 ----D---- C:\ProgramData\PDVD
2011-05-27 22:33:46 ----D---- C:\ProgramData\Temp
2011-05-27 22:33:45 ----D---- C:\ProgramData\install_clap
2011-05-27 22:02:31 ----D---- C:\ProgramData\Skype Extras
2011-05-27 22:01:10 ----D---- C:\Program Files\Common Files\Skype
2011-05-27 21:44:12 ----D---- C:\Program Files\Common Files\DESIGNER
2011-05-27 21:43:58 ----D---- C:\Program Files\Microsoft Visual Studio
2011-05-27 21:23:28 ----D---- C:\Program Files\game
2011-05-27 21:23:28 ----D---- C:\Program Files\air
2011-05-27 21:09:59 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-05-27 21:09:58 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-05-27 21:09:57 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-05-17 21:01:20 ----D---- C:\Users\Kuba\AppData\Roaming\WinRAR

======List of files/folders modified in the last 1 months======

2011-06-03 21:24:14 ----D---- C:\Windows\Temp
2011-06-03 21:23:16 ----D---- C:\Windows\system32\Tasks
2011-06-03 21:22:09 ----SHD---- C:\Windows\Installer
2011-06-03 21:22:08 ----SHD---- C:\Config.Msi
2011-06-03 21:21:54 ----SHD---- C:\System Volume Information
2011-06-03 21:13:19 ----D---- C:\Program Files\DAEMON Tools Toolbar
2011-06-03 20:37:22 ----RD---- C:\Program Files
2011-06-03 20:27:33 ----D---- C:\Windows
2011-06-03 20:27:33 ----AD---- C:\Windows\System32
2011-06-03 20:21:05 ----D---- C:\Windows\winsxs
2011-06-03 20:19:53 ----SD---- C:\ProgramData\Microsoft
2011-06-03 20:19:18 ----RSD---- C:\Windows\assembly
2011-06-03 20:18:52 ----SD---- C:\Users\Kuba\AppData\Roaming\Microsoft
2011-06-03 20:18:52 ----D---- C:\Program Files\Common Files\microsoft shared
2011-06-03 20:14:38 ----D---- C:\ProgramData\NVIDIA
2011-06-03 20:14:26 ----AD---- C:\Windows\system32\drivers
2011-06-03 20:14:25 ----D---- C:\Windows\system32\catroot
2011-06-03 20:14:17 ----D---- C:\Windows\inf
2011-06-03 19:08:56 ----D---- C:\Windows\system32\migration
2011-06-03 19:08:56 ----D---- C:\Program Files\Internet Explorer
2011-06-03 13:49:15 ----D---- C:\Windows\system32\catroot2
2011-06-03 13:18:54 ----D---- C:\Windows\rescache
2011-06-03 12:55:57 ----D---- C:\Windows\system32\en-US
2011-06-03 12:55:57 ----D---- C:\Windows\system32\cs-CZ
2011-06-03 12:55:57 ----D---- C:\Windows\PolicyDefinitions
2011-06-03 12:32:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-06-03 12:25:43 ----D---- C:\Program Files\WinRAR
2011-06-02 19:32:08 ----D---- C:\Program Files\Common Files
2011-06-01 21:16:34 ----D---- C:\Program Files\Common Files\Nikon
2011-06-01 21:16:32 ----HD---- C:\ProgramData
2011-06-01 21:16:03 ----A---- C:\Windows\system32\ATL71.DLL
2011-06-01 20:15:42 ----D---- C:\Program Files\Nero
2011-05-29 20:18:25 ----D---- C:\Windows\system32\zh-TW
2011-05-29 20:18:25 ----D---- C:\Windows\system32\uk-UA
2011-05-29 20:18:25 ----D---- C:\Windows\system32\tr-TR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\th-TH
2011-05-29 20:18:25 ----D---- C:\Windows\system32\sv-SE
2011-05-29 20:18:25 ----D---- C:\Windows\system32\sr-Latn-CS
2011-05-29 20:18:25 ----D---- C:\Windows\system32\sl-SI
2011-05-29 20:18:25 ----D---- C:\Windows\system32\sk-SK
2011-05-29 20:18:25 ----D---- C:\Windows\system32\pt-PT
2011-05-29 20:18:25 ----D---- C:\Windows\system32\pt-BR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\pl-PL
2011-05-29 20:18:25 ----D---- C:\Windows\system32\nl-NL
2011-05-29 20:18:25 ----D---- C:\Windows\system32\lv-LV
2011-05-29 20:18:25 ----D---- C:\Windows\system32\lt-LT
2011-05-29 20:18:25 ----D---- C:\Windows\system32\ko-KR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\it-IT
2011-05-29 20:18:25 ----D---- C:\Windows\system32\hu-HU
2011-05-29 20:18:25 ----D---- C:\Windows\system32\hr-HR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\he-IL
2011-05-29 20:18:25 ----D---- C:\Windows\system32\fr-FR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\fi-FI
2011-05-29 20:18:25 ----D---- C:\Windows\system32\et-EE
2011-05-29 20:18:25 ----D---- C:\Windows\system32\es-ES
2011-05-29 20:18:25 ----D---- C:\Windows\system32\el-GR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\de-DE
2011-05-29 20:18:25 ----D---- C:\Windows\system32\bg-BG
2011-05-29 20:18:24 ----D---- C:\Windows\system32\zh-CN
2011-05-29 20:18:24 ----D---- C:\Windows\system32\ru-RU
2011-05-29 20:18:24 ----D---- C:\Windows\system32\ro-RO
2011-05-29 20:18:24 ----D---- C:\Windows\system32\nb-NO
2011-05-29 20:18:24 ----D---- C:\Windows\system32\ja-JP
2011-05-29 20:18:24 ----D---- C:\Windows\system32\da-DK
2011-05-29 20:18:24 ----D---- C:\Windows\system32\ar-SA
2011-05-29 20:13:44 ----D---- C:\Windows\SoftwareDistribution
2011-05-29 20:09:50 ----D---- C:\Program Files\DAEMON Tools Lite
2011-05-29 20:09:04 ----D---- C:\Program Files\K-Lite Codec Pack
2011-05-29 20:04:31 ----A---- C:\Windows\Codec Pack - All In 1 Setup Log.txt
2011-05-29 19:39:30 ----D---- C:\Program Files\Microsoft Silverlight
2011-05-29 19:35:43 ----D---- C:\ProgramData\Adobe
2011-05-28 12:05:34 ----D---- C:\Users\Kuba\AppData\Roaming\Adobe
2011-05-27 22:45:04 ----D---- C:\Program Files\Common Files\Adobe
2011-05-27 22:41:16 ----D---- C:\Users\Kuba\AppData\Roaming\CyberLink
2011-05-27 22:41:16 ----D---- C:\ProgramData\Cyberlink
2011-05-27 22:35:10 ----D---- C:\Program Files\CyberLink
2011-05-27 22:34:55 ----D---- C:\Windows\Prefetch
2011-05-27 22:33:45 ----HD---- C:\Program Files\InstallShield Installation Information
2011-05-27 22:13:04 ----D---- C:\Users\Kuba\AppData\Roaming\Skype
2011-05-27 22:07:59 ----D---- C:\Program Files\Mozilla Firefox
2011-05-27 22:07:15 ----D---- C:\Program Files\Spyware Terminator
2011-05-27 22:02:52 ----D---- C:\Users\Kuba\AppData\Roaming\skypePM
2011-05-27 22:01:10 ----RD---- C:\Program Files\Skype
2011-05-27 22:01:04 ----D---- C:\ProgramData\Skype
2011-05-27 21:58:24 ----D---- C:\Program Files\Electronic Arts
2011-05-27 21:47:21 ----D---- C:\ProgramData\Microsoft Help
2011-05-27 21:46:57 ----A---- C:\Windows\win.ini
2011-05-27 21:44:13 ----D---- C:\Program Files\Microsoft Office
2011-05-27 21:44:12 ----D---- C:\Program Files\Microsoft Works
2011-05-27 21:44:09 ----D---- C:\Program Files\MSBuild
2011-05-27 21:27:44 ----D---- C:\Program Files\Đ»đ¸ßÇĺµçÓ°
2011-05-27 21:27:30 ----D---- C:\Program Files\Windows Media Player
2011-05-27 21:27:30 ----D---- C:\Program Files\WinClamAVShield
2011-05-27 21:27:30 ----D---- C:\Program Files\Webcam 1200
2011-05-27 21:26:02 ----D---- C:\Program Files\Testy Autoškola
2011-05-27 21:26:02 ----D---- C:\Program Files\Temp
2011-05-27 21:25:52 ----D---- C:\Program Files\PC Connectivity Solution
2011-05-27 21:25:45 ----D---- C:\Program Files\Mumble
2011-05-27 21:25:44 ----D---- C:\Program Files\Movies
2011-05-27 21:25:31 ----D---- C:\Program Files\McAfee Security Scan
2011-05-27 21:25:31 ----D---- C:\Program Files\lg_fwupdate
2011-05-27 21:25:31 ----D---- C:\Program Files\LANGMaster Škola DNES
2011-05-27 21:25:30 ----D---- C:\Program Files\ICQ6Toolbar
2011-05-27 21:25:08 ----D---- C:\Program Files\ICQ6.5
2011-05-27 21:25:07 ----D---- C:\Program Files\HELP
2011-05-27 21:24:56 ----D---- C:\Program Files\Fraps
2011-05-27 21:24:55 ----D---- C:\Program Files\FinePixViewer
2011-05-27 21:24:55 ----D---- C:\Program Files\FelixNET_Demo
2011-05-27 21:23:55 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2011-05-27 21:23:54 ----D---- C:\Program Files\Common Files\Services
2011-05-27 21:23:52 ----D---- C:\Program Files\Common Files\GraphBoard 2.50
2011-05-27 21:23:46 ----D---- C:\Program Files\CCleaner
2011-05-27 21:23:43 ----D---- C:\Program Files\AGEIA Technologies
2011-05-27 21:23:34 ----D---- C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
2011-05-27 20:40:21 ----D---- C:\ProgramData\Spyware Terminator
2011-05-27 20:36:32 ----D---- C:\Windows\Tasks
2011-05-27 20:34:48 ----D---- C:\Users\Kuba\AppData\Roaming\Spyware Terminator
2011-05-26 20:25:29 ----D---- C:\Users\Kuba\AppData\Roaming\Mumble
2011-05-24 22:23:03 ----RD---- C:\Users
2011-05-14 12:26:28 ----RSD---- C:\Windows\Fonts
2011-05-14 12:24:29 ----D---- C:\Program Files\Common Files\System
2011-05-10 22:14:51 ----A---- C:\Windows\system32\mrt.exe
2011-05-10 22:14:38 ----D---- C:\Program Files\Windows Mail

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2008-12-25 717296]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-02-23 25432]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-02-23 371544]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-02-23 301528]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-02-23 49240]
R1 InCDPass;Nero InCDPass; C:\Windows\system32\drivers\InCDPass.sys [2008-02-18 36648]
R1 incdrm;Nero InCD MRW Remapper; C:\Windows\system32\drivers\InCDRm.sys [2008-02-18 38312]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\Windows\system32\drivers\sp_rsdrv2.sys [2010-03-18 142592]
R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2011/05/27 22:36:39]; \??\C:\Program Files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [2011-04-12 77296]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-02-23 19544]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-02-23 53592]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-12-28 278728]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-12-28 25416]
R2 ntk_PowerDVD;ntk_PowerDVD; \??\C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys [2011-04-20 71664]
R3 3xHybrid;3xHybrid service; C:\Windows\system32\DRIVERS\3xHybrid.sys [2007-04-20 674048]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-09-24 2171672]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-12-05 8238720]
R3 PAC207;Webcam 1200; C:\Windows\system32\DRIVERS\PFC027.SYS [2007-06-29 611584]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-02 44544]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
R4 InCDfs;Nero InCD File System; C:\Windows\system32\drivers\InCDFs.sys [2008-02-18 118952]
S3 a80jkr8k;a80jkr8k; C:\Windows\system32\drivers\a80jkr8k.sys []
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2011-02-07 483200]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 EagleNT;EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys []
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 GMSIPCI;GMSIPCI; \??\H:\INSTALL\GMSIPCI.SYS []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-05-11 25280]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm60x32.sys [2006-11-02 429056]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-02-23 42184]
R2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
R2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
R2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
R2 FsUsbExService;FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [2009-03-31 233472]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2008-10-19 222456]
R2 InCDsrv;InCD Helper; C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe [2008-02-18 1553704]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-06-17 73728]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-09-17 196608]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-05-14 272024]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-03-18 488960]
S1 InCDrec;Nero InCD File System Recognizer; C:\Windows\system32\drivers\InCDRec.sys [2008-02-18 16040]
S2 gupdate1c9ea00b4bac978;Služba Google Update (gupdate1c9ea00b4bac978); C:\Program Files\Google\Update\GoogleUpdate.exe /svc []
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S2 NeroRegInCDSrv;Nero Registry InCD Service; C:\Program Files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe []
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-27 34312]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe /medsvc []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe []
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe []
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe []
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []

-----------------EOF-----------------

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: preventivka pro Chodnik74

#8 Příspěvek od chodnik74 »

:arrow: Stáhneme si na Plochu program OTMObrázek
  • Spustíme soubor OTM.exe (pokud máte Windows Vista nebo Windows 7,tak na soubor klikněte pravým tlačítkem myši a dejte ,,Spustit jako správce,,)
  • Spustí se nám program OTM a do levého okna ,,Paste Instructions for Items to be Moved,, vložíme následující skript a stiskneme tlačítko MoveIt

    Kód: Vybrat vše

    :files
    C:\Program Files\AVG\
    C:\Program Files\Google\Google Toolbar\
    C:\Program Files\ICQ6Toolbar\
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
    
    :reg
    [HKCU\Software\Microsoft\Internet Explorer\Main]
    "Search Bar"=""
    "Start Page"=""
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{855F3B16-6D32-4fe6-8A56-BBB695989046}"=-
    "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"=-
    "{4B3803EA-5230-4DC3-A7FC-33638F3D3542}"=-
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^ExifLauncher2.lnk]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Remote Control.lnk]
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "RemoteControl"=-
    "LanguageShortcut"=-
    "SecurDisc"=-
    "InCD"=-
    "GrooveMonitor"=-
    "NPSStartup"=-
    "RemoteControl11"=-
    "Adobe Reader Speed Launcher"=-
    "Adobe ARM"=-
    "QuickTime Task"=-
    "NvSvc"=-
    "NvMediaCenter"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "ehTray.exe"=-
    "swg"=-
    
    :commands
    [emptytemp]
    
    
  • Po restartu pc se vám objeví log z OTM,ten mi sem prosím vložte..
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Kuba55
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 03 čer 2011 19:33

Re: preventivka pro Chodnik74

#9 Příspěvek od Kuba55 »

program sem omylem vypnul tak sem davam log z Rsit jestli to pomuze


Logfile of random's system information tool 1.08 (written by random/random)
Run by Kuba at 2011-06-03 22:07:14
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 246 GB (52%) free of 477 GB
Total RAM: 3071 MB (48% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:07:22, on 3.6.2011
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.19048)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Windows\PixArt\Pac207\Monitor.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Users\Kuba\Desktop\RSIT.exe
C:\Program Files\trend micro\Kuba.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60341
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mydtzone.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (file missing)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [RemoteControl11] "C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (file missing)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS3\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS4\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS5\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS6\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS7\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS8\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS9\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O17 - HKLM\System\CS10\Services\Tcpip\..\{1B0E2C37-F4F5-4C5D-A12A-599A60F36BEF}: NameServer = 172.16.15.113,88.146.158.2
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: CLHNServiceForPowerDVD - Unknown owner - C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
O23 - Service: CyberLink PowerDVD 11.0 Monitor Service - CyberLink - C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
O23 - Service: CyberLink PowerDVD 11.0 Service - CyberLink - C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: Služba Google Update (gupdate1c9ea00b4bac978) (gupdate1c9ea00b4bac978) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (file missing)
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (file missing)
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Unknown owner - C:\Program Files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ServiceLayer - Unknown owner - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 13562 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\User_Feed_Synchronization-{117EE415-AC59-4170-8EB9-1FFA8FC45375}.job
C:\Windows\tasks\User_Feed_Synchronization-{9B42D2DF-3071-4FBD-B856-79594C08C035}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-15 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-01-28 1230288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll [2011-05-26 1007160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll []
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-01-28 1230288]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2008-09-24 6335008]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2007-03-14 71216]
"LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD\Language\Language.exe []
"LGODDFU"=C:\Program Files\lg_fwupdate\fwupdate.exe blrun []
"SecurDisc"=C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe [2008-02-18 1629480]
"InCD"=C:\Program Files\Nero\Nero 7\InCD\InCD.exe [2008-02-18 1057064]
"Monitor"=C:\Windows\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"ArcSoft Connection Service"=C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2007-07-03 64000]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"NPSStartup"= []
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-02-23 3451496]
"RemoteControl11"=C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe [2011-04-20 234792]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2010-11-15 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-11-29 421888]
"NvSvc"=C:\Windows\system32\nvsvc.dll [2007-12-05 86016]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2007-12-05 8530464]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2007-12-05 81920]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-21 1233920]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-06-17 2363392]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-06-10 39408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-12-29 687560]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-03-18 2166784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^ExifLauncher2.lnk]
C:\PROGRA~1\FINEPI~1\QUICKD~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Remote Control.lnk]
C:\PROGRA~1\KWORLD~1\TVTUNE~1\HMCP3X~1.EXE []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
Nikon Monitor.lnk - C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2011-06-03 20:37:22 ----D---- C:\Program Files\trend micro
2011-06-03 20:37:21 ----D---- C:\rsit
2011-06-03 20:20:10 ----D---- C:\Program Files\Microsoft Sync Framework
2011-06-03 20:19:53 ----D---- C:\Program Files\Microsoft
2011-06-03 20:19:17 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2011-06-03 20:18:46 ----D---- C:\Program Files\Windows Live SkyDrive
2011-06-03 20:18:30 ----D---- C:\Program Files\Windows Live
2011-06-03 20:14:38 ----A---- C:\Windows\system32\nvexpbar.dll
2011-06-03 20:14:17 ----D---- C:\Windows\LastGood.Tmp
2011-06-03 13:50:53 ----D---- C:\531fa313e61102992eb7ab72
2011-06-03 13:49:52 ----A---- C:\Windows\system32\mshtml.dll
2011-06-03 13:49:51 ----A---- C:\Windows\system32\wininet.dll
2011-06-03 13:49:51 ----A---- C:\Windows\system32\urlmon.dll
2011-06-03 13:49:51 ----A---- C:\Windows\system32\ieframe.dll
2011-06-03 13:49:48 ----A---- C:\Windows\system32\mstime.dll
2011-06-03 13:49:48 ----A---- C:\Windows\system32\msfeeds.dll
2011-06-03 13:49:48 ----A---- C:\Windows\system32\iertutil.dll
2011-06-03 13:49:48 ----A---- C:\Windows\system32\iedkcs32.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\occache.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\mshtmled.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\licmgr10.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\jsproxy.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\ieUnatt.exe
2011-06-03 13:49:47 ----A---- C:\Windows\system32\ieui.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\iesysprep.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\iesetup.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\iernonce.dll
2011-06-03 13:49:47 ----A---- C:\Windows\system32\iepeers.dll
2011-06-03 13:49:45 ----A---- C:\Windows\system32\msfeedssync.exe
2011-06-03 13:49:45 ----A---- C:\Windows\system32\ie4uinit.exe
2011-06-03 13:49:39 ----A---- C:\Windows\system32\vbscript.dll
2011-06-03 13:49:39 ----A---- C:\Windows\system32\jscript.dll
2011-06-03 12:53:00 ----A---- C:\Windows\system32\msls31.dll
2011-06-03 12:53:00 ----A---- C:\Windows\system32\mshtmler.dll
2011-06-03 12:53:00 ----A---- C:\Windows\system32\icardie.dll
2011-06-03 12:53:00 ----A---- C:\Windows\system32\corpol.dll
2011-06-03 12:53:00 ----A---- C:\Windows\system32\admparse.dll
2011-06-03 12:52:59 ----A---- C:\Windows\system32\inseng.dll
2011-06-03 12:52:59 ----A---- C:\Windows\system32\imgutil.dll
2011-06-03 12:52:59 ----A---- C:\Windows\system32\ieakeng.dll
2011-06-03 12:52:59 ----A---- C:\Windows\system32\dxtrans.dll
2011-06-03 12:52:59 ----A---- C:\Windows\system32\dxtmsft.dll
2011-06-03 12:52:58 ----A---- C:\Windows\system32\WinFXDocObj.exe
2011-06-03 12:52:58 ----A---- C:\Windows\system32\wextract.exe
2011-06-03 12:52:58 ----A---- C:\Windows\system32\webcheck.dll
2011-06-03 12:52:58 ----A---- C:\Windows\system32\msrating.dll
2011-06-03 12:52:58 ----A---- C:\Windows\system32\ieakui.dll
2011-06-03 12:52:58 ----A---- C:\Windows\system32\ieaksie.dll
2011-06-03 12:52:57 ----A---- C:\Windows\system32\url.dll
2011-06-03 12:52:57 ----A---- C:\Windows\system32\pngfilt.dll
2011-06-03 12:52:57 ----A---- C:\Windows\system32\ieapfltr.dll
2011-06-03 12:52:57 ----A---- C:\Windows\system32\advpack.dll
2011-06-03 12:52:56 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-06-03 12:52:56 ----A---- C:\Windows\system32\SetDepNx.exe
2011-06-03 12:52:56 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-06-03 12:52:56 ----A---- C:\Windows\system32\PDMSetup.exe
2011-06-03 12:52:56 ----A---- C:\Windows\system32\mshta.exe
2011-06-03 12:52:56 ----A---- C:\Windows\system32\iexpress.exe
2011-06-02 19:32:08 ----D---- C:\Program Files\Common Files\Windows Live
2011-06-01 21:19:51 ----D---- C:\Users\Kuba\AppData\Roaming\Nikon
2011-06-01 21:16:36 ----D---- C:\Program Files\Common Files\muvee Technologies
2011-06-01 21:16:32 ----D---- C:\ProgramData\Nikon
2011-06-01 21:16:29 ----D---- C:\Program Files\Nikon
2011-06-01 19:37:46 ----D---- C:\Program Files\Ubisoft
2011-06-01 19:36:58 ----D---- C:\Users\Kuba\AppData\Roaming\Nero
2011-05-31 21:29:44 ----ASH---- C:\hiberfil.sys
2011-05-31 19:37:24 ----D---- C:\ProgramData\page
2011-05-30 19:27:21 ----D---- C:\Users\Kuba\AppData\Roaming\Ashampoo
2011-05-30 19:26:54 ----D---- C:\ProgramData\ashampoo
2011-05-30 19:26:42 ----D---- C:\Program Files\Ashampoo
2011-05-29 21:10:29 ----D---- C:\Program Files\FlatOut2
2011-05-29 20:29:21 ----D---- C:\Program Files\Common Files\LightScribe
2011-05-29 20:14:30 ----A---- C:\Windows\system32\msimsg.dll
2011-05-29 20:14:30 ----A---- C:\Windows\system32\msihnd.dll
2011-05-29 20:14:30 ----A---- C:\Windows\system32\msiexec.exe
2011-05-29 20:14:30 ----A---- C:\Windows\system32\msi.dll
2011-05-29 19:44:19 ----D---- C:\Program Files\DivX
2011-05-28 11:49:22 ----D---- C:\ProgramData\Apple Computer
2011-05-28 11:49:22 ----D---- C:\Program Files\QuickTime
2011-05-28 11:47:28 ----D---- C:\Program Files\Common Files\Apple
2011-05-28 11:47:14 ----D---- C:\Program Files\Apple Software Update
2011-05-28 11:47:13 ----D---- C:\ProgramData\Apple
2011-05-27 22:44:46 ----D---- C:\Program Files\Adobe
2011-05-27 22:36:53 ----D---- C:\ProgramData\PDVD
2011-05-27 22:33:46 ----D---- C:\ProgramData\Temp
2011-05-27 22:33:45 ----D---- C:\ProgramData\install_clap
2011-05-27 22:02:31 ----D---- C:\ProgramData\Skype Extras
2011-05-27 22:01:10 ----D---- C:\Program Files\Common Files\Skype
2011-05-27 21:44:12 ----D---- C:\Program Files\Common Files\DESIGNER
2011-05-27 21:43:58 ----D---- C:\Program Files\Microsoft Visual Studio
2011-05-27 21:23:28 ----D---- C:\Program Files\game
2011-05-27 21:23:28 ----D---- C:\Program Files\air
2011-05-27 21:09:59 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-05-27 21:09:58 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-05-27 21:09:57 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-05-17 21:01:20 ----D---- C:\Users\Kuba\AppData\Roaming\WinRAR

======List of files/folders modified in the last 1 months======

2011-06-03 22:07:20 ----D---- C:\Windows\Temp
2011-06-03 21:54:49 ----D---- C:\Users\Kuba\AppData\Roaming\Skype
2011-06-03 21:45:48 ----SHD---- C:\System Volume Information
2011-06-03 21:40:18 ----D---- C:\Users\Kuba\AppData\Roaming\skypePM
2011-06-03 21:23:16 ----D---- C:\Windows\system32\Tasks
2011-06-03 21:22:09 ----SHD---- C:\Windows\Installer
2011-06-03 21:22:08 ----SHD---- C:\Config.Msi
2011-06-03 21:13:19 ----D---- C:\Program Files\DAEMON Tools Toolbar
2011-06-03 20:37:22 ----RD---- C:\Program Files
2011-06-03 20:27:33 ----D---- C:\Windows
2011-06-03 20:27:33 ----AD---- C:\Windows\System32
2011-06-03 20:21:05 ----D---- C:\Windows\winsxs
2011-06-03 20:19:53 ----SD---- C:\ProgramData\Microsoft
2011-06-03 20:19:18 ----RSD---- C:\Windows\assembly
2011-06-03 20:18:52 ----SD---- C:\Users\Kuba\AppData\Roaming\Microsoft
2011-06-03 20:18:52 ----D---- C:\Program Files\Common Files\microsoft shared
2011-06-03 20:14:38 ----D---- C:\ProgramData\NVIDIA
2011-06-03 20:14:26 ----AD---- C:\Windows\system32\drivers
2011-06-03 20:14:25 ----D---- C:\Windows\system32\catroot
2011-06-03 20:14:17 ----D---- C:\Windows\inf
2011-06-03 19:08:56 ----D---- C:\Windows\system32\migration
2011-06-03 19:08:56 ----D---- C:\Program Files\Internet Explorer
2011-06-03 13:49:15 ----D---- C:\Windows\system32\catroot2
2011-06-03 13:18:54 ----D---- C:\Windows\rescache
2011-06-03 12:55:57 ----D---- C:\Windows\system32\en-US
2011-06-03 12:55:57 ----D---- C:\Windows\system32\cs-CZ
2011-06-03 12:55:57 ----D---- C:\Windows\PolicyDefinitions
2011-06-03 12:32:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-06-03 12:25:43 ----D---- C:\Program Files\WinRAR
2011-06-02 19:32:08 ----D---- C:\Program Files\Common Files
2011-06-01 21:16:34 ----D---- C:\Program Files\Common Files\Nikon
2011-06-01 21:16:32 ----HD---- C:\ProgramData
2011-06-01 21:16:03 ----A---- C:\Windows\system32\ATL71.DLL
2011-06-01 20:15:42 ----D---- C:\Program Files\Nero
2011-05-29 20:18:25 ----D---- C:\Windows\system32\zh-TW
2011-05-29 20:18:25 ----D---- C:\Windows\system32\uk-UA
2011-05-29 20:18:25 ----D---- C:\Windows\system32\tr-TR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\th-TH
2011-05-29 20:18:25 ----D---- C:\Windows\system32\sv-SE
2011-05-29 20:18:25 ----D---- C:\Windows\system32\sr-Latn-CS
2011-05-29 20:18:25 ----D---- C:\Windows\system32\sl-SI
2011-05-29 20:18:25 ----D---- C:\Windows\system32\sk-SK
2011-05-29 20:18:25 ----D---- C:\Windows\system32\pt-PT
2011-05-29 20:18:25 ----D---- C:\Windows\system32\pt-BR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\pl-PL
2011-05-29 20:18:25 ----D---- C:\Windows\system32\nl-NL
2011-05-29 20:18:25 ----D---- C:\Windows\system32\lv-LV
2011-05-29 20:18:25 ----D---- C:\Windows\system32\lt-LT
2011-05-29 20:18:25 ----D---- C:\Windows\system32\ko-KR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\it-IT
2011-05-29 20:18:25 ----D---- C:\Windows\system32\hu-HU
2011-05-29 20:18:25 ----D---- C:\Windows\system32\hr-HR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\he-IL
2011-05-29 20:18:25 ----D---- C:\Windows\system32\fr-FR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\fi-FI
2011-05-29 20:18:25 ----D---- C:\Windows\system32\et-EE
2011-05-29 20:18:25 ----D---- C:\Windows\system32\es-ES
2011-05-29 20:18:25 ----D---- C:\Windows\system32\el-GR
2011-05-29 20:18:25 ----D---- C:\Windows\system32\de-DE
2011-05-29 20:18:25 ----D---- C:\Windows\system32\bg-BG
2011-05-29 20:18:24 ----D---- C:\Windows\system32\zh-CN
2011-05-29 20:18:24 ----D---- C:\Windows\system32\ru-RU
2011-05-29 20:18:24 ----D---- C:\Windows\system32\ro-RO
2011-05-29 20:18:24 ----D---- C:\Windows\system32\nb-NO
2011-05-29 20:18:24 ----D---- C:\Windows\system32\ja-JP
2011-05-29 20:18:24 ----D---- C:\Windows\system32\da-DK
2011-05-29 20:18:24 ----D---- C:\Windows\system32\ar-SA
2011-05-29 20:13:44 ----D---- C:\Windows\SoftwareDistribution
2011-05-29 20:09:50 ----D---- C:\Program Files\DAEMON Tools Lite
2011-05-29 20:09:04 ----D---- C:\Program Files\K-Lite Codec Pack
2011-05-29 20:04:31 ----A---- C:\Windows\Codec Pack - All In 1 Setup Log.txt
2011-05-29 19:39:30 ----D---- C:\Program Files\Microsoft Silverlight
2011-05-29 19:35:43 ----D---- C:\ProgramData\Adobe
2011-05-28 12:05:34 ----D---- C:\Users\Kuba\AppData\Roaming\Adobe
2011-05-27 22:45:04 ----D---- C:\Program Files\Common Files\Adobe
2011-05-27 22:41:16 ----D---- C:\Users\Kuba\AppData\Roaming\CyberLink
2011-05-27 22:41:16 ----D---- C:\ProgramData\Cyberlink
2011-05-27 22:35:10 ----D---- C:\Program Files\CyberLink
2011-05-27 22:34:55 ----D---- C:\Windows\Prefetch
2011-05-27 22:33:45 ----HD---- C:\Program Files\InstallShield Installation Information
2011-05-27 22:07:59 ----D---- C:\Program Files\Mozilla Firefox
2011-05-27 22:07:15 ----D---- C:\Program Files\Spyware Terminator
2011-05-27 22:01:10 ----RD---- C:\Program Files\Skype
2011-05-27 22:01:04 ----D---- C:\ProgramData\Skype
2011-05-27 21:58:24 ----D---- C:\Program Files\Electronic Arts
2011-05-27 21:47:21 ----D---- C:\ProgramData\Microsoft Help
2011-05-27 21:46:57 ----A---- C:\Windows\win.ini
2011-05-27 21:44:13 ----D---- C:\Program Files\Microsoft Office
2011-05-27 21:44:12 ----D---- C:\Program Files\Microsoft Works
2011-05-27 21:44:09 ----D---- C:\Program Files\MSBuild
2011-05-27 21:27:44 ----D---- C:\Program Files\Đ»đ¸ßÇĺµçÓ°
2011-05-27 21:27:30 ----D---- C:\Program Files\Windows Media Player
2011-05-27 21:27:30 ----D---- C:\Program Files\WinClamAVShield
2011-05-27 21:27:30 ----D---- C:\Program Files\Webcam 1200
2011-05-27 21:26:02 ----D---- C:\Program Files\Testy Autoškola
2011-05-27 21:26:02 ----D---- C:\Program Files\Temp
2011-05-27 21:25:52 ----D---- C:\Program Files\PC Connectivity Solution
2011-05-27 21:25:45 ----D---- C:\Program Files\Mumble
2011-05-27 21:25:44 ----D---- C:\Program Files\Movies
2011-05-27 21:25:31 ----D---- C:\Program Files\McAfee Security Scan
2011-05-27 21:25:31 ----D---- C:\Program Files\lg_fwupdate
2011-05-27 21:25:31 ----D---- C:\Program Files\LANGMaster Škola DNES
2011-05-27 21:25:30 ----D---- C:\Program Files\ICQ6Toolbar
2011-05-27 21:25:08 ----D---- C:\Program Files\ICQ6.5
2011-05-27 21:25:07 ----D---- C:\Program Files\HELP
2011-05-27 21:24:56 ----D---- C:\Program Files\Fraps
2011-05-27 21:24:55 ----D---- C:\Program Files\FinePixViewer
2011-05-27 21:24:55 ----D---- C:\Program Files\FelixNET_Demo
2011-05-27 21:23:55 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2011-05-27 21:23:54 ----D---- C:\Program Files\Common Files\Services
2011-05-27 21:23:52 ----D---- C:\Program Files\Common Files\GraphBoard 2.50
2011-05-27 21:23:46 ----D---- C:\Program Files\CCleaner
2011-05-27 21:23:43 ----D---- C:\Program Files\AGEIA Technologies
2011-05-27 21:23:34 ----D---- C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
2011-05-27 20:40:21 ----D---- C:\ProgramData\Spyware Terminator
2011-05-27 20:36:32 ----D---- C:\Windows\Tasks
2011-05-27 20:34:48 ----D---- C:\Users\Kuba\AppData\Roaming\Spyware Terminator
2011-05-26 20:25:29 ----D---- C:\Users\Kuba\AppData\Roaming\Mumble
2011-05-24 22:23:03 ----RD---- C:\Users
2011-05-14 12:26:28 ----RSD---- C:\Windows\Fonts
2011-05-14 12:24:29 ----D---- C:\Program Files\Common Files\System
2011-05-10 22:14:51 ----A---- C:\Windows\system32\mrt.exe
2011-05-10 22:14:38 ----D---- C:\Program Files\Windows Mail

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2008-12-25 717296]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-02-23 25432]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-02-23 371544]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-02-23 301528]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-02-23 49240]
R1 InCDPass;Nero InCDPass; C:\Windows\system32\drivers\InCDPass.sys [2008-02-18 36648]
R1 incdrm;Nero InCD MRW Remapper; C:\Windows\system32\drivers\InCDRm.sys [2008-02-18 38312]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\Windows\system32\drivers\sp_rsdrv2.sys [2010-03-18 142592]
R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2011/05/27 22:36:39]; \??\C:\Program Files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [2011-04-12 77296]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-02-23 19544]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-02-23 53592]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-12-28 278728]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-12-28 25416]
R2 ntk_PowerDVD;ntk_PowerDVD; \??\C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys [2011-04-20 71664]
R3 3xHybrid;3xHybrid service; C:\Windows\system32\DRIVERS\3xHybrid.sys [2007-04-20 674048]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-09-24 2171672]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-12-05 8238720]
R3 PAC207;Webcam 1200; C:\Windows\system32\DRIVERS\PFC027.SYS [2007-06-29 611584]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-02 44544]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
R4 InCDfs;Nero InCD File System; C:\Windows\system32\drivers\InCDFs.sys [2008-02-18 118952]
S3 a80jkr8k;a80jkr8k; C:\Windows\system32\drivers\a80jkr8k.sys []
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2011-02-07 483200]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 EagleNT;EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys []
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 GMSIPCI;GMSIPCI; \??\H:\INSTALL\GMSIPCI.SYS []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-05-11 25280]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm60x32.sys [2006-11-02 429056]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-02-23 42184]
R2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
R2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
R2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
R2 FsUsbExService;FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [2009-03-31 233472]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2008-10-19 222456]
R2 InCDsrv;InCD Helper; C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe [2008-02-18 1553704]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-06-17 73728]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-09-17 196608]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-05-14 272024]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-03-18 488960]
S1 InCDrec;Nero InCD File System Recognizer; C:\Windows\system32\drivers\InCDRec.sys [2008-02-18 16040]
S2 gupdate1c9ea00b4bac978;Služba Google Update (gupdate1c9ea00b4bac978); C:\Program Files\Google\Update\GoogleUpdate.exe /svc []
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S2 NeroRegInCDSrv;Nero Registry InCD Service; C:\Program Files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe []
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-27 34312]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe /medsvc []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe []
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe []
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe []
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []

-----------------EOF-----------------

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: preventivka pro Chodnik74

#10 Příspěvek od chodnik74 »

Zkuste předchozí krok ještě jednou :) znovu OTM :)
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: preventivka pro Chodnik74

#11 Příspěvek od chodnik74 »

po konzultaci přes PM


:arrow: Malwarebytes' Anti-Malware Obrázek
  • Stáhneme,nainstalujeme a spustíme(pokud si nevíte rady jak,klikněte ZDE)
  • Vybereme Úplná kontrola a klikneme na tlačítko ProhledatObrázek
  • Program provede kontrolu počítače a na konci se vám objeví hláska,že bylo skenování dokončeno,tak potvrdíme tlačítkem OK
  • Objeví se vám log,který mi sem vložte
  • NIC NEMAZAT!!Program mívá občas falešné detekce,takže mazat budeme až po konzultaci :twisted:
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Kuba55
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 03 čer 2011 19:33

Re: preventivka pro Chodnik74

#12 Příspěvek od Kuba55 »

zde to je


Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Verze databáze: 6766

Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.19048

3.6.2011 23:17:48
mbam-log-2011-06-03 (23-17-48).txt

Typ: Rychlá kontrola
Kontrolované objekty: 227054
Uplynulý čas: 8 minut, 11 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 0

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: preventivka pro Chodnik74

#13 Příspěvek od chodnik74 »

Zítra teda udělej Úplný sken..jak jsem ti říkal :) tento je čistý ;-)
Naposledy upravil(a) chodnik74 dne 06 čer 2011 12:02, celkem upraveno 1 x.
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: preventivka pro Chodnik74

#14 Příspěvek od chodnik74 »

:arrow: Otevřeme si Poznámkový blok Obrázek
  • (stiskneme klávesovou kombinaci WIN+R a napíšeme ,,notepad,, bez úvozovek a dáme enter)
  • Vložíme do něj následující script:

    Kód: Vybrat vše

    Windows Registry Editor Version 5.00
    
    [HKCU\Software\Microsoft\Internet Explorer\Main]
    "Search Bar"=""
    "Start Page"=""
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{855F3B16-6D32-4fe6-8A56-BBB695989046}"=-
    "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"=-
    "{4B3803EA-5230-4DC3-A7FC-33638F3D3542}"=-
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^ExifLauncher2.lnk]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Remote Control.lnk]
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "RemoteControl"=-
    "LanguageShortcut"=-
    "SecurDisc"=-
    "InCD"=-
    "GrooveMonitor"=-
    "NPSStartup"=-
    "RemoteControl11"=-
    "Adobe Reader Speed Launcher"=-
    "Adobe ARM"=-
    "QuickTime Task"=-
    "NvSvc"=-
    "NvMediaCenter"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "ehTray.exe"=-
    "swg"=-
    
    
  • Soubor uložíme jako oprava.reg (při ukládání nastavte Uložit jako typ:Všechny soubory)
  • Poté tento soubor spustíme a potvrdíme :)


:arrow: Stáhneme si program Avanger:
http://swandog46.geekstogo.com/avenger.exe

Spustíme stažený soubor a jako první se nám zjeví upozornění,že to co děláte,provádíte na vlastní riziko.Potvrdíme OK

Zaškrkneme volbu Scan for rootkits a do okýnka Input script here: zkopírujeme a vložíme následující script a odstartujeme tlačítkem Execute:

Kód: Vybrat vše

Files to delete:
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk

Folders to delete:
C:\Program Files\AVG\
C:\Program Files\Google\Google Toolbar\
C:\Program Files\ICQ6Toolbar\
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: preventivka pro Chodnik74

#15 Příspěvek od chodnik74 »

Roli píše:Ahoj, ať smaže cache IE a Firefoxu, zřejmě je to nějaká chyba v google maps.
taky zkus :)
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Odpovědět