Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

srchasm.dll

Patříte mezi Vzorné návštěvníky? Pak je tato sekce pro vás.

Moderátor: Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Zpráva
Autor
Uživatelský avatar
Zizou
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 65
Registrován: 22 črc 2010 16:11
Kontaktovat uživatele:

srchasm.dll

#1 Příspěvek od Zizou »

Zdravím, MSE mi našel vir v C:\Windows\srchasst\srchasm.dll

Vím, že se má nejdřív dělat RSIT a až pak eventuálně CF, já jsem bohužel po CF spustil omylem RSIT ještě jednou :roll:

Logfile of random's system information tool 1.08 (written by random/random)
Run by Honzik at 2011-06-08 23:48:27
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 53 GB (9%) free of 610 GB
Total RAM: 3062 MB (36% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:48:32, on 8.6.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Unified Remote\RemoteServer.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Users\Honzik\AppData\Local\Google\Update\1.3.21.57\GoogleCrashHandler.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files\FileHippo.com\UpdateChecker.exe
C:\Users\Honzik\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Java\jre6\bin\javaw.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\notepad.exe
C:\Windows\explorer.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Users\Honzik\Documents\Downloads\RSIT.exe
C:\Program Files\trend micro\Honzik.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Mouse Gestures - {A6A49249-57AE-4295-8D4D-18A9502C7D8E} - C:\Program Files\Internet Explorer\Plugins\Drowse\MouseGestures.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [HTC Sync Loader] "C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [PocketCloud Location] C:\Program Files\Wyse\PocketCloud Windows Companion\WyseBrowser.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [PicPick Start] C:\Program Files\PicPick\picpick.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Unified Remote v2] C:\Program Files\Unified Remote\RemoteServer.exe
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.5\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [B0126BAED94CD465241FB2FC069A50FE1AD1022E._service_run] "C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service
O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background
O4 - HKCU\..\Run: [BSRemote] C:\Program Files\BSRemote\BSRemoteServer_32.exe
O4 - HKUS\S-1-5-21-350281380-233495102-1455855570-1011\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-350281380-233495102-1455855570-1011\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: android-notifier-desktop.lnk = ?
O4 - Startup: Dropbox.lnk = Honzik\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: &Stáhnout &vše FlashGetem - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {4E660F19-E91E-41E1-88EF-D1DFAB118F67} - C:\Program Files\Internet Explorer\Plugins\Drowse\MouseGestures.dll
O9 - Extra 'Tools' menuitem: Mouse Gestures... - {4E660F19-E91E-41E1-88EF-D1DFAB118F67} - C:\Program Files\Internet Explorer\Plugins\Drowse\MouseGestures.dll
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos-be ... canner.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe
O23 - Service: AST Service (astcc) - Nalpeiron Ltd. - C:\WINDOWS\system32\ASTSRV.EXE
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Služba Google Update (gupdate1c9ba1b510f0c16) (gupdate1c9ba1b510f0c16) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NLSSRV32.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: Wyse PocketCloud (WysePocketCloud) - Unknown owner - C:\Program Files\Wyse\PocketCloud Windows Companion\PocketCloudService.exe

--
End of file - 13410 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-350281380-233495102-1455855570-1004Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-350281380-233495102-1455855570-1004UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22 191792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-11-10 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6A49249-57AE-4295-8D4D-18A9502C7D8E}]
Mouse Gestures - C:\Program Files\Internet Explorer\Plugins\Drowse\MouseGestures.dll [2009-07-25 741376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL [2010-01-16 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-26 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-01-21 91520]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
"HTC Sync Loader"=C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2010-10-28 294912]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 997408]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-01-07 253672]
"PocketCloud Location"=C:\Program Files\Wyse\PocketCloud Windows Companion\WyseBrowser.exe [2011-03-24 399872]
"googletalk"=C:\Program Files\Google\Google Talk\googletalk.exe [2007-01-01 3739648]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2010-11-20 144384]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]
"PicPick Start"=C:\Program Files\PicPick\picpick.exe [2011-05-06 10822656]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"Unified Remote v2"=C:\Program Files\Unified Remote\RemoteServer.exe [2011-05-07 177152]
"ICQ"=C:\Program Files\ICQ7.5\ICQ.exe [2011-05-01 124216]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 354304]
"B0126BAED94CD465241FB2FC069A50FE1AD1022E._service_run"=C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe [2011-06-06 1011768]
"FileHippo.com"=C:\Program Files\FileHippo.com\UpdateChecker.exe [2010-08-09 248832]
"BSRemote"=C:\Program Files\BSRemote\BSRemoteServer_32.exe [2011-05-28 104448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccleaner]
C:\Program Files\CCleaner\CCleaner.exe [2011-05-25 2301752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gaming 3]
C:\Gaming Mouse\Gaming 3.exe [2009-11-09 1216512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
C:\WINDOWS\RaidTool\xInsIDE.exe [2008-11-18 36864]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Six Engine]
C:\Program Files\ASUS\EPU-6 Engine\SixEngine.exe [2008-11-13 5974528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TurboV]
C:\Program Files\ASUS\TurboV\TurboV.exe [2008-10-21 4040192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VolPanel]
C:\Program Files\Creative\USB Headsets\Volume Panel\VolPanlu.exe [2008-08-27 233588]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WLSync]
C:\Program Files\Windows Live\Mesh\WLSync.exe [2010-09-23 1448800]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Honzik^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
C:\Users\Honzik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-05-25 24176560]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Honzik^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Otevřít poznámkový blok.onetoc2]
C:\Users\Honzik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Otevřít poznámkový blok.onetoc2 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Honzik^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk]
C:\PROGRA~1\MIF5BA~1\Office14\ONENOTEM.EXE [2010-01-21 226176]

C:\Users\Honzik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
android-notifier-desktop.lnk - C:\Program Files\Android Notifier Desktop\android-notifier-desktop.exe
Dropbox.lnk - C:\Users\Honzik\AppData\Roaming\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2011-03-15 203776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll [2010-06-22 202088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"ConsentPromptBehaviorAdmin"=0
"PromptOnSecureDesktop"=0
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Documents and Settings\Honzik\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.dll"="C:\Users\Honzik\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin"
"C:\Documents and Settings\Honzik\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe"="C:\Users\Honzik\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
"C:\Program Files\Activision\Prototype\prototypef.exe"="C:\Program Files\Activision\Prototype\prototypef.exe:*:Enabled:Prototype(TM)"
"C:\Program Files\Activision\Wolfenstein\MP\Wolf2MP.exe"="C:\Program Files\Activision\Wolfenstein\MP\Wolf2MP.exe:*:Enabled:Wolfenstein(TM) "
"C:\Program Files\Activision\Wolfenstein\MP\Wolf2MPLite.exe"="C:\Program Files\Activision\Wolfenstein\MP\Wolf2MPLite.exe:*:Enabled:Wolfenstein(TM) "
"C:\Program Files\Codemasters\FUEL\FUEL.exe"="C:\Program Files\Codemasters\FUEL\FUEL.exe:*:Enabled:FUEL"
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
"C:\Program Files\Deep Silver\S.T.A.L.K.E.R. - Clear Sky\bin\dedicated\xrEngine.exe"="C:\Program Files\Deep Silver\S.T.A.L.K.E.R. - Clear Sky\bin\dedicated\xrEngine.exe:*:Enabled:S.T.A.L.K.E.R. - Clear Sky (SRV)"
"C:\Program Files\Deep Silver\S.T.A.L.K.E.R. - Clear Sky\bin\xrEngine.exe"="C:\Program Files\Deep Silver\S.T.A.L.K.E.R. - Clear Sky\bin\xrEngine.exe:*:Enabled:S.T.A.L.K.E.R. - Clear Sky (CLI)"
"C:\Program Files\Dragon Age\bin_ship\daorigins.exe"="C:\Program Files\Dragon Age\bin_ship\daorigins.exe:*:Enabled:Dragon Age Prameny Hra"
"C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe"="C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe:*:Enabled:Dragon Age Prameny Aktualizovat"
"C:\Program Files\Dragon Age\DAOriginsLauncher.exe"="C:\Program Files\Dragon Age\DAOriginsLauncher.exe:*:Enabled:Dragon Age Prameny Spustit"
"C:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe"="C:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe:*:Enabled:Burnout(TM) Paradise The Ultimate Box"
"C:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe"="C:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe:*:Enabled:Burnout(TM) Paradise The Ultimate Box"
"C:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe"="C:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe:*:Enabled:Burnout(TM) Paradise The Ultimate Box"
"C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe"="C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:*:Enabled:Crysis_32"
"C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe"="C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:*:Enabled:CrysisDedicatedServer_32"
"C:\Program Files\FlashGet Network\FlashGet universal\FlashGet.exe"="C:\Program Files\FlashGet Network\FlashGet universal\FlashGet.exe:*:Enabled:Flashget2"
"C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdate.exe"="C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdate.exe:*:Enabled:FGLiveUpdate"
"C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdateEx.exe"="C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdateEx.exe:*:Enabled:FGLiveUpdateEx"
"C:\Program Files\FlashGet\FlashGet.exe"="C:\Program Files\FlashGet\FlashGet.exe:*:Enabled:Flashget"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe"="C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Ubisoft\Techland\Call of Juarez - Bound in Blood\CoJBiBGame_x86.exe"="C:\Program Files\Ubisoft\Techland\Call of Juarez - Bound in Blood\CoJBiBGame_x86.exe:*:Enabled:Call of Juarez - Bound in Blood"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\WINDOWS\system32\vomhlm.exe"="C:\WINDOWS\system32\vomhlm.exe:*:Enabled:ENABLE"
"C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.txt - open - "C:\Program Files\PSPad editor\PSPad.exe" "%1"

======List of files/folders created in the last 1 months======

2011-06-08 23:42:41 ----SHD---- C:\$RECYCLE.BIN
2011-06-08 23:42:39 ----D---- C:\Windows\temp
2011-06-08 23:42:38 ----A---- C:\ComboFix.txt
2011-06-08 23:31:10 ----D---- C:\Qoobox
2011-06-08 20:11:31 ----D---- C:\Program Files\JDownloader
2011-06-08 19:53:03 ----A---- C:\Windows\system32\gigagetbho_v10.dll
2011-06-08 19:52:58 ----D---- C:\Program Files\Giganology
2011-06-08 12:16:10 ----A---- C:\Users\Honzik\AppData\Roaming\Network Meter_Settings.ini
2011-06-07 10:35:15 ----D---- C:\ProgramData\PopCap Games
2011-06-04 19:33:43 ----D---- C:\Program Files\Rovio
2011-06-04 18:43:21 ----D---- C:\Program Files\Wyse
2011-05-31 17:12:58 ----D---- C:\Users\Honzik\AppData\Roaming\BatteryBar
2011-05-31 17:12:57 ----D---- C:\Program Files\BatteryBar
2011-05-30 16:55:29 ----D---- C:\Program Files\BSRemote
2011-05-29 14:57:12 ----D---- C:\Users\Honzik\AppData\Roaming\MyPhoneExplorer
2011-05-29 14:56:53 ----D---- C:\Program Files\MyPhoneExplorer
2011-05-28 20:31:02 ----D---- C:\Program Files\IrfanView
2011-05-28 13:41:36 ----D---- C:\Program Files\Android Notifier Desktop
2011-05-26 17:07:07 ----D---- C:\Program Files\Common Files\Java
2011-05-26 17:05:05 ----A---- C:\Windows\system32\javaws.exe
2011-05-26 17:05:05 ----A---- C:\Windows\system32\javaw.exe
2011-05-26 17:05:05 ----A---- C:\Windows\system32\java.exe
2011-05-25 17:12:00 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2011-05-24 15:10:24 ----D---- C:\Program Files\O2
2011-05-24 14:40:18 ----D---- C:\Users\Honzik\AppData\Roaming\O2
2011-05-22 15:44:53 ----D---- C:\Program Files\Android
2011-05-22 15:18:41 ----A---- C:\Windows\system32\drivers\VBoxDrv.sys
2011-05-22 15:18:34 ----A---- C:\Windows\system32\drivers\VBoxUSBMon.sys
2011-05-22 15:18:31 ----D---- C:\Program Files\Oracle
2011-05-19 14:19:40 ----A---- C:\Windows\system32\poqexec.exe
2011-05-16 19:01:00 ----A---- C:\Windows\system32\drivers\VBoxNetFlt.sys
2011-05-16 19:01:00 ----A---- C:\Windows\system32\drivers\VBoxNetAdp.sys
2011-05-16 19:00:58 ----A---- C:\Windows\system32\VBoxNetFltNotify.dll
2011-05-14 22:49:20 ----D---- C:\ProgramData\NVIDIA
2011-05-14 22:42:09 ----A---- C:\Windows\system32\OpenCL.dll
2011-05-14 22:42:09 ----A---- C:\Windows\system32\nvwgf2um.dll
2011-05-14 22:42:09 ----A---- C:\Windows\system32\nvoglv32.dll
2011-05-14 22:42:09 ----A---- C:\Windows\system32\nvgenco322060.dll
2011-05-14 22:42:09 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-05-14 22:42:08 ----A---- C:\Windows\system32\nvdispco3220140.dll
2011-05-14 22:42:08 ----A---- C:\Windows\system32\nvd3dum.dll
2011-05-14 22:42:08 ----A---- C:\Windows\system32\nvcuvid.dll
2011-05-14 22:42:08 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-05-14 22:42:08 ----A---- C:\Windows\system32\nvcuda.dll
2011-05-14 22:42:08 ----A---- C:\Windows\system32\nvcompiler.dll
2011-05-14 22:42:08 ----A---- C:\Windows\system32\nvapi.dll
2011-05-14 17:18:51 ----D---- C:\Users\Honzik\AppData\Roaming\7stacks
2011-05-14 14:23:24 ----D---- C:\Program Files\Alastria Software
2011-05-13 15:26:24 ----D---- C:\Users\Honzik\AppData\Roaming\Chrome
2011-05-13 15:26:01 ----D---- C:\Program Files\Chrome Extensions
2011-05-13 14:43:40 ----D---- C:\ProgramData\Skype Extras
2011-05-11 11:49:53 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-05-11 11:49:53 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-05-11 11:49:51 ----A---- C:\Windows\system32\drivers\usbehci.sys
2011-05-11 11:49:50 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2011-05-11 11:49:50 ----A---- C:\Windows\system32\drivers\usbport.sys
2011-05-11 11:49:50 ----A---- C:\Windows\system32\drivers\usbohci.sys
2011-05-11 11:49:50 ----A---- C:\Windows\system32\drivers\usbhub.sys
2011-05-11 11:49:50 ----A---- C:\Windows\system32\drivers\usbd.sys
2011-05-11 11:49:50 ----A---- C:\Windows\system32\drivers\usbccgp.sys

======List of files/folders modified in the last 1 months======

2011-06-08 23:48:30 ----D---- C:\Program Files\trend micro
2011-06-08 23:42:39 ----AD---- C:\Windows
2011-06-08 23:41:07 ----A---- C:\Windows\system.ini
2011-06-08 23:41:02 ----D---- C:\Windows\system32\drivers\etc
2011-06-08 23:40:30 ----D---- C:\Program Files\Steam
2011-06-08 23:38:04 ----D---- C:\Windows\system32\drivers
2011-06-08 23:38:04 ----D---- C:\Windows\System32
2011-06-08 23:38:04 ----D---- C:\Windows\AppPatch
2011-06-08 23:38:03 ----D---- C:\Program Files\Common Files
2011-06-08 23:36:13 ----D---- C:\Windows\system32\config
2011-06-08 23:32:02 ----D---- C:\Windows\ERDNT
2011-06-08 23:24:32 ----SHD---- C:\System Volume Information
2011-06-08 23:22:02 ----D---- C:\Users\Honzik\AppData\Roaming\GetRightToGo
2011-06-08 23:07:21 ----D---- C:\Users\Honzik\AppData\Roaming\ICQ
2011-06-08 22:33:11 ----D---- C:\Windows\Prefetch
2011-06-08 21:49:31 ----SHD---- C:\Windows\Installer
2011-06-08 20:11:31 ----AD---- C:\Program Files
2011-06-08 16:18:01 ----D---- C:\Users\Honzik\AppData\Roaming\Dropbox
2011-06-08 14:42:16 ----RD---- C:\Program Files\Google
2011-06-08 11:55:58 ----D---- C:\Windows\system32\FxsTmp
2011-06-08 10:51:52 ----D---- C:\ProgramData\McAfee
2011-06-07 10:35:15 ----D---- C:\ProgramData
2011-06-04 19:37:00 ----D---- C:\Config.Msi
2011-06-04 19:33:51 ----D---- C:\Users\Honzik\AppData\Roaming\Rovio
2011-06-04 18:43:02 ----RSD---- C:\Windows\assembly
2011-06-02 16:50:31 ----D---- C:\Windows\inf
2011-06-02 16:50:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-05-29 17:20:07 ----D---- C:\Windows\system32\NDF
2011-05-27 20:50:53 ----D---- C:\Users\Honzik\AppData\Roaming\Skype
2011-05-27 20:50:53 ----D---- C:\Users\Honzik\AppData\Roaming\FileZilla
2011-05-27 20:50:19 ----D---- C:\Windows\Logs
2011-05-27 16:11:51 ----D---- C:\Windows\system32\catroot2
2011-05-26 17:11:35 ----RD---- C:\Program Files\WinRAR
2011-05-26 17:06:42 ----D---- C:\Users\Honzik\AppData\Roaming\skypePM
2011-05-26 17:06:15 ----D---- C:\Windows\system32\Tasks
2011-05-26 17:06:08 ----RD---- C:\Program Files\Skype
2011-05-26 17:04:58 ----A---- C:\Windows\system32\deployJava1.dll
2011-05-26 16:56:49 ----D---- C:\Program Files\FileZilla FTP Client
2011-05-26 16:56:16 ----D---- C:\Program Files\Defraggler
2011-05-26 16:47:26 ----D---- C:\Program Files\Mozilla Thunderbird
2011-05-26 16:46:23 ----RD---- C:\Program Files\CCleaner
2011-05-26 14:48:07 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-05-25 22:20:06 ----D---- C:\Windows\winsxs
2011-05-25 18:44:13 ----D---- C:\Program Files\Mafia II
2011-05-25 17:21:23 ----D---- C:\AdobeTemp
2011-05-25 17:11:34 ----D---- C:\Windows\system32\catroot
2011-05-22 15:37:23 ----RD---- C:\Program Files\Angry Birds
2011-05-22 15:19:02 ----D---- C:\Windows\system32\DriverStore
2011-05-22 15:18:41 ----DC---- C:\Windows\system32\DRVSTORE
2011-05-21 19:43:23 ----D---- C:\Windows\system32\wbem
2011-05-21 19:42:16 ----D---- C:\Users\Honzik\AppData\Roaming\picpick
2011-05-21 19:42:16 ----D---- C:\Users\Honzik\AppData\Roaming\Mp3tag
2011-05-21 19:42:08 ----D---- C:\Program Files\Scorpions WinCheater
2011-05-21 19:42:02 ----RD---- C:\Program Files\Opera
2011-05-21 19:41:53 ----D---- C:\Windows\AppCompat
2011-05-21 19:41:52 ----SD---- C:\Windows\Tasks
2011-05-21 19:41:52 ----D---- C:\Windows\system32\drivers\UMDF
2011-05-21 19:41:52 ----D---- C:\Windows\system32\CodeIntegrity
2011-05-21 19:41:51 ----D---- C:\Windows\registration
2011-05-20 15:23:13 ----D---- C:\Program Files\Common Files\Steam
2011-05-18 19:54:37 ----D---- C:\Program Files\Mp3tag
2011-05-18 19:54:09 ----D---- C:\Program Files\Logon Screen Rotator
2011-05-15 23:24:29 ----D---- C:\Windows\debug
2011-05-15 01:21:54 ----D---- C:\ProgramData\Microsoft Help
2011-05-15 01:21:52 ----D---- C:\Program Files\Common Files\Skype
2011-05-15 01:21:51 ----D---- C:\Program Files\NVIDIA Corporation
2011-05-15 01:21:49 ----D---- C:\Program Files\PSPad editor
2011-05-15 01:21:37 ----D---- C:\Users\Honzik\AppData\Roaming\PSpad
2011-05-15 01:21:36 ----D---- C:\Windows\security
2011-05-15 01:21:36 ----D---- C:\Windows\Help
2011-05-15 01:21:36 ----D---- C:\Windows\Downloaded Program Files
2011-05-15 01:21:35 ----D---- C:\Windows\system32\Macromed
2011-05-14 22:49:20 ----RD---- C:\Users
2011-05-14 22:49:07 ----HD---- C:\Program Files\InstallShield Installation Information
2011-05-14 22:47:36 ----D---- C:\ProgramData\NVIDIA Corporation
2011-05-14 14:23:07 ----D---- C:\Program Files\Stardock
2011-05-14 14:21:19 ----D---- C:\Users\Honzik\AppData\Roaming\Stardock
2011-05-13 16:27:55 ----D---- C:\Users\Honzik\AppData\Roaming\OneUpIndustries
2011-05-13 16:27:51 ----D---- C:\ProgramData\OneUpIndustries
2011-05-11 21:21:54 ----A---- C:\Windows\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2008-11-18 83296]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2009-05-01 43528]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-02-12 431672]
R0 tdrpman;Acronis Try&Decide and Restore Points filter; C:\Windows\system32\DRIVERS\tdrpman.sys [2009-10-28 368736]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 Amfilter;A4Tech Mouse Filter Driver; C:\Windows\system32\DRIVERS\Amfilter.sys [2007-05-14 9216]
R1 AsIO;AsIO; C:\Windows\system32\drivers\AsIO.sys [2007-12-17 12400]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-10-24 165264]
R1 MpKsl6bc6a255;MpKsl6bc6a255; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{28DA534E-4EB9-456C-B6F7-C46073BDF380}\MpKsl6bc6a255.sys [2011-06-08 28752]
R1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys [2011-05-16 162544]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows\system32\DRIVERS\VBoxUSBMon.sys [2011-05-16 44720]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-09-11 116008]
R2 ncryptpro;ncryptpro; \??\C:\WINDOWS\system32\Drivers\ncryptpro.sys [2009-08-11 186720]
R2 thdudf;TOSHIBA UDF2.5 Reader File System Driver; C:\Windows\system32\DRIVERS\thdudf.sys [2006-11-11 66944]
R3 catchme;catchme; \??\C:\Users\Honzik\AppData\Local\Temp\catchme.sys []
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2006-10-18 7680]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 P17;SB Live! 24-bit; C:\Windows\system32\drivers\P17.sys [2009-04-21 1147392]
R3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2011-03-21 362600]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2011-05-16 111280]
R3 VBoxNetFlt;VBoxNetFlt Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys [2011-05-16 122224]
S1 MpKsl0340f651;MpKsl0340f651; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{593ACB23-F587-4832-A78D-99B67C1C53E5}\MpKsl0340f651.sys []
S1 MpKsl1975be5b;MpKsl1975be5b; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{288CBA9C-5405-4F62-9C38-80E78B696D9B}\MpKsl1975be5b.sys []
S1 MpKsl26304fe0;MpKsl26304fe0; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E90FDFC9-0DF3-4A0B-9477-68D5CCBAC0FB}\MpKsl26304fe0.sys []
S1 MpKsl36bee938;MpKsl36bee938; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{835AADC9-F88A-449D-8195-205F92142825}\MpKsl36bee938.sys []
S1 MpKsl448e424c;MpKsl448e424c; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{590B22E2-838D-49F2-91E8-713F44DAF245}\MpKsl448e424c.sys []
S1 MpKsl479c9c00;MpKsl479c9c00; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F55A04F7-6CCE-4C1D-A54A-C54E61D77E1B}\MpKsl479c9c00.sys []
S1 MpKsl5981ba83;MpKsl5981ba83; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{72623F6E-E661-46A1-AC25-998F994F85EB}\MpKsl5981ba83.sys []
S1 MpKsl62250eeb;MpKsl62250eeb; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{14698E4C-E468-4440-955E-F8D19496F4E2}\MpKsl62250eeb.sys []
S1 MpKsl659e98a9;MpKsl659e98a9; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2581424A-C3BE-422B-B970-56B2F126C3F1}\MpKsl659e98a9.sys []
S1 MpKsl67ec1c8b;MpKsl67ec1c8b; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4DC72EFF-217B-414C-B3FD-16AB9B539497}\MpKsl67ec1c8b.sys []
S1 MpKsl6f6700e8;MpKsl6f6700e8; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CC2F519D-B3AB-4164-8E37-B8472D6C061C}\MpKsl6f6700e8.sys []
S1 MpKsl75a41f55;MpKsl75a41f55; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CC6512B3-BA56-4497-8309-BAA3CEA200F1}\MpKsl75a41f55.sys []
S1 MpKsl7f974c7a;MpKsl7f974c7a; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{18156338-5A36-4410-8FF8-0B522029468A}\MpKsl7f974c7a.sys []
S1 MpKsl814199f3;MpKsl814199f3; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F1BD7654-8515-4562-B92F-97627F860B0F}\MpKsl814199f3.sys []
S1 MpKsl82251cfe;MpKsl82251cfe; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4309D1AE-3F07-45D6-ACD6-4DCC8B9DBE79}\MpKsl82251cfe.sys []
S1 MpKsl882c7e61;MpKsl882c7e61; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CC6512B3-BA56-4497-8309-BAA3CEA200F1}\MpKsl882c7e61.sys []
S1 MpKsl9b11a6c8;MpKsl9b11a6c8; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{18156338-5A36-4410-8FF8-0B522029468A}\MpKsl9b11a6c8.sys []
S1 MpKslb053ee18;MpKslb053ee18; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9F793646-70E3-4918-B62E-55324839D95E}\MpKslb053ee18.sys []
S1 MpKslbbbd644e;MpKslbbbd644e; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D295FA0F-84C8-45B9-BB57-C892F6FCE108}\MpKslbbbd644e.sys []
S1 MpKslbff4a388;MpKslbff4a388; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E2F9BA8C-EEE4-4075-A891-050B79464AD4}\MpKslbff4a388.sys []
S1 MpKslc5e74ba3;MpKslc5e74ba3; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4C6BA80C-A768-46C8-83A6-6B5F4478E38D}\MpKslc5e74ba3.sys []
S1 MpKsldbb27d07;MpKsldbb27d07; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F032B02A-F541-4676-80FB-D54D5396142A}\MpKsldbb27d07.sys []
S1 MpKsle4ebc3fd;MpKsle4ebc3fd; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BDF64828-6C77-4552-996E-4B602E872877}\MpKsle4ebc3fd.sys []
S1 MpKsledc5af9e;MpKsledc5af9e; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9212A8F3-D8D7-4B27-9E64-33B515928A1F}\MpKsledc5af9e.sys []
S1 MpKslef491c2b;MpKslef491c2b; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B5B3C573-387E-4AC2-B1B4-8BED76E2440F}\MpKslef491c2b.sys []
S1 MpKslf51f62ca;MpKslf51f62ca; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{835AADC9-F88A-449D-8195-205F92142825}\MpKslf51f62ca.sys []
S2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys []
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 Amusbprt;A4Tech HID-compliant Mouse Driver; C:\Windows\system32\DRIVERS\Amusbprt.sys [2007-05-14 14336]
S3 appliandMP;appliandMP; C:\Windows\system32\DRIVERS\appliand.sys []
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 cpudrv;cpudrv; \??\C:\Program Files\SystemRequirementsLab\cpudrv.sys [2009-12-18 11336]
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys []
S3 DSGACommsDriver;DSGACommsDriver; \??\C:\WINDOWS\system32\drivers\DSGACommsDriver.sys [2009-09-30 19168]
S3 DSGAFilterDriver;DSGAFilterDriver; \??\C:\WINDOWS\system32\drivers\DSGAFilterDriver.sys [2009-09-30 17632]
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys [2008-09-17 27672]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-02-03 26176]
S3 HTCAND32;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys [2009-10-26 25088]
S3 htcnprot;HTC NDIS Protocol Driver; C:\Windows\system32\DRIVERS\htcnprot.sys [2010-06-23 23040]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys []
S3 MagicTune;MagicTune; C:\Windows\system32\drivers\MTiCtwl.sys [2006-08-28 13312]
S3 MonitorFunction;Driver for Monitor; C:\Windows\system32\DRIVERS\TVMonitor.sys [2011-01-12 13304]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-10-03 133120]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 skfiltv;skfiltv; C:\Windows\system32\drivers\skfiltv.sys [2008-08-14 17408]
S3 SMARTMouseFilterx86;HID-compliant mouse; C:\Windows\system32\DRIVERS\SMARTMouseFilterx86.sys [2010-06-15 11048]
S3 SMARTVHidMini2000x86;SMART HID Device; C:\Windows\system32\DRIVERS\SMARTVHidMini2000x86.sys [2010-06-15 14120]
S3 SMARTVTabletPCx86;SMART Virtual TabletPC; C:\Windows\system32\DRIVERS\SMARTVTabletPCx86.sys [2010-06-15 13440]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 TVICHW32;TVICHW32; \??\C:\Windows\system32\DRIVERS\TVICHW32.SYS [2009-11-11 23600]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 15872]
S3 ute3nda2;AVZ Kernel Driver; \??\C:\Windows\system32\Drivers\ute3nda2.sys [2011-03-02 7168]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 astcc;AST Service; C:\WINDOWS\system32\ASTSRV.EXE [2009-09-15 61760]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-05-26 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 11736]
R2 nlsX86cc;NLS Service; C:\Windows\system32\NLSSRV32.EXE [2011-01-12 68928]
R2 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [2011-04-07 612456]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-04-08 2218600]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-16 80896]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-05-20 66872]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-04-07 378472]
R2 TeamViewer6;TeamViewer 6; C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe [2011-04-15 2280312]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 AsSysCtrlService;ASUS System Control Service; C:\Program Files\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe [2008-08-15 86016]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate1c9ba1b510f0c16;Služba Google Update (gupdate1c9ba1b510f0c16); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-04-10 133104]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-11-26 79360]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-04-10 133104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-06-02 637952]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2011-05-12 403240]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S4 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
Zizou
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 65
Registrován: 22 črc 2010 16:11
Kontaktovat uživatele:

Re: srchasm.dll

#2 Příspěvek od Zizou »

CF:

ComboFix 11-06-08.01 - Honzik 08.06.2011 23:34:32.2.8 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3062.1853 [GMT 2:00]
Spuštěný z: c:\users\Honzik\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Steam\Steam.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-05-08 do 2011-06-08 )))))))))))))))))))))))))))))))
.
.
2011-06-08 21:40 . 2011-06-08 21:40 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-06-08 21:40 . 2011-06-08 21:40 -------- d-----w- c:\users\Intel\AppData\Local\temp
2011-06-08 21:40 . 2011-06-08 21:40 -------- d-----w- c:\users\IDE\AppData\Local\temp
2011-06-08 21:40 . 2011-06-08 21:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-08 21:24 . 2011-06-08 21:24 28752 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5213B8DA-033D-41F0-9BFC-5E0F5A138A9C}\MpKsl3aee28ca.sys
2011-06-08 21:24 . 2011-05-09 20:46 6962000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5213B8DA-033D-41F0-9BFC-5E0F5A138A9C}\mpengine.dll
2011-06-08 18:11 . 2011-06-08 18:14 -------- d-----w- c:\program files\JDownloader
2011-06-08 17:53 . 2006-01-09 13:01 86016 ----a-w- c:\windows\system32\gigagetbho_v10.dll
2011-06-08 17:52 . 2011-06-08 17:52 -------- d-----w- c:\program files\Giganology
2011-06-08 14:12 . 2011-06-08 14:13 -------- d-----w- c:\users\Honzik\KBCertifikat
2011-06-08 11:13 . 2011-06-08 11:23 -------- d-----w- c:\users\Honzik\AppData\Local\BuildAGadget Content
2011-06-07 08:35 . 2011-06-08 20:28 -------- d-----w- c:\programdata\PopCap Games
2011-06-04 17:33 . 2011-06-04 17:36 -------- d-----w- c:\program files\Rovio
2011-06-04 16:43 . 2011-06-04 16:43 -------- d-----w- c:\program files\Wyse
2011-05-31 15:12 . 2011-05-31 15:13 -------- d-----w- c:\users\Honzik\AppData\Roaming\BatteryBar
2011-05-31 15:12 . 2011-05-31 15:14 -------- d-----w- c:\program files\BatteryBar
2011-05-30 14:55 . 2011-05-30 14:55 -------- d-----w- c:\program files\BSRemote
2011-05-29 12:57 . 2011-05-29 13:06 -------- d-----w- c:\users\Honzik\AppData\Roaming\MyPhoneExplorer
2011-05-29 12:56 . 2011-05-29 12:57 -------- d-----w- c:\program files\MyPhoneExplorer
2011-05-28 18:31 . 2011-05-28 18:31 -------- d-----w- c:\program files\IrfanView
2011-05-28 11:41 . 2011-05-28 11:41 -------- d-----w- c:\program files\Android Notifier Desktop
2011-05-26 15:07 . 2011-05-26 15:07 -------- d-----w- c:\program files\Common Files\Java
2011-05-26 15:05 . 2011-05-26 15:04 472808 ----a-w- c:\program files\Mozilla Firefox\Plugins\npdeployJava1.dll
2011-05-25 15:12 . 2011-04-22 19:14 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-05-24 13:10 . 2011-05-24 13:10 -------- d-----w- c:\program files\O2
2011-05-24 12:40 . 2011-05-24 12:40 -------- d-----w- c:\users\Honzik\AppData\Roaming\O2
2011-05-22 13:44 . 2011-05-22 13:44 -------- d-----w- c:\program files\Android
2011-05-22 13:18 . 2011-05-16 17:01 162544 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2011-05-22 13:18 . 2011-05-16 17:01 44720 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2011-05-22 13:18 . 2011-05-22 13:18 -------- d-----w- c:\program files\Oracle
2011-05-21 11:01 . 2011-04-23 12:24 439632 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-05-21 11:01 . 2011-04-23 12:24 439632 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C9E7154C-A635-4652-8A7F-2E635D965331}\gapaengine.dll
2011-05-19 12:19 . 2011-04-09 05:56 123904 ----a-w- c:\windows\system32\poqexec.exe
2011-05-16 17:01 . 2011-05-16 17:01 122224 ----a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
2011-05-16 17:01 . 2011-05-16 17:01 111280 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2011-05-16 17:00 . 2011-05-16 17:00 135472 ----a-w- c:\windows\system32\VBoxNetFltNotify.dll
2011-05-14 20:49 . 2011-06-08 08:51 -------- d-----w- c:\programdata\NVIDIA
2011-05-14 20:49 . 2011-05-31 14:58 -------- d-----w- c:\users\UpdatusUser
2011-05-14 20:42 . 2011-04-08 05:14 855656 ----a-w- c:\windows\system32\nvgenco322060.dll
2011-05-14 20:42 . 2011-04-08 05:14 6299752 ----a-w- c:\windows\system32\nvwgf2um.dll
2011-05-14 20:42 . 2011-04-08 05:14 57960 ----a-w- c:\windows\system32\OpenCL.dll
2011-05-14 20:42 . 2011-04-08 05:14 15227496 ----a-w- c:\windows\system32\nvoglv32.dll
2011-05-14 20:42 . 2011-04-08 05:14 10690024 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-05-14 20:42 . 2011-04-08 05:14 944232 ----a-w- c:\windows\system32\nvdispco3220140.dll
2011-05-14 20:42 . 2011-04-08 05:14 5180824 ----a-w- c:\windows\system32\nvcuda.dll
2011-05-14 20:42 . 2011-04-08 05:14 2765928 ----a-w- c:\windows\system32\nvcuvid.dll
2011-05-14 20:42 . 2011-04-08 05:14 2074216 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-05-14 20:42 . 2011-04-08 05:14 2034280 ----a-w- c:\windows\system32\nvapi.dll
2011-05-14 20:42 . 2011-04-08 05:14 13007464 ----a-w- c:\windows\system32\nvcompiler.dll
2011-05-14 20:42 . 2011-04-08 05:14 10071656 ----a-w- c:\windows\system32\nvd3dum.dll
2011-05-14 15:34 . 2011-06-03 13:01 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-14 15:18 . 2011-05-14 15:18 -------- d-----w- c:\users\Honzik\AppData\Roaming\7stacks
2011-05-14 12:23 . 2011-05-14 23:21 -------- d-----w- c:\program files\Alastria Software
2011-05-13 13:26 . 2011-05-13 13:26 -------- d-----w- c:\users\Honzik\AppData\Roaming\Chrome
2011-05-13 13:26 . 2011-05-13 13:28 -------- d-----w- c:\program files\Chrome Extensions
2011-05-13 12:43 . 2011-05-26 15:16 -------- d-----w- c:\programdata\Skype Extras
2011-05-11 09:49 . 2011-04-09 06:02 3967872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-05-11 09:49 . 2011-04-09 06:02 3912576 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-05-11 09:49 . 2011-03-25 02:57 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2011-05-11 09:49 . 2011-03-25 02:58 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2011-05-11 09:49 . 2011-03-25 02:58 284672 ----a-w- c:\windows\system32\drivers\usbport.sys
2011-05-11 09:49 . 2011-03-25 02:58 75776 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-05-11 09:49 . 2011-03-25 02:57 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2011-05-11 09:49 . 2011-03-25 02:57 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2011-05-11 09:49 . 2011-03-25 02:57 5888 ----a-w- c:\windows\system32\drivers\usbd.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-26 15:04 . 2010-05-09 10:25 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-09 20:46 . 2011-04-25 11:11 6962000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-04-13 22:40 . 2011-04-13 22:40 4284416 ----a-w- c:\windows\system32\GPhotos.scr
2011-04-11 07:04 . 2011-04-22 12:44 7071056 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{ED05786E-613D-4CBB-9D54-1127A0FFA5C2}\mpengine.dll
2011-04-09 16:55 . 2011-04-09 16:55 15453336 ----a-w- c:\windows\system32\xlive.dll
2011-04-09 16:55 . 2011-04-09 16:55 13642904 ----a-w- c:\windows\system32\xlivefnt.dll
2011-04-08 05:14 . 2011-05-14 20:42 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2011-04-07 20:45 . 2011-04-07 20:45 580200 ----a-w- c:\windows\system32\easyUpdatusAPIU.dll
2011-04-07 20:45 . 2011-04-07 20:45 66664 ----a-w- c:\windows\system32\nvshext.dll
2011-04-07 20:45 . 2011-04-07 20:45 612456 ----a-w- c:\windows\system32\nvvsvc.exe
2011-04-07 20:45 . 2011-04-07 20:45 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-04-07 20:44 . 2011-04-07 20:44 3701352 ----a-w- c:\windows\system32\nvcpl.dll
2011-04-07 20:44 . 2011-04-07 20:44 2565224 ----a-w- c:\windows\system32\nvsvc.dll
2011-03-21 11:22 . 2011-03-21 11:22 80416 ----a-w- c:\windows\system32\RtNicProp32.dll
2011-03-21 11:22 . 2011-03-21 11:22 362600 ----a-w- c:\windows\system32\drivers\Rt86win7.sys
2011-03-21 11:22 . 2010-02-03 10:24 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2011-03-15 14:00 . 2011-03-15 14:00 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-03-15 14:00 . 2011-03-15 14:00 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-03-15 14:00 . 2011-03-15 14:00 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-03-15 14:00 . 2011-03-15 14:00 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-03-15 14:00 . 2011-03-15 14:00 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-03-15 14:00 . 2011-03-15 14:00 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-03-15 14:00 . 2011-03-15 14:00 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-15 14:00 . 2011-03-15 14:00 367104 ----a-w- c:\windows\system32\html.iec
2011-03-15 14:00 . 2011-03-15 14:00 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-03-15 14:00 . 2011-03-15 14:00 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-03-15 14:00 . 2011-03-15 14:00 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-03-15 14:00 . 2011-03-15 14:00 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-03-15 14:00 . 2011-03-15 14:00 161792 ----a-w- c:\windows\system32\msls31.dll
2011-03-15 14:00 . 2011-03-15 14:00 152064 ----a-w- c:\windows\system32\wextract.exe
2011-03-15 14:00 . 2011-03-15 14:00 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-03-15 14:00 . 2011-03-15 14:00 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-03-15 14:00 . 2011-03-15 14:00 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-03-15 14:00 . 2011-03-15 14:00 11776 ----a-w- c:\windows\system32\mshta.exe
2011-03-15 14:00 . 2011-03-15 14:00 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-03-15 14:00 . 2011-03-15 14:00 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-03-15 14:00 . 2011-03-15 14:00 101888 ----a-w- c:\windows\system32\admparse.dll
2011-03-12 11:23 . 2011-04-27 15:18 870912 ----a-w- c:\windows\system32\XpsPrint.dll
2011-03-11 05:39 . 2011-04-27 15:19 148864 ----a-w- c:\windows\system32\drivers\storport.sys
2011-03-11 05:39 . 2011-04-27 15:19 1211264 ----a-w- c:\windows\system32\drivers\ntfs.sys
2011-03-11 05:39 . 2011-04-27 15:19 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys
2011-03-11 05:39 . 2011-04-27 15:19 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys
2011-03-11 05:38 . 2011-04-27 15:19 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2011-03-11 05:38 . 2011-04-27 15:19 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys
2011-03-11 05:38 . 2011-04-27 15:19 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys
2011-03-11 05:33 . 2011-04-15 14:25 1137664 ----a-w- c:\windows\system32\mfc42.dll
2011-03-11 05:33 . 2011-04-15 14:25 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-11 05:33 . 2011-04-27 15:19 1699328 ----a-w- c:\windows\system32\esent.dll
2011-03-11 05:31 . 2011-04-27 15:19 74240 ----a-w- c:\windows\system32\fsutil.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\opera\program\plugins\ssldivx.dll
2011-05-04 19:41 . 2011-03-22 16:11 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\Honzik\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\Honzik\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\Honzik\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\Honzik\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2010-11-20 144384]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"PicPick Start"="c:\program files\PicPick\picpick.exe" [2011-05-06 10822656]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"Unified Remote v2"="c:\program files\Unified Remote\RemoteServer.exe" [2011-05-07 177152]
"ICQ"="c:\program files\ICQ7.5\ICQ.exe" [2011-05-01 124216]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2009-07-14 354304]
"B0126BAED94CD465241FB2FC069A50FE1AD1022E._service_run"="c:\users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe" [2011-06-06 1011768]
"FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2010-08-09 248832]
"BSRemote"="c:\program files\BSRemote\BSRemoteServer_32.exe" [2011-05-28 104448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 932288]
"HTC Sync Loader"="c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2010-10-28 294912]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
"PocketCloud Location"="c:\program files\Wyse\PocketCloud Windows Companion\WyseBrowser.exe" [2011-03-24 399872]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
.
c:\users\Honzik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
android-notifier-desktop.lnk - c:\program files\Android Notifier Desktop\android-notifier-desktop.exe [2010-10-6 608523]
Dropbox.lnk - c:\users\Honzik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2010-06-22 202088]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^Honzik^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\users\Honzik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Honzik^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Otevřít poznámkový blok.onetoc2]
path=c:\users\Honzik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Otevřít poznámkový blok.onetoc2
backup=c:\windows\pss\Otevřít poznámkový blok.onetoc2.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Honzik^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk]
path=c:\users\Honzik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccleaner]
2011-05-25 19:55 2301752 ----a-w- c:\program files\CCleaner\CCleaner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-01-20 09:20 1305408 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gaming 3]
2009-11-09 08:28 1216512 ----a-w- c:\gaming mouse\Gaming 3.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
2008-11-18 03:27 36864 ----a-r- c:\windows\RaidTool\xInsIDE.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Six Engine]
2008-11-13 20:31 5974528 ----a-w- c:\program files\ASUS\EPU-6 Engine\SixEngine.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TurboV]
2008-10-21 20:14 4040192 ----a-w- c:\program files\ASUS\TurboV\TurboV.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VolPanel]
2008-08-27 16:19 233588 ------w- c:\program files\Creative\USB Headsets\Volume Panel\VolPanlu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WLSync]
2010-09-22 22:19 1448800 ----a-w- c:\program files\Windows Live\Mesh\WLSync.exe
.
R1 MpKsl0340f651;MpKsl0340f651;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{593ACB23-F587-4832-A78D-99B67C1C53E5}\MpKsl0340f651.sys [x]
R1 MpKsl1975be5b;MpKsl1975be5b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{288CBA9C-5405-4F62-9C38-80E78B696D9B}\MpKsl1975be5b.sys [x]
R1 MpKsl26304fe0;MpKsl26304fe0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E90FDFC9-0DF3-4A0B-9477-68D5CCBAC0FB}\MpKsl26304fe0.sys [x]
R1 MpKsl36bee938;MpKsl36bee938;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{835AADC9-F88A-449D-8195-205F92142825}\MpKsl36bee938.sys [x]
R1 MpKsl448e424c;MpKsl448e424c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{590B22E2-838D-49F2-91E8-713F44DAF245}\MpKsl448e424c.sys [x]
R1 MpKsl479c9c00;MpKsl479c9c00;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F55A04F7-6CCE-4C1D-A54A-C54E61D77E1B}\MpKsl479c9c00.sys [x]
R1 MpKsl5981ba83;MpKsl5981ba83;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{72623F6E-E661-46A1-AC25-998F994F85EB}\MpKsl5981ba83.sys [x]
R1 MpKsl62250eeb;MpKsl62250eeb;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{14698E4C-E468-4440-955E-F8D19496F4E2}\MpKsl62250eeb.sys [x]
R1 MpKsl659e98a9;MpKsl659e98a9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2581424A-C3BE-422B-B970-56B2F126C3F1}\MpKsl659e98a9.sys [x]
R1 MpKsl67ec1c8b;MpKsl67ec1c8b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4DC72EFF-217B-414C-B3FD-16AB9B539497}\MpKsl67ec1c8b.sys [x]
R1 MpKsl6f6700e8;MpKsl6f6700e8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC2F519D-B3AB-4164-8E37-B8472D6C061C}\MpKsl6f6700e8.sys [x]
R1 MpKsl75a41f55;MpKsl75a41f55;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC6512B3-BA56-4497-8309-BAA3CEA200F1}\MpKsl75a41f55.sys [x]
R1 MpKsl7f974c7a;MpKsl7f974c7a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{18156338-5A36-4410-8FF8-0B522029468A}\MpKsl7f974c7a.sys [x]
R1 MpKsl814199f3;MpKsl814199f3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F1BD7654-8515-4562-B92F-97627F860B0F}\MpKsl814199f3.sys [x]
R1 MpKsl82251cfe;MpKsl82251cfe;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4309D1AE-3F07-45D6-ACD6-4DCC8B9DBE79}\MpKsl82251cfe.sys [x]
R1 MpKsl882c7e61;MpKsl882c7e61;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC6512B3-BA56-4497-8309-BAA3CEA200F1}\MpKsl882c7e61.sys [x]
R1 MpKsl9b11a6c8;MpKsl9b11a6c8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{18156338-5A36-4410-8FF8-0B522029468A}\MpKsl9b11a6c8.sys [x]
R1 MpKslb053ee18;MpKslb053ee18;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F793646-70E3-4918-B62E-55324839D95E}\MpKslb053ee18.sys [x]
R1 MpKslbbbd644e;MpKslbbbd644e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D295FA0F-84C8-45B9-BB57-C892F6FCE108}\MpKslbbbd644e.sys [x]
R1 MpKslbff4a388;MpKslbff4a388;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2F9BA8C-EEE4-4075-A891-050B79464AD4}\MpKslbff4a388.sys [x]
R1 MpKslc5e74ba3;MpKslc5e74ba3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4C6BA80C-A768-46C8-83A6-6B5F4478E38D}\MpKslc5e74ba3.sys [x]
R1 MpKsldbb27d07;MpKsldbb27d07;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F032B02A-F541-4676-80FB-D54D5396142A}\MpKsldbb27d07.sys [x]
R1 MpKsle4ebc3fd;MpKsle4ebc3fd;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BDF64828-6C77-4552-996E-4B602E872877}\MpKsle4ebc3fd.sys [x]
R1 MpKsledc5af9e;MpKsledc5af9e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9212A8F3-D8D7-4B27-9E64-33B515928A1F}\MpKsledc5af9e.sys [x]
R1 MpKslef491c2b;MpKslef491c2b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B5B3C573-387E-4AC2-B1B4-8BED76E2440F}\MpKslef491c2b.sys [x]
R1 MpKslf51f62ca;MpKslf51f62ca;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{835AADC9-F88A-449D-8195-205F92142825}\MpKslf51f62ca.sys [x]
R2 AsSysCtrlService;ASUS System Control Service;c:\program files\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe [2008-08-15 86016]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1c9ba1b510f0c16;Služba Google Update (gupdate1c9ba1b510f0c16);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-10 133104]
R3 appliandMP;appliandMP;c:\windows\system32\DRIVERS\appliand.sys [x]
R3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [2009-12-18 11336]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-11-26 79360]
R3 DSGACommsDriver;DSGACommsDriver;c:\windows\system32\drivers\DSGACommsDriver.sys [2009-09-30 19168]
R3 DSGAFilterDriver;DSGAFilterDriver;c:\windows\system32\drivers\DSGAFilterDriver.sys [2009-09-30 17632]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-10 133104]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-10-26 25088]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-23 23040]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
R3 MonitorFunction;Driver for Monitor;c:\windows\system32\DRIVERS\TVMonitor.sys [2011-01-12 13304]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 skfiltv;skfiltv;c:\windows\system32\drivers\skfiltv.sys [2008-08-14 17408]
R3 SMARTMouseFilterx86;HID-compliant mouse;c:\windows\system32\DRIVERS\SMARTMouseFilterx86.sys [2010-06-15 11048]
R3 SMARTVHidMini2000x86;SMART HID Device;c:\windows\system32\DRIVERS\SMARTVHidMini2000x86.sys [2010-06-15 14120]
R3 SMARTVTabletPCx86;SMART Virtual TabletPC;c:\windows\system32\DRIVERS\SMARTVTabletPCx86.sys [2010-06-15 13440]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 TVICHW32;TVICHW32;c:\windows\system32\DRIVERS\TVICHW32.SYS [2009-11-11 23600]
R3 ute3nda2;AVZ Kernel Driver;c:\windows\system32\Drivers\ute3nda2.sys [2011-03-02 7168]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-27 1343400]
R4 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu;c:\program files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 MpKsl3aee28ca;MpKsl3aee28ca;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5213B8DA-033D-41F0-9BFC-5E0F5A138A9C}\MpKsl3aee28ca.sys [2011-06-08 28752]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-05-16 162544]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-05-16 44720]
S2 ncryptpro;ncryptpro;c:\windows\system32\Drivers\ncryptpro.sys [2009-08-11 186720]
S2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [2011-01-12 68928]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-04-08 2218600]
S2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-16 80896]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-04-07 378472]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-04-15 2280312]
S2 thdudf;TOSHIBA UDF2.5 Reader File System Driver;c:\windows\system32\DRIVERS\thdudf.sys [2006-11-11 66944]
S2 WysePocketCloud;Wyse PocketCloud;c:\program files\Wyse\PocketCloud Windows Companion\PocketCloudService.exe [2011-03-24 83968]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-03-21 362600]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-05-16 111280]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-05-16 122224]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MPKSL3AEE28CA
*NewlyCreated* - MPKSL4BD516F5
*Deregistered* - ehdrv
*Deregistered* - epfw
*Deregistered* - epfwtdi
*Deregistered* - MpKsl4bd516f5
.
Obsah adresáře 'Naplánované úlohy'
.
2011-06-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-10 20:31]
.
2011-06-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-10 20:31]
.
2011-06-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-350281380-233495102-1455855570-1004Core.job
- c:\users\Honzik\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-17 17:03]
.
2011-06-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-350281380-233495102-1455855570-1004UA.job
- c:\users\Honzik\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-17 17:03]
.
.
------- Doplňkový sken -------
.
uDefault_Search_URL = hxxp://www.google.com/ie
uStart Page = about:blank
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: &Stáhnout &vše FlashGetem - c:\program files\FlashGet\jc_all.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Honzik\AppData\Roaming\Mozilla\Firefox\Profiles\lo8zxial.default\
.
.
------- Asociace souborů -------
.
txtfile="c:\program files\PSPad editor\PSPad.exe" "%1"
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-Steam - c:\program files\Steam\steam.exe
SharedTaskScheduler-{1984D045-52CF-49cd-DB77-08F378FEA4DB} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-350281380-233495102-1455855570-1004\Software\SecuROM\License information*]
"datasecu"=hex:1a,a2,c3,2f,1a,00,aa,cf,bc,af,3b,1a,38,59,0f,ce,34,a1,c1,24,9d,
fd,f3,71,ef,ca,9e,e7,dc,b6,f9,2c,e6,0b,94,b8,4c,dd,e3,cb,a6,ea,81,b1,d0,8c,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Premiere Pro\1.5\DefaultPreset]
@DACL=(02 0000)
@="c:\\Program Files\\Adobe\\Premiere Pro 1.5 Tryout\\Settings\\DV - NTSC\\Standard 48kHz.prpreset"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Premiere Pro\1.5\Help]
@DACL=(02 0000)
"AdobeMediaEncoder"="c:\\Program Files\\Adobe\\Premiere Pro 1.5 Tryout\\Help\\1_0_0_0.html"
"Contents"="c:\\Program Files\\Adobe\\Premiere Pro 1.5 Tryout\\Help\\1_0_0_0.html"
"ExportToDVD"="c:\\Program Files\\Adobe\\Premiere Pro 1.5 Tryout\\Help\\1_19_2_0.html"
"HowToUse"="c:\\Program Files\\Adobe\\Premiere Pro 1.5 Tryout\\Help\\0_0_0_0.html"
"Keyboard"="c:\\Program Files\\Adobe\\Premiere Pro 1.5 Tryout\\Help\\1_21_0_0.html"
"Search"="c:\\Program Files\\Adobe\\Premiere Pro 1.5 Tryout\\Help\\search.html"
"Support"="http://www.adobe.com/support/products/premiere.html"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-06-08 23:42:38
ComboFix-quarantined-files.txt 2011-06-08 21:42
ComboFix2.txt 2011-04-21 17:06
.
Před spuštěním: Volných bajtů: 55 306 633 216
Po spuštění: Volných bajtů: 55 151 611 904
.
- - End Of File - - 4B85EF4CF7B9EF4E3CD2C5149EDF3C84

Uživatelský avatar
Zizou
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 65
Registrován: 22 črc 2010 16:11
Kontaktovat uživatele:

Re: srchasm.dll

#3 Příspěvek od Zizou »

*omylem doublepost*

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: srchasm.dll

#4 Příspěvek od motji »

Dobré ranko :)

:arrow: Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
Zizou
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 65
Registrován: 22 črc 2010 16:11
Kontaktovat uživatele:

Re: srchasm.dll

#5 Příspěvek od Zizou »

Dobré odpoledne :)

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Verze databáze: 6817

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

9.6.2011 13:10:25
mbam-log-2011-06-09 (13-10-20).txt

Typ: Úplná kontrola (C:\|)
Kontrolované objekty: 410351
Uplynulý čas: 1 hodin, 12 minut, 12 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 3

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
c:\program files\installapk\installapk.exe (Trojan.Agent) -> No action taken.
c:\Users\Honzik\AppData\Local\Xenocode\XSandbox\installapk\1.0.0.0\2009.06.01t16.17\Virtual\STUBEXE\@programfiles@\installapk\adb.EXE (Trojan.Agent) -> No action taken.
c:\Users\Honzik\AppData\Local\Xenocode\XSandbox\installapk\1.0.0.0\2009.06.01t16.17\Virtual\STUBEXE\@programfiles@\installapk\installapk.exe (Trojan.Agent) -> No action taken.


Myslím si, že zrovna tyhle soubory nejsou infikované. Jedná se o nástroje pro instalaci *.apk aplikací přímo z PC do Androidu.

Pro jistotu výsledky z VirusTotal:

c:\program files\installapk\installapk.exe - http://goo.gl/bwVUY
c:\Users\Honzik\AppData\Local\Xenocode\XSandbox\installapk\1.0.0.0\2009.06.01t16.17\Virtual\STUBEXE\@programfiles@\installapk\adb.EXE - http://goo.gl/tWklC
c:\Users\Honzik\AppData\Local\Xenocode\XSandbox\installapk\1.0.0.0\2009.06.01t16.17\Virtual\STUBEXE\@programfiles@\installapk\installapk.exe - http://goo.gl/PMp8B

Větší starost mi ale dělá ten srchasm.dll, jestli je pryč. :roll: Chytil jsem ho z jednoho traineru ke hře, MSE ho sice identifikoval ale zneškodnit neuměl.

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: srchasm.dll

#6 Příspěvek od cernohous13 »

Zdravím, než se objeví motji, tak jí připrav log
:arrow: Stáhni "System Look" - http://jpshortstuff.247fixes.com/SystemLook.exe
Spusť jej a do okna zkopíruj

Kód: Vybrat vše

:filefind
srchasm.dll
Klik na Look a po scanu sem zkopíruj výsledek hledání
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Uživatelský avatar
Zizou
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 65
Registrován: 22 črc 2010 16:11
Kontaktovat uživatele:

Re: srchasm.dll

#7 Příspěvek od Zizou »

Tak to nic nenašlo.

SystemLook 04.09.10 by jpshortstuff
Log created at 19:03 on 09/06/2011 by Honzik
Administrator - Elevation successful

========== filefind ==========

Searching for "srchasm.dll"
No files found.

-= EOF =-

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: srchasm.dll

#8 Příspěvek od motji »

Antivir ten soubor stále nachází?
V mbamu tedy nemažte.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
Zizou
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 65
Registrován: 22 črc 2010 16:11
Kontaktovat uživatele:

Re: srchasm.dll

#9 Příspěvek od Zizou »

No v MSE je pouze vidět v historii, ale když jej nenašel ani SystemLook, tak by měl být pryč, že?

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: srchasm.dll

#10 Příspěvek od motji »

Já ho nikde nevidím, takže pravděpodobně ano. udělejte ještě přes MSE uplný sken, zda ho najde.
Jinak to s pc vypadá jak?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
Zizou
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 65
Registrován: 22 črc 2010 16:11
Kontaktovat uživatele:

Re: srchasm.dll

#11 Příspěvek od Zizou »

Takže MSE po úplném skenu nic nenašel. PC se chová normálně. Pokud je to vše, děkuji za kontrolu. :)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: srchasm.dll

#12 Příspěvek od motji »

:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://tharifas.sweb.cz/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
Zizou
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 65
Registrován: 22 črc 2010 16:11
Kontaktovat uživatele:

Re: srchasm.dll

#13 Příspěvek od Zizou »

Provedeno. :turned:

PC se chová standardně, jen mě ten srchasm.dll vylekal. Ale jak jsme ho teda vyléčili? MSE mi napsal, že ho neumí odstranit, Combofix ho nenašel. Že by falešná detekce?

Nový log z RSIT:


Logfile of random's system information tool 1.08 (written by random/random)
Run by Honzik at 2011-06-10 23:00:49
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 49 GB (8%) free of 610 GB
Total RAM: 3062 MB (44% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:01:11, on 10.6.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Wyse\PocketCloud Windows Companion\WyseBrowser.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\PicPick\picpick.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Unified Remote\RemoteServer.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\ICQ7.5\ICQ.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files\FileHippo.com\UpdateChecker.exe
C:\Program Files\BSRemote\BSRemoteServer_32.exe
C:\Program Files\Steam\Steam.exe
C:\Users\Honzik\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Java\jre6\launch4j-tmp\android-notifier-desktop.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Users\Honzik\Downloads\RSIT.exe
C:\Program Files\trend micro\Honzik.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Mouse Gestures - {A6A49249-57AE-4295-8D4D-18A9502C7D8E} - C:\Program Files\Internet Explorer\Plugins\Drowse\MouseGestures.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [HTC Sync Loader] "C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [PocketCloud Location] C:\Program Files\Wyse\PocketCloud Windows Companion\WyseBrowser.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [PicPick Start] C:\Program Files\PicPick\picpick.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Unified Remote v2] C:\Program Files\Unified Remote\RemoteServer.exe
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.5\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [B0126BAED94CD465241FB2FC069A50FE1AD1022E._service_run] "C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service
O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background
O4 - HKCU\..\Run: [BSRemote] C:\Program Files\BSRemote\BSRemoteServer_32.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKUS\S-1-5-21-350281380-233495102-1455855570-1011\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-350281380-233495102-1455855570-1011\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: android-notifier-desktop.lnk = ?
O4 - Startup: Dropbox.lnk = Honzik\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: &Stáhnout &vše FlashGetem - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {4E660F19-E91E-41E1-88EF-D1DFAB118F67} - C:\Program Files\Internet Explorer\Plugins\Drowse\MouseGestures.dll
O9 - Extra 'Tools' menuitem: Mouse Gestures... - {4E660F19-E91E-41E1-88EF-D1DFAB118F67} - C:\Program Files\Internet Explorer\Plugins\Drowse\MouseGestures.dll
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos-be ... canner.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe
O23 - Service: AST Service (astcc) - Nalpeiron Ltd. - C:\WINDOWS\system32\ASTSRV.EXE
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Služba Google Update (gupdate1c9ba1b510f0c16) (gupdate1c9ba1b510f0c16) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NLSSRV32.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: Wyse PocketCloud (WysePocketCloud) - Unknown owner - C:\Program Files\Wyse\PocketCloud Windows Companion\PocketCloudService.exe

--
End of file - 13345 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-350281380-233495102-1455855570-1004Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-350281380-233495102-1455855570-1004UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22 191792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-11-10 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6A49249-57AE-4295-8D4D-18A9502C7D8E}]
Mouse Gestures - C:\Program Files\Internet Explorer\Plugins\Drowse\MouseGestures.dll [2009-07-25 741376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL [2010-01-16 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-26 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-01-21 91520]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
"HTC Sync Loader"=C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2010-10-28 294912]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 997408]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-01-07 253672]
"PocketCloud Location"=C:\Program Files\Wyse\PocketCloud Windows Companion\WyseBrowser.exe [2011-03-24 399872]
"googletalk"=C:\Program Files\Google\Google Talk\googletalk.exe [2007-01-01 3739648]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2011-05-29 449584]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2010-11-20 144384]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]
"PicPick Start"=C:\Program Files\PicPick\picpick.exe [2011-05-06 10822656]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"Unified Remote v2"=C:\Program Files\Unified Remote\RemoteServer.exe [2011-05-07 177152]
"ICQ"=C:\Program Files\ICQ7.5\ICQ.exe [2011-05-01 124216]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 354304]
"B0126BAED94CD465241FB2FC069A50FE1AD1022E._service_run"=C:\Users\Honzik\AppData\Local\Google\Chrome\Application\chrome.exe [2011-06-06 1011768]
"FileHippo.com"=C:\Program Files\FileHippo.com\UpdateChecker.exe [2010-08-09 248832]
"BSRemote"=C:\Program Files\BSRemote\BSRemoteServer_32.exe [2011-05-28 104448]
"Steam"=C:\Program Files\Steam\steam.exe [2011-06-09 1242448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccleaner]
C:\Program Files\CCleaner\CCleaner.exe [2011-05-25 2301752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gaming 3]
C:\Gaming Mouse\Gaming 3.exe [2009-11-09 1216512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
C:\WINDOWS\RaidTool\xInsIDE.exe [2008-11-18 36864]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Six Engine]
C:\Program Files\ASUS\EPU-6 Engine\SixEngine.exe [2008-11-13 5974528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TurboV]
C:\Program Files\ASUS\TurboV\TurboV.exe [2008-10-21 4040192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VolPanel]
C:\Program Files\Creative\USB Headsets\Volume Panel\VolPanlu.exe [2008-08-27 233588]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WLSync]
C:\Program Files\Windows Live\Mesh\WLSync.exe [2010-09-23 1448800]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Honzik^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
C:\Users\Honzik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-05-25 24176560]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Honzik^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Otevřít poznámkový blok.onetoc2]
C:\Users\Honzik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Otevřít poznámkový blok.onetoc2 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Honzik^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk]
C:\PROGRA~1\MIF5BA~1\Office14\ONENOTEM.EXE [2010-01-21 226176]

C:\Users\Honzik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
android-notifier-desktop.lnk - C:\Program Files\Android Notifier Desktop\android-notifier-desktop.exe
Dropbox.lnk - C:\Users\Honzik\AppData\Roaming\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2011-03-15 203776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll [2010-06-22 202088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"ConsentPromptBehaviorAdmin"=0
"PromptOnSecureDesktop"=0
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Documents and Settings\Honzik\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.dll"="C:\Users\Honzik\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin"
"C:\Documents and Settings\Honzik\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe"="C:\Users\Honzik\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
"C:\Program Files\Activision\Prototype\prototypef.exe"="C:\Program Files\Activision\Prototype\prototypef.exe:*:Enabled:Prototype(TM)"
"C:\Program Files\Activision\Wolfenstein\MP\Wolf2MP.exe"="C:\Program Files\Activision\Wolfenstein\MP\Wolf2MP.exe:*:Enabled:Wolfenstein(TM) "
"C:\Program Files\Activision\Wolfenstein\MP\Wolf2MPLite.exe"="C:\Program Files\Activision\Wolfenstein\MP\Wolf2MPLite.exe:*:Enabled:Wolfenstein(TM) "
"C:\Program Files\Codemasters\FUEL\FUEL.exe"="C:\Program Files\Codemasters\FUEL\FUEL.exe:*:Enabled:FUEL"
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
"C:\Program Files\Deep Silver\S.T.A.L.K.E.R. - Clear Sky\bin\dedicated\xrEngine.exe"="C:\Program Files\Deep Silver\S.T.A.L.K.E.R. - Clear Sky\bin\dedicated\xrEngine.exe:*:Enabled:S.T.A.L.K.E.R. - Clear Sky (SRV)"
"C:\Program Files\Deep Silver\S.T.A.L.K.E.R. - Clear Sky\bin\xrEngine.exe"="C:\Program Files\Deep Silver\S.T.A.L.K.E.R. - Clear Sky\bin\xrEngine.exe:*:Enabled:S.T.A.L.K.E.R. - Clear Sky (CLI)"
"C:\Program Files\Dragon Age\bin_ship\daorigins.exe"="C:\Program Files\Dragon Age\bin_ship\daorigins.exe:*:Enabled:Dragon Age Prameny Hra"
"C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe"="C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe:*:Enabled:Dragon Age Prameny Aktualizovat"
"C:\Program Files\Dragon Age\DAOriginsLauncher.exe"="C:\Program Files\Dragon Age\DAOriginsLauncher.exe:*:Enabled:Dragon Age Prameny Spustit"
"C:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe"="C:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe:*:Enabled:Burnout(TM) Paradise The Ultimate Box"
"C:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe"="C:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe:*:Enabled:Burnout(TM) Paradise The Ultimate Box"
"C:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe"="C:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe:*:Enabled:Burnout(TM) Paradise The Ultimate Box"
"C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe"="C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:*:Enabled:Crysis_32"
"C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe"="C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:*:Enabled:CrysisDedicatedServer_32"
"C:\Program Files\FlashGet Network\FlashGet universal\FlashGet.exe"="C:\Program Files\FlashGet Network\FlashGet universal\FlashGet.exe:*:Enabled:Flashget2"
"C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdate.exe"="C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdate.exe:*:Enabled:FGLiveUpdate"
"C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdateEx.exe"="C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdateEx.exe:*:Enabled:FGLiveUpdateEx"
"C:\Program Files\FlashGet\FlashGet.exe"="C:\Program Files\FlashGet\FlashGet.exe:*:Enabled:Flashget"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe"="C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Ubisoft\Techland\Call of Juarez - Bound in Blood\CoJBiBGame_x86.exe"="C:\Program Files\Ubisoft\Techland\Call of Juarez - Bound in Blood\CoJBiBGame_x86.exe:*:Enabled:Call of Juarez - Bound in Blood"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\WINDOWS\system32\vomhlm.exe"="C:\WINDOWS\system32\vomhlm.exe:*:Enabled:ENABLE"
"C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.txt - open - "C:\Program Files\PSPad editor\PSPad.exe" "%1"

======List of files/folders created in the last 1 months======

2011-06-10 23:00:49 ----D---- C:\rsit
2011-06-10 12:40:59 ----D---- C:\Program Files\PopCap Games
2011-06-09 16:59:38 ----A---- C:\Windows\system32\nvsvcr.dll
2011-06-09 16:57:35 ----A---- C:\Windows\system32\OpenCL.dll
2011-06-09 16:57:34 ----A---- C:\Windows\system32\nvoglv32.dll
2011-06-09 16:57:34 ----A---- C:\Windows\system32\nvgenco322090.dll
2011-06-09 16:57:34 ----A---- C:\Windows\system32\nvdispco3220150.dll
2011-06-09 16:57:34 ----A---- C:\Windows\system32\nvcuvid.dll
2011-06-09 16:57:34 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-06-09 16:57:34 ----A---- C:\Windows\system32\nvcuda.dll
2011-06-09 16:57:34 ----A---- C:\Windows\system32\nvcompiler.dll
2011-06-09 16:57:34 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-06-09 15:43:06 ----D---- C:\Program Files\WindowManager
2011-06-09 11:55:34 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2011-06-09 11:55:30 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-06-08 23:42:41 ----SHD---- C:\$RECYCLE.BIN
2011-06-08 23:42:39 ----D---- C:\Windows\temp
2011-06-08 23:31:10 ----D---- C:\Qoobox
2011-06-08 20:11:31 ----D---- C:\Program Files\JDownloader
2011-06-08 19:53:03 ----A---- C:\Windows\system32\gigagetbho_v10.dll
2011-06-08 19:52:58 ----D---- C:\Program Files\Giganology
2011-06-08 12:16:10 ----A---- C:\Users\Honzik\AppData\Roaming\Network Meter_Settings.ini
2011-06-07 10:35:15 ----D---- C:\ProgramData\PopCap Games
2011-06-04 19:33:43 ----D---- C:\Program Files\Rovio
2011-06-04 18:43:21 ----D---- C:\Program Files\Wyse
2011-05-31 17:12:58 ----D---- C:\Users\Honzik\AppData\Roaming\BatteryBar
2011-05-31 17:12:57 ----D---- C:\Program Files\BatteryBar
2011-05-30 16:55:29 ----D---- C:\Program Files\BSRemote
2011-05-29 14:57:12 ----D---- C:\Users\Honzik\AppData\Roaming\MyPhoneExplorer
2011-05-29 14:56:53 ----D---- C:\Program Files\MyPhoneExplorer
2011-05-28 20:31:02 ----D---- C:\Program Files\IrfanView
2011-05-28 13:41:36 ----D---- C:\Program Files\Android Notifier Desktop
2011-05-26 17:07:07 ----D---- C:\Program Files\Common Files\Java
2011-05-26 17:05:05 ----A---- C:\Windows\system32\javaws.exe
2011-05-26 17:05:05 ----A---- C:\Windows\system32\javaw.exe
2011-05-26 17:05:05 ----A---- C:\Windows\system32\java.exe
2011-05-25 17:12:00 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2011-05-24 15:10:24 ----D---- C:\Program Files\O2
2011-05-24 14:40:18 ----D---- C:\Users\Honzik\AppData\Roaming\O2
2011-05-22 15:44:53 ----D---- C:\Program Files\Android
2011-05-22 15:18:41 ----A---- C:\Windows\system32\drivers\VBoxDrv.sys
2011-05-22 15:18:34 ----A---- C:\Windows\system32\drivers\VBoxUSBMon.sys
2011-05-22 15:18:31 ----D---- C:\Program Files\Oracle
2011-05-20 22:35:28 ----A---- C:\Windows\system32\nvStreaming.exe
2011-05-19 14:19:40 ----A---- C:\Windows\system32\poqexec.exe
2011-05-16 19:01:00 ----A---- C:\Windows\system32\drivers\VBoxNetFlt.sys
2011-05-16 19:01:00 ----A---- C:\Windows\system32\drivers\VBoxNetAdp.sys
2011-05-16 19:00:58 ----A---- C:\Windows\system32\VBoxNetFltNotify.dll
2011-05-14 22:49:20 ----D---- C:\ProgramData\NVIDIA
2011-05-14 22:42:09 ----A---- C:\Windows\system32\nvwgf2um.dll
2011-05-14 22:42:09 ----A---- C:\Windows\system32\nvgenco322060.dll
2011-05-14 22:42:08 ----A---- C:\Windows\system32\nvdispco3220140.dll
2011-05-14 22:42:08 ----A---- C:\Windows\system32\nvd3dum.dll
2011-05-14 22:42:08 ----A---- C:\Windows\system32\nvapi.dll
2011-05-14 17:18:51 ----D---- C:\Users\Honzik\AppData\Roaming\7stacks
2011-05-14 14:23:24 ----D---- C:\Program Files\Alastria Software
2011-05-13 15:26:24 ----D---- C:\Users\Honzik\AppData\Roaming\Chrome
2011-05-13 15:26:01 ----D---- C:\Program Files\Chrome Extensions
2011-05-13 14:43:40 ----D---- C:\ProgramData\Skype Extras
2011-05-11 11:49:53 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-05-11 11:49:53 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-05-11 11:49:51 ----A---- C:\Windows\system32\drivers\usbehci.sys
2011-05-11 11:49:50 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2011-05-11 11:49:50 ----A---- C:\Windows\system32\drivers\usbport.sys
2011-05-11 11:49:50 ----A---- C:\Windows\system32\drivers\usbohci.sys
2011-05-11 11:49:50 ----A---- C:\Windows\system32\drivers\usbhub.sys
2011-05-11 11:49:50 ----A---- C:\Windows\system32\drivers\usbd.sys
2011-05-11 11:49:50 ----A---- C:\Windows\system32\drivers\usbccgp.sys

======List of files/folders modified in the last 1 months======

2011-06-10 23:01:11 ----D---- C:\Program Files\trend micro
2011-06-10 23:01:02 ----D---- C:\Windows\Prefetch
2011-06-10 22:48:11 ----SHD---- C:\Windows\Installer
2011-06-10 22:48:08 ----D---- C:\Windows\system32\config
2011-06-10 22:47:58 ----D---- C:\Windows\SoftwareDistribution
2011-06-10 22:47:47 ----D---- C:\Windows\system32\FxsTmp
2011-06-10 22:47:34 ----D---- C:\Users\Honzik\AppData\Roaming\Skype
2011-06-10 22:47:34 ----D---- C:\Program Files\Steam
2011-06-10 22:47:11 ----AD---- C:\Windows
2011-06-10 22:45:53 ----D---- C:\Users\Honzik\AppData\Roaming\ICQ
2011-06-10 22:45:47 ----D---- C:\Users\Honzik\AppData\Roaming\Dropbox
2011-06-10 12:41:01 ----AD---- C:\Program Files
2011-06-10 12:39:13 ----D---- C:\AdobeTemp
2011-06-10 12:18:24 ----D---- C:\Windows\inf
2011-06-10 12:18:13 ----D---- C:\Windows\System32
2011-06-10 00:08:22 ----D---- C:\Users\Honzik\AppData\Roaming\skypePM
2011-06-09 17:02:57 ----D---- C:\Config.Msi
2011-06-09 17:01:58 ----SHD---- C:\System Volume Information
2011-06-09 17:01:31 ----D---- C:\Program Files\NVIDIA Corporation
2011-06-09 17:01:26 ----D---- C:\Windows\system32\DriverStore
2011-06-09 17:01:26 ----D---- C:\Windows\system32\catroot
2011-06-09 16:58:09 ----D---- C:\Windows\system32\drivers
2011-06-09 15:44:37 ----D---- C:\Windows\system32\Tasks
2011-06-09 11:55:34 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-06-08 23:41:07 ----A---- C:\Windows\system.ini
2011-06-08 23:41:02 ----D---- C:\Windows\system32\drivers\etc
2011-06-08 23:38:04 ----D---- C:\Windows\AppPatch
2011-06-08 23:38:03 ----D---- C:\Program Files\Common Files
2011-06-08 23:32:02 ----D---- C:\Windows\ERDNT
2011-06-08 23:22:02 ----D---- C:\Users\Honzik\AppData\Roaming\GetRightToGo
2011-06-08 14:42:16 ----RD---- C:\Program Files\Google
2011-06-08 10:51:52 ----D---- C:\ProgramData\McAfee
2011-06-07 10:35:15 ----D---- C:\ProgramData
2011-06-04 19:33:51 ----D---- C:\Users\Honzik\AppData\Roaming\Rovio
2011-06-04 18:43:02 ----RSD---- C:\Windows\assembly
2011-06-02 16:50:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-05-29 17:20:07 ----D---- C:\Windows\system32\NDF
2011-05-27 20:50:53 ----D---- C:\Users\Honzik\AppData\Roaming\FileZilla
2011-05-27 20:50:19 ----D---- C:\Windows\Logs
2011-05-27 16:11:51 ----D---- C:\Windows\system32\catroot2
2011-05-26 17:11:35 ----RD---- C:\Program Files\WinRAR
2011-05-26 17:06:08 ----RD---- C:\Program Files\Skype
2011-05-26 17:04:58 ----A---- C:\Windows\system32\deployJava1.dll
2011-05-26 16:56:49 ----D---- C:\Program Files\FileZilla FTP Client
2011-05-26 16:56:16 ----D---- C:\Program Files\Defraggler
2011-05-26 16:47:26 ----D---- C:\Program Files\Mozilla Thunderbird
2011-05-26 16:46:23 ----RD---- C:\Program Files\CCleaner
2011-05-26 14:48:07 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-05-25 22:20:06 ----D---- C:\Windows\winsxs
2011-05-25 18:44:13 ----D---- C:\Program Files\Mafia II
2011-05-25 09:24:57 ----A---- C:\Windows\system32\nvvsvc.exe
2011-05-25 09:24:56 ----A---- C:\Windows\system32\nvsvc.dll
2011-05-25 09:24:54 ----A---- C:\Windows\system32\nvshext.dll
2011-05-25 09:24:53 ----A---- C:\Windows\system32\nvmctray.dll
2011-05-25 09:24:47 ----A---- C:\Windows\system32\nvcpl.dll
2011-05-25 09:24:45 ----A---- C:\Windows\system32\easyupdatusapiu.dll
2011-05-22 15:37:23 ----RD---- C:\Program Files\Angry Birds
2011-05-22 15:18:41 ----DC---- C:\Windows\system32\DRVSTORE
2011-05-21 19:43:23 ----D---- C:\Windows\system32\wbem
2011-05-21 19:42:16 ----D---- C:\Users\Honzik\AppData\Roaming\picpick
2011-05-21 19:42:16 ----D---- C:\Users\Honzik\AppData\Roaming\Mp3tag
2011-05-21 19:42:08 ----D---- C:\Program Files\Scorpions WinCheater
2011-05-21 19:42:02 ----RD---- C:\Program Files\Opera
2011-05-21 19:41:53 ----D---- C:\Windows\AppCompat
2011-05-21 19:41:52 ----SD---- C:\Windows\Tasks
2011-05-21 19:41:52 ----D---- C:\Windows\system32\drivers\UMDF
2011-05-21 19:41:52 ----D---- C:\Windows\system32\CodeIntegrity
2011-05-21 19:41:51 ----D---- C:\Windows\registration
2011-05-20 15:23:13 ----D---- C:\Program Files\Common Files\Steam
2011-05-18 19:54:37 ----D---- C:\Program Files\Mp3tag
2011-05-18 19:54:09 ----D---- C:\Program Files\Logon Screen Rotator
2011-05-15 23:24:29 ----D---- C:\Windows\debug
2011-05-15 01:21:54 ----D---- C:\ProgramData\Microsoft Help
2011-05-15 01:21:52 ----D---- C:\Program Files\Common Files\Skype
2011-05-15 01:21:49 ----D---- C:\Program Files\PSPad editor
2011-05-15 01:21:37 ----D---- C:\Users\Honzik\AppData\Roaming\PSpad
2011-05-15 01:21:36 ----D---- C:\Windows\security
2011-05-15 01:21:36 ----D---- C:\Windows\Help
2011-05-15 01:21:36 ----D---- C:\Windows\Downloaded Program Files
2011-05-15 01:21:35 ----D---- C:\Windows\system32\Macromed
2011-05-14 22:49:20 ----RD---- C:\Users
2011-05-14 22:49:07 ----HD---- C:\Program Files\InstallShield Installation Information
2011-05-14 22:47:36 ----D---- C:\ProgramData\NVIDIA Corporation
2011-05-14 14:23:07 ----D---- C:\Program Files\Stardock
2011-05-14 14:21:19 ----D---- C:\Users\Honzik\AppData\Roaming\Stardock
2011-05-13 16:27:55 ----D---- C:\Users\Honzik\AppData\Roaming\OneUpIndustries
2011-05-13 16:27:51 ----D---- C:\ProgramData\OneUpIndustries
2011-05-11 21:21:54 ----A---- C:\Windows\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2008-11-18 83296]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2009-05-01 43528]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-02-12 431672]
R0 tdrpman;Acronis Try&Decide and Restore Points filter; C:\Windows\system32\DRIVERS\tdrpman.sys [2009-10-28 368736]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 Amfilter;A4Tech Mouse Filter Driver; C:\Windows\system32\DRIVERS\Amfilter.sys [2007-05-14 9216]
R1 AsIO;AsIO; C:\Windows\system32\drivers\AsIO.sys [2007-12-17 12400]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-10-24 165264]
R1 MpKsl5b950fee;MpKsl5b950fee; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CF674744-49C2-4AE9-8208-14AF14E9D3CF}\MpKsl5b950fee.sys [2011-06-10 28752]
R1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys [2011-05-16 162544]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows\system32\DRIVERS\VBoxUSBMon.sys [2011-05-16 44720]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-09-11 116008]
R2 ncryptpro;ncryptpro; \??\C:\WINDOWS\system32\Drivers\ncryptpro.sys [2009-08-11 186720]
R2 thdudf;TOSHIBA UDF2.5 Reader File System Driver; C:\Windows\system32\DRIVERS\thdudf.sys [2006-11-11 66944]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-05-29 22712]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2006-10-18 7680]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 P17;SB Live! 24-bit; C:\Windows\system32\drivers\P17.sys [2009-04-21 1147392]
R3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2011-03-21 362600]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2011-05-16 111280]
R3 VBoxNetFlt;VBoxNetFlt Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys [2011-05-16 122224]
S1 MpKsl0340f651;MpKsl0340f651; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{593ACB23-F587-4832-A78D-99B67C1C53E5}\MpKsl0340f651.sys []
S1 MpKsl1975be5b;MpKsl1975be5b; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{288CBA9C-5405-4F62-9C38-80E78B696D9B}\MpKsl1975be5b.sys []
S1 MpKsl26304fe0;MpKsl26304fe0; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E90FDFC9-0DF3-4A0B-9477-68D5CCBAC0FB}\MpKsl26304fe0.sys []
S1 MpKsl36bee938;MpKsl36bee938; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{835AADC9-F88A-449D-8195-205F92142825}\MpKsl36bee938.sys []
S1 MpKsl448e424c;MpKsl448e424c; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{590B22E2-838D-49F2-91E8-713F44DAF245}\MpKsl448e424c.sys []
S1 MpKsl479c9c00;MpKsl479c9c00; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F55A04F7-6CCE-4C1D-A54A-C54E61D77E1B}\MpKsl479c9c00.sys []
S1 MpKsl5981ba83;MpKsl5981ba83; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{72623F6E-E661-46A1-AC25-998F994F85EB}\MpKsl5981ba83.sys []
S1 MpKsl62250eeb;MpKsl62250eeb; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{14698E4C-E468-4440-955E-F8D19496F4E2}\MpKsl62250eeb.sys []
S1 MpKsl659e98a9;MpKsl659e98a9; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2581424A-C3BE-422B-B970-56B2F126C3F1}\MpKsl659e98a9.sys []
S1 MpKsl67ec1c8b;MpKsl67ec1c8b; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4DC72EFF-217B-414C-B3FD-16AB9B539497}\MpKsl67ec1c8b.sys []
S1 MpKsl6f6700e8;MpKsl6f6700e8; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CC2F519D-B3AB-4164-8E37-B8472D6C061C}\MpKsl6f6700e8.sys []
S1 MpKsl75a41f55;MpKsl75a41f55; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CC6512B3-BA56-4497-8309-BAA3CEA200F1}\MpKsl75a41f55.sys []
S1 MpKsl7f974c7a;MpKsl7f974c7a; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{18156338-5A36-4410-8FF8-0B522029468A}\MpKsl7f974c7a.sys []
S1 MpKsl814199f3;MpKsl814199f3; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F1BD7654-8515-4562-B92F-97627F860B0F}\MpKsl814199f3.sys []
S1 MpKsl82251cfe;MpKsl82251cfe; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4309D1AE-3F07-45D6-ACD6-4DCC8B9DBE79}\MpKsl82251cfe.sys []
S1 MpKsl882c7e61;MpKsl882c7e61; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CC6512B3-BA56-4497-8309-BAA3CEA200F1}\MpKsl882c7e61.sys []
S1 MpKsl9b11a6c8;MpKsl9b11a6c8; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{18156338-5A36-4410-8FF8-0B522029468A}\MpKsl9b11a6c8.sys []
S1 MpKslb053ee18;MpKslb053ee18; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9F793646-70E3-4918-B62E-55324839D95E}\MpKslb053ee18.sys []
S1 MpKslbbbd644e;MpKslbbbd644e; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D295FA0F-84C8-45B9-BB57-C892F6FCE108}\MpKslbbbd644e.sys []
S1 MpKslbff4a388;MpKslbff4a388; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E2F9BA8C-EEE4-4075-A891-050B79464AD4}\MpKslbff4a388.sys []
S1 MpKslc5e74ba3;MpKslc5e74ba3; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4C6BA80C-A768-46C8-83A6-6B5F4478E38D}\MpKslc5e74ba3.sys []
S1 MpKsld8069b1f;MpKsld8069b1f; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{28DA534E-4EB9-456C-B6F7-C46073BDF380}\MpKsld8069b1f.sys []
S1 MpKsldbb27d07;MpKsldbb27d07; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F032B02A-F541-4676-80FB-D54D5396142A}\MpKsldbb27d07.sys []
S1 MpKsle4ebc3fd;MpKsle4ebc3fd; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BDF64828-6C77-4552-996E-4B602E872877}\MpKsle4ebc3fd.sys []
S1 MpKsledc5af9e;MpKsledc5af9e; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9212A8F3-D8D7-4B27-9E64-33B515928A1F}\MpKsledc5af9e.sys []
S1 MpKslef491c2b;MpKslef491c2b; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B5B3C573-387E-4AC2-B1B4-8BED76E2440F}\MpKslef491c2b.sys []
S1 MpKslf51f62ca;MpKslf51f62ca; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{835AADC9-F88A-449D-8195-205F92142825}\MpKslf51f62ca.sys []
S2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys []
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 Amusbprt;A4Tech HID-compliant Mouse Driver; C:\Windows\system32\DRIVERS\Amusbprt.sys [2007-05-14 14336]
S3 appliandMP;appliandMP; C:\Windows\system32\DRIVERS\appliand.sys []
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 cpudrv;cpudrv; \??\C:\Program Files\SystemRequirementsLab\cpudrv.sys [2009-12-18 11336]
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys []
S3 DSGACommsDriver;DSGACommsDriver; \??\C:\WINDOWS\system32\drivers\DSGACommsDriver.sys [2009-09-30 19168]
S3 DSGAFilterDriver;DSGAFilterDriver; \??\C:\WINDOWS\system32\drivers\DSGAFilterDriver.sys [2009-09-30 17632]
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys [2008-09-17 27672]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-02-03 26176]
S3 HTCAND32;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys [2009-10-26 25088]
S3 htcnprot;HTC NDIS Protocol Driver; C:\Windows\system32\DRIVERS\htcnprot.sys [2010-06-23 23040]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys []
S3 MagicTune;MagicTune; C:\Windows\system32\drivers\MTiCtwl.sys [2006-08-28 13312]
S3 MonitorFunction;Driver for Monitor; C:\Windows\system32\DRIVERS\TVMonitor.sys [2011-01-12 13304]
S3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-10-03 133120]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 skfiltv;skfiltv; C:\Windows\system32\drivers\skfiltv.sys [2008-08-14 17408]
S3 SMARTMouseFilterx86;HID-compliant mouse; C:\Windows\system32\DRIVERS\SMARTMouseFilterx86.sys [2010-06-15 11048]
S3 SMARTVHidMini2000x86;SMART HID Device; C:\Windows\system32\DRIVERS\SMARTVHidMini2000x86.sys [2010-06-15 14120]
S3 SMARTVTabletPCx86;SMART Virtual TabletPC; C:\Windows\system32\DRIVERS\SMARTVTabletPCx86.sys [2010-06-15 13440]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 TVICHW32;TVICHW32; \??\C:\Windows\system32\DRIVERS\TVICHW32.SYS [2009-11-11 23600]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 15872]
S3 ute3nda2;AVZ Kernel Driver; \??\C:\Windows\system32\Drivers\ute3nda2.sys [2011-03-02 7168]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe [2008-08-15 86016]
R2 astcc;AST Service; C:\WINDOWS\system32\ASTSRV.EXE [2009-09-15 61760]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-05-26 153376]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 11736]
R2 nlsX86cc;NLS Service; C:\Windows\system32\NLSSRV32.EXE [2011-01-12 68928]
R2 NVSvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-05-25 615528]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-25 2214504]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-16 80896]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-05-20 66872]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-05-20 378472]
R2 TeamViewer6;TeamViewer 6; C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe [2011-04-15 2280312]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate1c9ba1b510f0c16;Služba Google Update (gupdate1c9ba1b510f0c16); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-04-10 133104]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-11-26 79360]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-04-10 133104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-06-02 637952]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2011-05-12 403240]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S4 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: srchasm.dll

#14 Příspěvek od motji »

:arrow: Otevřete si Poznámkový blok a zkopírujte do něj text

Kód: Vybrat vše

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=-
"Adobe Reader Speed Launcher"=-
"Adobe ARM"=-
"SunJavaUpdateSched"=-
"Malwarebytes' Anti-Malware"=-

 
-uložte jako (typ: všechny soubory) kde za název souboru zadáte "smazani.reg" bez uvozovek,
klikněte na uložit, pak na soubor standardně 2X klikněte a potvrďte dialogové okno.


Možná ho přece jen smazal, v pc ho prostě nevidím. Kdyby se znovu objevil, ozvěte se. :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
Zizou
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 65
Registrován: 22 črc 2010 16:11
Kontaktovat uživatele:

Re: srchasm.dll

#15 Příspěvek od Zizou »

OKi. Díky za kontrolku ;)

Odpovědět