Stránka 2 z 5

Re: Kontrola logu

Napsal: 05 pro 2010 18:47
od shorty1963
Tak to nezjistim.Musel bych znovu spustit Combofix.
Mám ho opětovně spustit?

Re: Kontrola logu

Napsal: 05 pro 2010 18:49
od Rudy
Stačí, když se podíváte, zda jsou přítomny tyto soubory:
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\64dlls.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\intel64.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\Kernel32.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\localsys64.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\ntos.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\oembios.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\sdra64.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\sdra73.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\swin32.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\twex.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\twext.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\wsnpoema.exe

Re: Kontrola logu

Napsal: 05 pro 2010 19:02
od shorty1963
Soubory jsem přes vyhledávač v PC nenašel, ale nevidím ani složku "c:\documents and settings", to je nějaké divné...Ani jako skrytou složku.

Re: Kontrola logu

Napsal: 05 pro 2010 19:42
od Rudy
Pak by mělo být po problémech.

Re: Kontrola logu

Napsal: 05 pro 2010 19:58
od shorty1963
Tak bohužel není...
Combofix soubory smaže ale pak po znovu projetím jsou tam znovu, zase je smázne ale tak to jde pořád dokola.

ComboFix 10-12-04.02 - KratkyJ 05.12.2010 19:37:40.10.2 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1250.420.1029.18.3070.2029 [GMT 1:00]
Spuštěný z: c:\users\KratkyJ\Desktop\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\64dlls.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\intel64.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\Kernel32.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\localsys64.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\ntos.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\oembios.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\sdra64.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\sdra73.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\swin32.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\twex.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\twext.exe
c:\documents and settings\ReleaseEngineer.MACROVISION\Application Data\wsnpoema.exe
c:\windows\regedit.com
c:\windows\system32\taskmgr.com

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-05 do 2010-12-05 )))))))))))))))))))))))))))))))
.

2010-12-05 18:17 . 2010-12-05 18:17 -------- d---a-w- c:\windows\rundll16.exe
2010-12-05 18:17 . 2010-12-05 18:17 -------- d---a-w- c:\windows\logo1_.exe
2010-12-05 17:37 . 2010-12-05 17:37 -------- d-----w- c:\users\KratkyJ\AppData\Roaming\smkits
2010-12-05 14:05 . 2008-01-21 02:25 134656 ----a-w- c:\windows\R.COM
2010-12-05 14:05 . 2008-01-21 02:25 163840 ----a-w- c:\windows\system32\T.COM
2010-12-05 09:08 . 2010-12-05 09:08 24448 ----a-w- c:\windows\system32\drivers\rkhdrv40.sys
2010-12-05 09:08 . 2009-06-18 11:55 18816 ------w- c:\windows\system32\SAVRKBootTasks.sys
2010-12-03 06:03 . 2010-11-10 04:33 6273872 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{7F346C85-7D5D-48AC-AD26-D86C3522D7EA}\mpengine.dll
2010-11-29 10:47 . 2010-11-29 10:47 -------- d-----w- c:\users\KratkyJ\AppData\Local\Symantec
2010-11-29 10:46 . 2010-09-10 21:32 167936 ----a-w- c:\windows\system32\drivers\wpshelper.sys
2010-11-29 10:45 . 2010-11-25 10:54 97096 ----a-w- c:\windows\system32\drivers\SysPlant.sys
2010-11-29 10:45 . 2010-11-29 10:45 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-11-29 10:43 . 2010-11-29 10:46 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-11-29 10:43 . 2010-11-29 10:45 -------- d-----w- c:\program files\Symantec
2010-11-26 12:45 . 2010-11-26 12:45 53248 ----a-r- c:\users\KratkyJ\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2010-11-26 12:44 . 2010-11-26 12:44 -------- d-----w- c:\program files\Logitech
2010-11-26 12:39 . 2010-08-25 14:41 263272 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
2010-11-26 12:39 . 2009-12-03 16:27 80416 ----a-w- c:\windows\system32\RtNicProp32.dll
2010-11-26 12:37 . 2010-11-26 12:37 -------- d-----w- c:\windows\system32\RTCOM
2010-11-26 12:35 . 2006-02-07 14:40 204800 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2010-11-26 12:35 . 2006-02-07 14:45 757760 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2010-11-26 12:35 . 2006-02-07 14:40 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2010-11-26 12:35 . 2006-02-07 14:40 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2010-11-26 12:35 . 2005-11-13 22:19 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2010-11-26 12:35 . 2010-11-26 12:35 200836 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2010-11-26 12:35 . 2010-11-26 12:35 331908 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2010-11-26 12:19 . 2010-11-26 12:19 -------- d-----w- C:\NVIDIA
2010-11-26 11:58 . 2010-11-26 11:58 -------- d-----w- c:\program files\Driver-Soft
2010-11-24 05:00 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-11-21 07:48 . 2010-11-21 07:48 -------- d-----w- c:\users\KratkyJ\AppData\Roaming\BitComet
2010-11-21 07:44 . 2010-11-21 07:44 -------- d-----w- c:\users\KratkyJ\AppData\Roaming\Zbshareware Lab
2010-11-10 05:58 . 2010-10-07 11:37 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-30 05:20 . 2010-11-30 05:18 22997742 ----a-w- c:\windows\REGBK43.ZIP
2010-11-29 16:42 . 2009-06-04 20:21 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-29 16:42 . 2009-06-04 20:21 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-26 12:45 . 2010-05-09 15:06 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2010-11-26 12:36 . 2008-09-18 07:39 319456 ----a-w- c:\windows\DIFxAPI.dll
2010-10-19 09:41 . 2009-10-03 06:24 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-18 09:14 . 2010-10-31 12:34 6959616 ----a-w- c:\windows\system32\drivers\NETwNv32.sys
2010-10-16 18:55 . 2010-11-26 12:20 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2010-10-16 18:55 . 2010-07-25 16:26 5473896 ----a-w- c:\windows\system32\nvwgf2um.dll
2010-10-16 18:55 . 2008-06-08 23:23 1719912 ----a-w- c:\windows\system32\nvapi.dll
2010-10-16 18:55 . 2008-06-08 23:23 10023528 ----a-w- c:\windows\system32\nvd3dum.dll
2010-10-16 11:42 . 2010-10-16 11:42 600680 ----a-w- c:\windows\system32\nvvsvc.exe
2010-10-16 11:42 . 2010-10-16 11:42 279144 ----a-w- c:\windows\system32\nvhotkey.dll
2010-10-16 11:42 . 2010-10-16 11:42 1881704 ----a-w- c:\windows\system32\nvsvcr.dll
2010-10-16 11:42 . 2010-10-16 11:42 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-10-16 11:42 . 2010-10-16 11:42 3420776 ----a-w- c:\windows\system32\nvcpl.dll
2010-10-16 11:42 . 2010-10-16 11:42 2079336 ----a-w- c:\windows\system32\nvsvc.dll
2010-10-15 15:00 . 2010-10-15 14:57 21659212 ----a-w- c:\windows\REGBK42.ZIP
2010-10-04 21:02 . 2008-09-18 07:22 53248 ----a-w- c:\windows\system32\CSVer.dll
2010-09-22 22:47 . 2010-09-22 22:47 49016 ----a-w- c:\windows\system32\sirenacm.dll
2010-09-22 22:32 . 2010-09-22 22:32 301936 ----a-w- c:\windows\WLXPGSS.SCR
2010-09-22 22:21 . 2010-10-23 06:13 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2010-09-13 13:56 . 2010-10-13 05:02 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2010-09-08 09:17 . 2010-09-08 09:17 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 09:17 . 2010-09-08 09:17 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-09-08 06:01 . 2010-10-13 05:02 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-08 05:57 . 2010-10-13 05:02 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-08 05:57 . 2010-10-13 05:02 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-09-08 05:56 . 2010-10-13 05:02 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-09-08 05:56 . 2010-10-13 05:02 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-09-08 05:04 . 2010-10-13 05:02 385024 ----a-w- c:\windows\system32\html.iec
2010-09-08 04:26 . 2010-10-13 05:02 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-09-08 04:25 . 2010-10-13 05:02 1638912 ----a-w- c:\windows\system32\mshtml.tlb
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2010-05-14 1479680]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2008-01-23 7766016]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-11-16 1029416]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2008-02-01 61440]
"Client Access Service"="c:\program files\IBM\Client Access\cwbsvstr.exe" [2005-06-09 20530]
"Client Access Check Version"="c:\program files\IBM\Client Access\cwbckver.exe" [2005-06-09 45106]
"Client Access Express Welcome"="c:\program files\IBM\Client Access\cwbwlwiz.exe" [2005-06-09 20480]
"Client Access PC5250 Sound"="c:\program files\IBM\Client Access\Emulator\pcssnd.exe" [2005-06-09 40960]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2010-11-25 115560]
"NetTime"="c:\program files\NetTime\NetTime.exe" [2003-01-30 3791032]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"

[HKLM\~\startupfolder\C:^Users^KratkyJ^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Registrace produktu.lnk]
path=c:\users\KratkyJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Registrace produktu.lnk
backup=c:\windows\pss\Logitech . Registrace produktu.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EvtMgr6]
2010-10-28 23:32 1352272 ----a-w- c:\program files\Logitech\SetPointP\SetPoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2010-01-08 18:56 186904 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2010-05-14 08:32 1479680 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 09:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2010-11-02 18:28 9808488 ------w- c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2010-11-25 23888]
R3 NETw5v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2010-01-13 6628352]
R3 rkhdrv40;Rootkit Unhooker Driver; [x]
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-01-07 348752]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-01-15 206256]
S1 SAVRKBootTasks;Boot Tasks Driver;c:\windows\system32\SAVRKBootTasks.sys [2009-06-18 18816]
S2 KVPNCSvc;Kerio VPN Client Service;c:\program files\Kerio\VPN Client\kvpncsvc.exe [2009-10-26 972648]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-11-29 363344]
S2 NetTimeSvc;NetTime;c:\program files\NetTime\NeTmSvNT.exe [2003-01-30 452096]
S2 SCPDFReadSpool;SolidConverterPDFReadSpool;c:\windows\Installer\MSI357.tmp [2010-01-22 189696]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-01-29 29736]
S3 DCamUSBET;USB2.0 1.3M UVC WebCam;c:\windows\system32\DRIVERS\etDevice.sys [2008-10-20 138920]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-12-03 102448]
S3 FiltUSBET;ET USB Device Lower Filter;c:\windows\system32\DRIVERS\etFilter.sys [2008-10-20 21544]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2007-12-18 54784]
S3 kvnet;Kerio Virtual Network Adapter;c:\windows\system32\DRIVERS\kvnet.sys [2009-03-23 26624]
S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\Drivers\LEqdUsb.Sys [2010-08-24 40912]
S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\Drivers\LHidEqd.Sys [2010-08-24 10448]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-11-29 20952]
S3 NETwNv32;___ Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETwNv32.sys [2010-10-18 6959616]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-09-07 123496]
S3 ScanUSBET;ET USB Still Image Capture Device;c:\windows\system32\DRIVERS\etScan.sys [2008-10-20 13224]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-03-17 15:56 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'

2010-12-05 c:\windows\Tasks\User_Feed_Synchronization-{5BE08792-9337-42D5-8B1C-76BA4E5D1B15}.job
- c:\windows\system32\msfeedssync.exe [2010-10-13 04:25]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://kompas.hzap.local/
IE: Stáhnout odkaz s použitím BitCometu - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: Stáhnout všechny odkazy s použitím BitCometu - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
Trusted Zone: ntsd01
Trusted Zone: pproi
DPF: {0D221D00-A6ED-477C-8A91-41F3B660A832} - hxxp://ntsd01/ReportServer/Reserved.ReportViewerWebControl.axd?ExecutionID=biaoeojn20c52q45j1yrl5ev&ControlID=97c13acdd6a9479ca40b6e09030bda69&Culture=1029&UICulture=9&ReportStack=1&OpType=PrintCab
DPF: {41861299-EAB2-4DCC-986C-802AE12AC499} - hxxp://ntsd01/ReportServer/Reserved.ReportViewerWebControl.axd?ExecutionID=dmm1sk45nfmtibmthlcb3mi0&ControlID=0292a48b3b4246c3a458c906515d254c&Culture=1029&UICulture=9&ReportStack=1&OpType=PrintCab
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

SafeBoot-WudfPf
SafeBoot-WudfRd



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-05 19:52
Windows 6.0.6002 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SCPDFReadSpool]
"ImagePath"="c:\windows\Installer\MSI357.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2010-12-05 19:55:03
ComboFix-quarantined-files.txt 2010-12-05 18:55
ComboFix2.txt 2010-12-05 17:11

Před spuštěním: Volných bajtů: 29 203 480 576
Po spuštění: Volných bajtů: 29 462 269 952

Current=1 Default=1 Failed=0 LastKnownGood=46 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46
- - End Of File - - FCB7642F9A6D18CD886D5941F071E46E

Re: Kontrola logu

Napsal: 05 pro 2010 20:47
od Rudy
Udělejte kompletní sken AVPTool: http://www.viry.cz/forum/viewtopic.php?f=29&t=58179 a dejte log.

Re: Kontrola logu

Napsal: 06 pro 2010 10:43
od shorty1963
Akci jsem provedl, PC běžel celou noc, skoro 9 hodin, až teď to doběhlo, nic to tam celkem nenašlo, jen nějaké staré trojáky v poště z roku 2009.
Pokusím se poslat celý log ale nějak se mi zatím nedaří.

Re: Kontrola logu

Napsal: 06 pro 2010 16:02
od shorty1963
Tak ten log se mi nepodařilo vyexportovat.
Nepomohlo by spuštění Combofixu v "Nouzovém" a nebo "Diagnostickém" spuštění?

Re: Kontrola logu

Napsal: 06 pro 2010 16:13
od shorty1963
Ještě mi MWAV našel toto systémových souborech:
Backdoor (IRCBot) Trojans Spyware/Adware
Antispyware Pro XP Corrupted Spyware/Adware
Orifice2K.plugin Trojan

Posílám log.
06 XII 2010 15:49:25 - **********************************************************
06 XII 2010 15:49:25 - eScan Anti Virus & Spyware Toolkit Utility.
06 XII 2010 15:49:25 - Copyright © 2003-2006, MicroWorld Technologies Inc.
06 XII 2010 15:49:25 - **********************************************************
06 XII 2010 15:49:25 - Source: C:\Users\KratkyJ\Downloads\PC-udrzba\SOS\MWAV\mwav.exe
06 XII 2010 15:49:25 - Verze 11.0.86 (C:\USERS\KRATKYJ\APPDATA\LOCAL\TEMP\MEXE.COM)
06 XII 2010 15:49:25 - Log soubor: C:\Users\KratkyJ\AppData\Local\Temp\MWAV.LOG
06 XII 2010 15:49:25 - Datum a čas posledního testu: 05.12.2010 19:17:17
06 XII 2010 15:49:25 - MWAV Registered: TRUE
06 XII 2010 15:49:25 - User Account: KratkyJ (Administrator Mode)
06 XII 2010 15:49:25 - OS Type: Windows Workstation
06 XII 2010 15:49:25 - OS: Windows XP [OS Install Date: 18 Sep 2008 18:03:15]
06 XII 2010 15:49:25 - Ver: Service Pack 2 (Build 2600)
06 XII 2010 15:49:25 - System Up Time: 7 Minutes, 6 Seconds


06 XII 2010 15:49:25 - Windows Root Folder: C:\Windows
06 XII 2010 15:49:25 - Windows Sys32 Folder: C:\Windows\system32
06 XII 2010 15:49:25 - DHCP NameServer: 172.16.0.41
06 XII 2010 15:49:25 - Interface0 DHCPNameServer: 172.16.0.41
06 XII 2010 15:49:25 - Interface1 DHCPNameServer: 172.16.0.21 172.16.0.22
06 XII 2010 15:49:25 - Interface2 DHCPNameServer: 172.16.0.41
06 XII 2010 15:49:25 - Local Fixed Drives: c:\,d:\
06 XII 2010 15:49:25 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware)
06 XII 2010 15:49:25 - [CREATED ZIP FILE: C:\Users\KratkyJ\AppData\Local\Temp\pinfect.zip]

06 XII 2010 15:49:25 - ********** Soubory vytvořené/upravené ve složce Windows a kořenovém adresáři od posledního testu **********
06 XII 2010 15:49:25 - C:\Windows\DIFxAPI.dll (319456), 26-Nov-2010, Microsoft Corporation, Driver Install Frameworks API (DIFxAPI)
06 XII 2010 15:49:26 - C:\Windows\R.COM (134656), 05-Dec-2010, Microsoft Corporation, Microsoft® Windows® Operating System
06 XII 2010 15:49:26 - C:\Windows\RtlExUpd.dll (1251944), 26-Nov-2010, Realtek Semiconductor Corp., RtlExUpd Dynamic Link Library
06 XII 2010 15:49:26 - C:\Windows\system32\AERTACap.dll (175200), 26-Nov-2010, Andrea Electronics Corporation, Capture LFX Filters (32-bit)
06 XII 2010 15:49:26 - C:\Windows\system32\AERTARen.dll (96160), 26-Nov-2010, Andrea Electronics Corporation, Render GFX Filters (32-bit)
06 XII 2010 15:49:26 - C:\Windows\system32\capicom.dll (511328), 29-Nov-2010, Microsoft Corporation, CAPICOM Module
06 XII 2010 15:49:26 - C:\Windows\system32\DTSBassEnhancementDLL.dll (448616), 26-Nov-2010, DTS, DTS Surround Sensation
06 XII 2010 15:49:26 - C:\Windows\system32\DTSBoostDLL.dll (901224), 26-Nov-2010, DTS, DTS Boost
06 XII 2010 15:49:26 - C:\Windows\system32\DTSGainCompensatorDLL.dll (236648), 26-Nov-2010, DTS, DTS Post Processing APO
06 XII 2010 15:49:26 - C:\Windows\system32\DTSGFXAPO.dll (107112), 26-Nov-2010, DTS, DTS Post Processing APO
06 XII 2010 15:49:26 - C:\Windows\system32\DTSGFXAPONS.dll (106600), 26-Nov-2010, DTS, DTS Post Processing APO
06 XII 2010 15:49:26 - C:\Windows\system32\DTSLFXAPO.dll (107112), 26-Nov-2010, DTS, DTS Post Processing APO
06 XII 2010 15:49:26 - C:\Windows\system32\DTSLimiterDLL.dll (224360), 26-Nov-2010, DTS, DTS Post Processing APO
06 XII 2010 15:49:26 - C:\Windows\system32\DTSNeoPCDLL.dll (291432), 26-Nov-2010, DTS, DTS NEO:PC
06 XII 2010 15:49:26 - C:\Windows\system32\DTSS2HeadphoneDLL.dll (962664), 26-Nov-2010, DTS, DTS Surround Sensation
06 XII 2010 15:49:26 - C:\Windows\system32\DTSS2SpeakerDLL.dll (1132648), 26-Nov-2010, DTS, DTS Surround Sensation
06 XII 2010 15:49:26 - C:\Windows\system32\DTSSymmetryDLL.dll (429160), 26-Nov-2010, DTS, DTS Symmetry
06 XII 2010 15:49:26 - C:\Windows\system32\DTSVoiceClarityDLL.dll (406120), 26-Nov-2010, DTS, DTS Surround Sensation
06 XII 2010 15:49:26 - C:\Windows\system32\FMAPO.dll (1558432), 26-Nov-2010, Fortemedia Corporation, Fortemedia SAMSoft sAPO
06 XII 2010 15:49:26 - C:\Windows\system32\FwsVpn.dll (87368), 25-Nov-2010, Symantec Corporation, Symantec CMC Firewall
06 XII 2010 15:49:26 - C:\Windows\system32\MaxxAudioAPO.dll (132368), 26-Nov-2010, Waves Audio Ltd., Waves Audio MaxxAudio
06 XII 2010 15:49:26 - C:\Windows\system32\MaxxAudioAPO20.dll (232792), 26-Nov-2010, Waves Audio Ltd., Waves Audio MaxxAudio
06 XII 2010 15:49:26 - C:\Windows\system32\MaxxAudioAPO30.dll (259928), 26-Nov-2010, Waves Audio Ltd., Waves Audio MaxxAudio
06 XII 2010 15:49:26 - C:\Windows\system32\MaxxAudioEQ.dll (1938704), 26-Nov-2010, Waves Audio Ltd.
06 XII 2010 15:49:26 - C:\Windows\system32\MaxxAudioRealtek.dll (1336664), 26-Nov-2010, Waves Audio Ltd.
06 XII 2010 15:49:26 - C:\Windows\system32\MaxxVolumeSDAPO.dll (252760), 26-Nov-2010, Waves Audio Ltd., Waves Audio MaxxVolumeSD
06 XII 2010 15:49:26 - C:\Windows\system32\nvapo32v.dll (65640), 26-Nov-2010, NVIDIA Corporation, NVIDIA HDMI Audio Driver
06 XII 2010 15:49:26 - C:\Windows\system32\nvcompiler.dll (13019752), 26-Nov-2010, NVIDIA Corporation, NVIDIA Compiler
06 XII 2010 15:49:26 - C:\Windows\system32\nvcuda.dll (4837480), 26-Nov-2010, NVIDIA Corporation, NVIDIA CUDA 3.2.1 driver
06 XII 2010 15:49:26 - C:\Windows\system32\nvcuvenc.dll (2666600), 26-Nov-2010, NVIDIA Corporation, NVIDIA CUDA Video Encoder
06 XII 2010 15:49:26 - C:\Windows\system32\nvcuvid.dll (2912360), 26-Nov-2010, NVIDIA Corporation, NVIDIA CUDA Video Decode API
06 XII 2010 15:49:26 - C:\Windows\system32\nvdispco322050.dll (888424), 26-Nov-2010, NVIDIA Corporation, NVIDIA Install Application
06 XII 2010 15:49:26 - C:\Windows\system32\nvgenco32.dll (813672), 26-Nov-2010, NVIDIA Corporation, NVIDIA Install Application
06 XII 2010 15:49:26 - C:\Windows\system32\nvgenco322030.dll (813672), 26-Nov-2010, NVIDIA Corporation, NVIDIA Install Application
06 XII 2010 15:49:26 - C:\Windows\system32\nvhdap32.dll (26216), 26-Nov-2010, NVIDIA Corporation, NVIDIA HDMI Audio Driver
06 XII 2010 15:49:26 - C:\Windows\system32\nvoglv32.dll (14899816), 26-Nov-2010, NVIDIA Corporation, NVIDIA Compatible OpenGL ICD
06 XII 2010 15:49:26 - C:\Windows\system32\OpenCL.dll (57960), 26-Nov-2010, Khronos Group, Khronos OpenCL ICD
06 XII 2010 15:49:26 - C:\Windows\system32\R4EEA32A.dll (78992), 26-Nov-2010, Dolby Laboratories, Not for Release - Dolby PCEE4 ASL
06 XII 2010 15:49:26 - C:\Windows\system32\R4EED32A.dll (339600), 26-Nov-2010, Dolby Laboratories, Not for Release - Dolby PCEE4 COM DLL
06 XII 2010 15:49:26 - C:\Windows\system32\R4EEG32A.dll (59536), 26-Nov-2010, Dolby Laboratories, Not for Release - Dolby PCEE4 GFX APO
06 XII 2010 15:49:26 - C:\Windows\system32\R4EEL32A.dll (94352), 26-Nov-2010, Dolby Laboratories, Not for Release - Dolby PCEE4 LFX APO
06 XII 2010 15:49:26 - C:\Windows\system32\R4EEP32A.dll (1703568), 26-Nov-2010, Dolby Laboratories, Not for Release - Dolby PCEE4 Control Panel
06 XII 2010 15:49:26 - C:\Windows\system32\RP3DAA32.dll (293584), 26-Nov-2010, Dolby Laboratories, Inc., Dolby PCEE3 Control Panel
06 XII 2010 15:49:26 - C:\Windows\system32\RP3DHT32.dll (293584), 26-Nov-2010, Dolby Laboratories, Inc., Dolby PCEE3 Control Panel
06 XII 2010 15:49:26 - C:\Windows\system32\RTEED32A.dll (168648), 26-Nov-2010, Dolby Laboratories, Inc., Dolby PCEE3 COM DLL
06 XII 2010 15:49:26 - C:\Windows\system32\RTEEG32A.dll (62664), 26-Nov-2010, Dolby Laboratories, Inc., Dolby PCEE3 GFX APO
06 XII 2010 15:49:26 - C:\Windows\system32\RTEEL32A.dll (76488), 26-Nov-2010, Dolby Laboratories, Inc., Dolby PCEE3 LFX APO
06 XII 2010 15:49:26 - C:\Windows\system32\RTEEP32A.dll (357576), 26-Nov-2010, Dolby Laboratories, Inc., Dolby PCEE3 Control Panel
06 XII 2010 15:49:26 - C:\Windows\system32\RtkAPO.dll (3633256), 26-Nov-2010, Realtek Semiconductor Corp., Realtek(r) LFX/GFX DSP component
06 XII 2010 15:49:26 - C:\Windows\system32\RtkApoApi.dll (461416), 26-Nov-2010, Realtek Semiconductor Corp., Realtek APO API
06 XII 2010 15:49:26 - C:\Windows\system32\RtkCoInst.dll (68200), 26-Nov-2010, Realtek Semiconductor Corp., Realtek HD Audio Coinstaller
06 XII 2010 15:49:26 - C:\Windows\system32\RtkPgExt.dll (1889896), 26-Nov-2010, Realtek Semiconductor Corp., Realtek LFX/GFX DSP UI component
06 XII 2010 15:49:26 - C:\Windows\system32\RtNicProp32.dll (80416), 26-Nov-2010 [Added C:\Windows\system32\RtNicProp32.dll to ZIP FILE]
06 XII 2010 15:49:26 - C:\Windows\system32\RTSndMgr.cpl (1084008), 26-Nov-2010, Realtek Semiconductor Corp., Realtek HD Audio Sound Effect Manager
06 XII 2010 15:49:26 - C:\Windows\system32\SAVRKBootTasks.sys (18816), 05-Dec-2010, Sophos Plc, Sophos Anti-Rootkit
06 XII 2010 15:49:26 - C:\Windows\system32\SFAPO.dll (68944), 26-Nov-2010, Virage Logic Corporation / Sonic Focus, Sonic Focus Effects
06 XII 2010 15:49:26 - C:\Windows\system32\SFCOM.dll (74064), 26-Nov-2010, Virage Logic Corporation / Sonic Focus, Sonic Focus Effects
06 XII 2010 15:49:26 - C:\Windows\system32\SFNHK.dll (214352), 26-Nov-2010, Virage Logic Corporation / Sonic Focus, Sonic Focus Effects
06 XII 2010 15:49:26 - C:\Windows\system32\SRSHP360.dll (173296), 26-Nov-2010, SRS Labs, Inc., Headphone 360 for Windows
06 XII 2010 15:49:26 - C:\Windows\system32\SRSTSHD.dll (185584), 26-Nov-2010, SRS Labs, Inc., TruSurround HD and HD4 COM object for Windows
06 XII 2010 15:49:26 - C:\Windows\system32\SRSTSXT.dll (345328), 26-Nov-2010, SRS Labs, Inc., TruSurroundXT
06 XII 2010 15:49:26 - C:\Windows\system32\SRSWOW.dll (140528), 26-Nov-2010, SRS Labs, Inc., WOW HD
06 XII 2010 15:49:26 - C:\Windows\system32\SymVPN.dll (107848), 25-Nov-2010, Symantec Corporation, Symantec Client Management Component
06 XII 2010 15:49:26 - C:\Windows\system32\sysfer.dll (353608), 25-Nov-2010, Symantec Corporation, Symantec CMC Firewall
06 XII 2010 15:49:26 - C:\Windows\system32\T.COM (163840), 05-Dec-2010, Microsoft Corporation, Microsoft(R) Windows (R) 2000 Operating System
06 XII 2010 15:49:26 - C:\Windows\system32\WavesGUILib.dll (1725784), 26-Nov-2010, Waves Audio Ltd., Waves general library
06 XII 2010 15:49:26 - C:\Windows\system32\WavesLib.dll (1783056), 26-Nov-2010, Waves Audio Ltd., Waves general library
06 XII 2010 15:49:26 - C:\Windows\system32\drivers\COH_Mon.sys (23888), 25-Nov-2010, Symantec Corporation, Confidence Online Utility Driver
06 XII 2010 15:49:26 - C:\Windows\system32\drivers\LNonPnP.sys (16400), 26-Nov-2010, Logitech, Inc., Logitech SetPoint(TM)
06 XII 2010 15:49:26 - C:\Windows\system32\drivers\mbam.sys (20952), 29-Nov-2010, Malwarebytes Corporation, Malwarebytes' Anti-Malware
06 XII 2010 15:49:26 - C:\Windows\system32\drivers\mbamswissarmy.sys (38224), 29-Nov-2010, Malwarebytes Corporation, Malwarebytes' Anti-Malware
06 XII 2010 15:49:26 - C:\Windows\system32\drivers\nvhda32v.sys (123496), 26-Nov-2010, NVIDIA Corporation, NVIDIA HDMI Audio Driver
06 XII 2010 15:49:26 - C:\Windows\system32\drivers\nvlddmkm.sys (10084360), 26-Nov-2010, NVIDIA Corporation, NVIDIA Windows Kernel Mode Driver, Version 260.99
06 XII 2010 15:49:26 - C:\Windows\system32\drivers\rkhdrv40.sys (24448), 05-Dec-2010, RkUnhooker Driver
06 XII 2010 15:49:26 - C:\Windows\system32\drivers\RTKVHDA.sys (3228712), 26-Nov-2010, Realtek Semiconductor Corp., Realtek(r) High Definition Audio Function Driver
06 XII 2010 15:49:26 - C:\Windows\system32\drivers\Rtlh86.sys (263272), 26-Nov-2010, Realtek, Realtek 8136/8168/8169 PCI/PCIe Adapters
06 XII 2010 15:49:26 - C:\Windows\system32\drivers\srtsp.sys (283184), 25-Nov-2010, Symantec Corporation, AutoProtect
06 XII 2010 15:49:27 - C:\Windows\system32\drivers\srtspl.sys (320944), 25-Nov-2010, Symantec Corporation, AutoProtect
06 XII 2010 15:49:27 - C:\Windows\system32\drivers\srtspx.sys (43696), 25-Nov-2010, Symantec Corporation, AutoProtect
06 XII 2010 15:49:27 - C:\Windows\system32\drivers\symdns.sys (12720), 25-Nov-2010, Symantec Corporation, Symantec Security Drivers
06 XII 2010 15:49:27 - C:\Windows\system32\drivers\SYMEVENT.SYS (124976), 29-Nov-2010, Symantec Corporation, SYMEVENT
06 XII 2010 15:49:27 - C:\Windows\system32\drivers\symfw.sys (145968), 25-Nov-2010, Symantec Corporation, Symantec Security Drivers
06 XII 2010 15:49:27 - C:\Windows\system32\drivers\symids.sys (39856), 25-Nov-2010, Symantec Corporation, Symantec Security Drivers
06 XII 2010 15:49:27 - C:\Windows\system32\drivers\symndisv.sys (38448), 25-Nov-2010, Symantec Corporation, Symantec Security Drivers
06 XII 2010 15:49:27 - C:\Windows\system32\drivers\symredrv.sys (26416), 25-Nov-2010, Symantec Corporation, Symantec Security Drivers
06 XII 2010 15:49:27 - C:\Windows\system32\drivers\symtdi.sys (188080), 25-Nov-2010, Symantec Corporation, Symantec Security Drivers
06 XII 2010 15:49:27 - C:\Windows\system32\drivers\SysPlant.sys (97096), 25-Nov-2010, Symantec Corporation, Symantec CMC Firewall
06 XII 2010 15:49:27 - C:\Windows\system32\drivers\Teefer2.sys (67472), 25-Nov-2010, Symantec Corporation, Symantec CMC Firewall
06 XII 2010 15:49:27 - C:\Windows\system32\drivers\WPSDRVnt.sys (43336), 25-Nov-2010, Symantec Corporation, Symantec CMC Firewall
06 XII 2010 15:49:27 - C:\Windows\system32\drivers\wpshelper.sys (167936), 29-Nov-2010, Symantec Corporation, Symantec Intrusion Detection

06 XII 2010 15:49:27 - C:\Windows\Fonts, 02-Nov-2006 [SR] [Složky]
06 XII 2010 15:49:27 - C:\Windows\Media, 02-Nov-2006 [SR] [Složky]
06 XII 2010 15:49:27 - C:\Windows\system32\%APPDATA%, 12-Aug-2010 [HS] [Složky]
06 XII 2010 15:49:27 - C:\Windows\system32\GroupPolicy, 02-Nov-2006 [H] [Složky]
06 XII 2010 15:49:27 - C:\Windows\system32\Microsoft, 02-Nov-2006 [S] [Složky]
06 XII 2010 15:49:27 - C:\Windows\system32\RTCOM, 26-Nov-2010 [Složky]

Re: Kontrola logu

Napsal: 06 pro 2010 18:11
od Rudy
Podle všeho tam nic není. Zkuste ten CF v nouz. režimu.

Re: Kontrola logu

Napsal: 06 pro 2010 19:17
od shorty1963
To je divne...Ale proc mi Combofix po spusteni porad hlasi Rootkita, pak restartuje PC, soubory pořád ty samé smaže, ale ty se tam pak znovu objeví?
Dnes mi PC zase 1x uplne vytuhl, jinak se ale chova podle mě normálně.
V Nouzovem a nebo Diagnostickem? Zkusim to zitra, dnes nemam PC doma.
Zatim moc diky a uvidim tedy zitra.

Re: Kontrola logu

Napsal: 06 pro 2010 19:56
od Rudy
Myslím, že tam je něco, co je obnovuje. nemohu ale přijít na to, co. Spíše zkuste nouz. režim. Nevím, co bude CF dělat v diagnostickém. Nezkoušel jsem to a nikde to není popsáno.

Re: Kontrola logu

Napsal: 07 pro 2010 06:37
od shorty1963
Tak jsem provedl start Combofix z Nouzového režimu, zase zahlásil přítomnost Rootkita, ukázal ty samé exe soubory co bude chtít smazat, napsal že musí být restartován a po restartování systém normálně naběhl do normálního režimu, Combofix neproběhl. Ještě se podívám jestli nějaký ten exe soubor v PC najdu. Možná jsem zaregistroval ještě jednu věc, PC asi vždy zatuhne když se buď ručně nebo pak podle plánu spustí antivirák a nebo nějaký jiný nástroj k odstraňování havěti.

Re: Kontrola logu

Napsal: 07 pro 2010 07:05
od shorty1963
Ještě posílám nový log.

info.txt logfile of random's system information tool 1.08 2010-12-07 06:55:15

======Uninstall list======

-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\AFPViewr\DeIsL3.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL31.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL32.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL33.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL34.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL35.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL36.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL37.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL38.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL39.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL40.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL41.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL42.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL43.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL44.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL45.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\Emulator\DeIsL5.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\Emulator\DeIsL6.isu"
-->C:\Windows\IsUninst.exe -f"C:\Program Files\IBM\Client Access\Emulator\DeIsL8.isu"
-->MsiExec /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
2007 Microsoft Office system-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROHYBRIDR /dll OSETUP.DLL
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\FlashUtil10l_Plugin.exe -maintain plugin
Adobe Reader 9.1.3 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A91000000001}
AnyDVD-->"C:\Program Files\SlySoft\AnyDVD\AnyDVD-uninst.exe" /D="C:\Program Files\SlySoft\AnyDVD"
Apple Application Support-->MsiExec.exe /I{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
ASUS LifeFrame3-->MsiExec.exe /I{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}
ASUS Power4Gear eXtreme-->MsiExec.exe /I{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}
ASUS SmartLogon-->MsiExec.exe /I{64452561-169F-4A36-A2FF-B5E118EC65F5}
ASUS Virtual Camera-->MsiExec.exe /I{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}
ATK Generic Function Service-->C:\Program Files\InstallShield Installation Information\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}\Setup.exe -runfromtemp -l0x0009 -removeonly
ATK Hotkey-->C:\Program Files\InstallShield Installation Information\{3912D529-02BC-4CA8-B5ED-0D0C20EB6003}\setup.exe -runfromtemp -l0x0005 -removeonly
ATK Media-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{139B0FFA-187E-4BA1-BCA6-6B56B2B6AB8C}\Setup.exe" -l0x9
ATKOSD2-->C:\Program Files\InstallShield Installation Information\{5C1DB4ED-E9B4-402D-BB14-D75D97D6C1A6}\Setup.exe -runfromtemp -l0x0009 -removeonly
AuthenTec Fingerprint Sensor Minimum Install-->MsiExec.exe /I{EB4DF30B-102B-4F0C-927A-D50E037A325D}
Balíček ovladače systému Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)-->C:\PROGRA~1\DIFX\B4723E9A0713E5B1\dpinst.exe /u C:\Windows\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.inf
BitComet 1.24-->C:\Program Files\BitComet\uninst.exe
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
CloneCD-->"C:\Program Files\SlySoft\CloneCD\ccd-uninst.exe" /D="C:\Program Files\SlySoft\CloneCD"
CloneDVD2-->"C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD2-uninst.exe" /D="C:\Program Files\Elaborate Bytes\CloneDVD2"
CodeStuff Starter-->"C:\Program Files\CodeStuff\Starter\unStarter.exe"
Cortona3D Viewer-->MsiExec.exe /X{7D228E96-4124-4DDB-A4B3-C89FBCABC77F}
CyberLink DVD Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
D3DX10-->MsiExec.exe /X{E09C4DB7-630C-4F06-A631-8EA7239923AF}
Dolby Control Center-->MsiExec.exe /I{DE66EFAD-B9CC-4FD4-9157-6C18E5100161}
Doplněk Microsoft Save as PDF or XPS pro aplikace sady Microsoft Office 2007-->MsiExec.exe /X{90120000-00B2-0405-0000-0000000FF1CE}
Driver Genius Professional Edition-->"C:\Program Files\Driver-Soft\DriverGenius\unins000.exe"
DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
eReg-->MsiExec.exe /I{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}
EVEREST Home Edition v2.20-->"C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
IBM iSeries Access for Windows-->"C:\Program Files\IBM\Client Access\cwbinarp.exe"
ICQ7.2-->"C:\Program Files\InstallShield Installation Information\{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}\ICQ7.exe" -runfromtemp -l0x0009 -removeonly
Intel® Matrix Storage Manager-->C:\Program Files\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
IrfanView (remove only)-->C:\Program Files\IrfanView\iv_uninstall.exe
ITECIR-->C:\Program Files\InstallShield Installation Information\{40580068-9B10-40B5-9548-536CE88AB23C}\SETUP.EXE -runfromtemp -l0x0005 -removeonly
Java 2 Runtime Environment, SE v1.4.2-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142000}
Java(TM) 6 Update 18-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216018FF}
Junk Mail filter update-->MsiExec.exe /I{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}
Kerio VPN Client-->MsiExec.exe /X{EDAD3775-9BBB-4483-AC6E-DCB6BB18A9FC}
K-Lite Mega Codec Pack 5.6.1-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
LabelPrint-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" -uninstall
LightScribe System Software 1.12.37.1-->MsiExec.exe /X{004C5DA2-2051-4D25-94BA-51CF810C91EB}
LiveUpdate 3.3 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Logitech SetPoint 6.20-->C:\Program Files\Common Files\LogiShrd\sp6_Uninstall\setup.exe
Lotus Notes 7.0.4 cs-->MsiExec.exe /I{5EF37456-E8FF-4E9E-8CAC-9FD66A40E46E}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
MediaShow-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5A9B7C0-8751-11D8-9D75-000129760D75}\setup.exe" -uninstall
Mesh Runtime-->MsiExec.exe /I{8C6D6116-B724-4810-8F2D-D047E6B7D68E}
Messenger Companion-->MsiExec.exe /I{B44F3823-52DD-45CA-A916-8B320778715D}
Microsoft .NET Framework 3.5 Language Pack SP1 - csy-->MsiExec.exe /I{DD73CA82-EA82-38AA-863D-9A24A018DC96}
Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - csy\setup.exe
Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office Access MUI (Czech) 2007-->MsiExec.exe /X{90120000-0015-0405-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Outlook Connector-->MsiExec.exe /X{95140000-007A-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Professional Hybrid 2007-->MsiExec.exe /X{91120000-0031-0000-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Czech) 2007-->MsiExec.exe /X{90120000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Search Enhancement Pack-->MsiExec.exe /X{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Mozilla Firefox (3.6.12)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSVC80_x86_v2-->MsiExec.exe /I{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}
MSVC80_x86-->MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
MSVC90_x86-->MsiExec.exe /I{AF111648-99A1-453E-81DD-80DBBF6DAD0D}
MSVCRT-->MsiExec.exe /I{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NetTime 2.0-->"C:\Program Files\NetTime\unins000.exe"
Nokia Connectivity Cable Driver-->MsiExec.exe /I{F1FDAA01-988C-423F-AC12-0D8F333943FD}
Nokia PC Suite-->C:\ProgramData\Installations\{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}\Nokia_PC_Suite_cze_web.exe
Nokia PC Suite-->MsiExec.exe /I{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}
Nokia Software Updater-->MsiExec.exe /X{650E2ABD-270A-499C-BA9F-09180DDDDA16}
NVIDIA Ovladač 3D Vision 260.99-->"C:\Windows\system32\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.3DVision
NVIDIA Ovladač HD audia 1.1.9.0-->"C:\Windows\system32\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage HDAudio.Driver
NVIDIA Ovladače grafiky 260.99-->"C:\Windows\system32\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.Driver
NVIDIA PhysX-->MsiExec.exe /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
NVIDIA Stereoscopic 3D Driver-->"C:\Program Files\NVIDIA Corporation\3D Vision\nvStInst.exe" /uninstall /ask
NVIDIA Systémový software PhysX 260.99-->"C:\Windows\system32\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.PhysX
OGA Notifier 2.0.0048.0-->MsiExec.exe /I{B2544A03-10D0-4E5E-BA69-0362FFC20D18}
Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení-->MsiExec.exe /I{B6190387-0036-4BEB-8D74-A0AFC5F14706}
PC Connectivity Solution-->MsiExec.exe /I{E3DBED25-09EE-45FE-BE53-4B07B0CBA0FC}
pdfFactory Pro-->C:\Windows\system32\spool\DRIVERS\W32X86\3\fppinst3.exe /uninstall
PhotoNow!-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D36DD326-7280-11D8-97C8-000129760CBE}\setup.exe" -uninstall
Power2Go-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" -uninstall
PowerArchiver 2010 Czech-->MsiExec.exe /I{E72D7025-339A-431E-8CF4-41807660911B}
PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" -l0x000409 /z-uninstall
PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
PowerProducer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
QuickTime-->MsiExec.exe /I{E7004147-2CCA-431C-AA05-2AB166B9785D}
Realtek Ethernet Controller Driver-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -removeonly
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
Recuva-->"C:\Program Files\Recuva\uninst.exe"
Security Update for 2007 Microsoft Office System (KB2288621)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {5C497F0B-2061-4CC9-A61C-6B45B867354D}
Security Update for 2007 Microsoft Office System (KB2289158)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {210B16C0-CEBD-4DE9-B474-04A7E8735E16}
Security Update for 2007 Microsoft Office System (KB2344875)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {6FC5C4C1-D7AE-44C3-94B7-6424FC3E752F}
Security Update for 2007 Microsoft Office System (KB2345043)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {536FB502-775F-4494-BACE-C02CC90B7A5B}
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB976321)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {7F207DCA-3399-40CB-A968-6E5991B1421A}
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A8894F19-59C8-38D2-8A75-36C0CCE56A5B} /qb+ REBOOTPROMPT=""
Security Update for Microsoft Office Access 2007 (KB979440)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {1142CCEC-ACA9-484B-BA90-C3A5CA1988C5}
Security Update for Microsoft Office Access 2007 (KB979440)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {5A4E43D5-858F-49BD-BA72-8F30E1793060}
Security Update for Microsoft Office Excel 2007 (KB2345035)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {B23002DD-34EC-4988-B810-A5E2A0BF04F1}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
Security Update for Microsoft Office Outlook 2007 (KB2288953)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {8B772E1C-7C05-42D2-839D-3EC2D39EFF22}
Security Update for Microsoft Office PowerPoint 2007 (KB982158)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {F5B70033-E79C-4569-90BF-BC9B4E4F3F46}
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {3DED0A62-44C8-4E00-A785-5212F297A9D9}
Security Update for Microsoft Office Publisher 2007 (KB982124)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {289FA8BC-6A8E-4341-B194-EB26B49E9F5D}
Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
Security Update for Microsoft Office Word 2007 (KB2344993)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}
Segoe UI-->MsiExec.exe /I{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}
Smarty Uninstaller Pro-->"C:\Program Files\Smarty Uninstaller Pro\unins000.exe"
Software Intel(R) PROSet/Wireless WiFi-->MsiExec.exe /I{F22FD942-651D-4EE8-BD6F-7E0AF5E17625}
Solid Converter PDF-->MsiExec.exe /I{56BFAA6E-2BCC-4AED-9233-84731E66B205}
Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Spyware Doctor 6.1-->C:\Program Files\Spyware Doctor\unins000.exe /LOG
SuperCleaner-->"C:\Program Files\SuperCleaner\Uninst.exe" C:\Program Files\SuperCleaner\Uninst.ini
Symantec Endpoint Protection-->MsiExec.exe /I{3C1AE512-3C37-44FA-BA42-ABB721EC5B1D}
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Total Commander (Remove or Repair)-->c:\totalcmd\tcuninst.exe
Ultra MKV Converter 3.2.0610-->"C:\Program Files\Ultra MKV Converter\unins000.exe"
Ultra Video Converter 4.4.1222-->"C:\Program Files\Ultra Video Converter\unins000.exe"
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Outlook 2007 Junk Email Filter (KB2443839)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {E8CFA21A-2D44-446D-8324-ADFA3C9FCAD2}
USB Disk Security-->"C:\Program Files\USB Disk Security\unins000.exe"
USB2.0 1.3M UVC WebCam-->C:\Windows\Uninstall.exe
VLC media player 1.1.2-->C:\Program Files\VideoLAN\VLC\uninstall.exe
WIDCOMM Bluetooth Software-->MsiExec.exe /X{03D1988F-469F-4843-8E6E-E5FE9D17889D}
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Live Communications Platform-->MsiExec.exe /I{D45240D3-B6B3-4FF9-B243-54ECE3E10066}
Windows Live Essentials-->C:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{FE62C88B-425B-4BDE-8B70-CD5AE3B83176}
Windows Live Family Safety-->MsiExec.exe /I{8A30D5C0-BD4A-4E65-AADF-20A457DE6D38}
Windows Live Family Safety-->MsiExec.exe /X{F53D678E-238F-4A71-9742-08BB6774E9DC}
Windows Live Fotogalerie-->MsiExec.exe /X{FB79FDB7-4DE1-453D-99FE-9A880F57380E}
Windows Live ID Sign-in Assistant-->MsiExec.exe /I{61AD15B2-50DB-4686-A739-14FE180D4429}
Windows Live Installer-->MsiExec.exe /I{0B0F231F-CE6A-483D-AA23-77B364F75917}
Windows Live Mail-->MsiExec.exe /I{9D56775A-93F3-44A3-8092-840E3826DE30}
Windows Live Mail-->MsiExec.exe /I{C454280F-3C3E-4929-B60E-9E6CED5717E7}
Windows Live Mesh-->MsiExec.exe /I{80E8C65A-8F70-4585-88A2-ABC54BABD576}
Windows Live Mesh-->MsiExec.exe /I{DECDCB7C-58CC-4865-91AF-627F9798FE48}
Windows Live Messenger Companion Core-->MsiExec.exe /I{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}
Windows Live Messenger-->MsiExec.exe /X{50300123-F8FC-4B50-B449-E847D04F1BA2}
Windows Live Messenger-->MsiExec.exe /X{EB4DF488-AAEF-406F-A341-CB2AAA315B90}
Windows Live MIME IFilter-->MsiExec.exe /I{AF844339-2F8A-4593-81B3-9F4C54038C4E}
Windows Live Movie Maker-->MsiExec.exe /X{64B2D6B3-71AC-45A7-A6A1-2E07ABF58341}
Windows Live Movie Maker-->MsiExec.exe /X{92EA4134-10D1-418A-91E1-5A0453131A38}
Windows Live Photo Common-->MsiExec.exe /X{78906B56-0E81-42A7-AC25-F54C946E1538}
Windows Live Photo Common-->MsiExec.exe /X{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}
Windows Live Photo Gallery-->MsiExec.exe /X{3336F667-9049-4D46-98B6-4C743EEBC5B1}
Windows Live PIMT Platform-->MsiExec.exe /I{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}
Windows Live Remote Client Resources-->MsiExec.exe /I{454F5782-A4C3-480E-A629-D435795DEFD8}
Windows Live Remote Client-->MsiExec.exe /I{19A4A990-5343-4FF7-B3B5-6F046C091EDF}
Windows Live Remote Service Resources-->MsiExec.exe /I{0891B708-EF3F-4D7E-9724-265245F46276}
Windows Live Remote Service-->MsiExec.exe /I{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}
Windows Live SOXE Definitions-->MsiExec.exe /I{200FEC62-3C34-4D60-9CE8-EC372E01C08F}
Windows Live SOXE-->MsiExec.exe /I{682B3E4F-696A-42DE-A41C-4C07EA1678B4}
Windows Live Sync-->MsiExec.exe /X{1407B87C-36E3-4FC1-9051-D08B21E1096F}
Windows Live UX Platform Language Pack-->MsiExec.exe /I{463F67F4-58D0-4C0D-BBC9-D0CC4E56D1B8}
Windows Live UX Platform-->MsiExec.exe /I{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}
Windows Live Writer Resources-->MsiExec.exe /X{AB78C965-5C67-409B-8433-D7B5BDB12073}
Windows Live Writer-->MsiExec.exe /X{4264C020-850B-4F08-ACBE-98205D9C336C}
Windows Live Writer-->MsiExec.exe /X{A726AE06-AAA3-43D1-87E3-70F510314F04}
Windows Live Writer-->MsiExec.exe /X{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
Wireless Console 2-->C:\Program Files\InstallShield Installation Information\{83F73CB1-7705-49D1-9852-84D839CA2A45}\Setup.exe -runfromtemp -l0x0009 -removeonly
Zoner Photo Studio 12-->"C:\Program Files\Zoner\Photo Studio 12\unins000.exe" /SILENT /SILENT

======Security center information======

AS: Spybot - Search and Destroy (disabled)
AS: Windows Defender

======System event log======

Computer Name: KratkyJvn
Event Code: 20003
Message: Správa ovladačů ukončila proces přidání služby WUDFRd pro ID instance zařízení ROOT\WPD\0003 s následujícím stavem: 0.
Record Number: 359177
Source Name: Microsoft-Windows-User-PnP
Time Written: 20100816071246.372000-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: KratkyJvn
Event Code: 10100
Message: Instalační balíček ovladače byl úspěšný.
Record Number: 359176
Source Name: Microsoft-Windows-DriverFrameworks-UserMode
Time Written: 20100816071246.278400-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: KratkyJvn
Event Code: 10002
Message: Služba UMDF PCCSWpdDriver (CLSID {8FFB782B-62AE-4C0F-8366-66A69625B39D}) byla upgradována. Vyžaduje verzi platformy 1.9.0 nebo vyšší.
Record Number: 359175
Source Name: Microsoft-Windows-DriverFrameworks-UserMode
Time Written: 20100816071246.200400-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: KratkyJvn
Event Code: 10000
Message: Do zařízení ROOT\WPD\0003 je instalován balíček ovladače, který používá verzi platformy ovladače v uživatelském režimu 1.9.0.
Record Number: 359174
Source Name: Microsoft-Windows-DriverFrameworks-UserMode
Time Written: 20100816071246.184800-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: KratkyJvn
Event Code: 24579
Message: Registrace automatického přehrávání u zařízení WPD_NOKIA_73fd2114_0d73_49c3_9c65_1a2b2c7f6eba byla přeskočena.
Record Number: 359173
Source Name: Microsoft-Windows-WPDClassInstaller
Time Written: 20100816071247.000000-000
Event Type: Informace
User:

=====Application event log=====

Computer Name: KratkyJvn
Event Code: 32
Message: V úložišti C:\Users\KratkyJ\AppData\Local\Microsoft\Outlook\archive1.pst byl zjištěn kontrolní bod katalogu.
Record Number: 46885
Source Name: Outlook
Time Written: 20100115102522.000000-000
Event Type: Informace
User:

Computer Name: KratkyJvn
Event Code: 32
Message: V úložišti C:\Users\KratkyJ\AppData\Local\Microsoft\Outlook\arch2008.pst byl zjištěn kontrolní bod katalogu.
Record Number: 46884
Source Name: Outlook
Time Written: 20100115102522.000000-000
Event Type: Informace
User:

Computer Name: KratkyJvn
Event Code: 32
Message: V úložišti C:\Users\KratkyJ\AppData\Local\Microsoft\Outlook\mailbox-1.pst byl zjištěn kontrolní bod katalogu.
Record Number: 46883
Source Name: Outlook
Time Written: 20100115102522.000000-000
Event Type: Informace
User:

Computer Name: KratkyJvn
Event Code: 32
Message: V úložišti C:\Documents and Settings\KratkyJ\Local Settings\Data aplikací\Microsoft\Outlook\archive.pst byl zjištěn kontrolní bod katalogu.
Record Number: 46882
Source Name: Outlook
Time Written: 20100115102522.000000-000
Event Type: Informace
User:

Computer Name: KratkyJvn
Event Code: 32
Message: V úložišti C:\Users\KratkyJ\AppData\Local\Microsoft\Outlook\arch2005-odeslane.pst byl zjištěn kontrolní bod katalogu.
Record Number: 46881
Source Name: Outlook
Time Written: 20100115102522.000000-000
Event Type: Informace
User:

=====Security event log=====

Computer Name: KratkyJvn
Event Code: 4648
Message: Došlo k pokusu o přihlášení pomocí explicitního pověření.

Předmět:
ID zabezpečení: S-1-5-21-3634038287-2164415200-2504289352-1000
Název účtu: KratkyJ
Doména účtu: KratkyJvn
ID přihlášení: 0xa85b9
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Účet, jehož pověření bylo použito:
Název účtu: kratkyj
Doména účtu: HZAP.LOCAL
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Cílový server:
Název cílového serveru: pproi
Další informace: HTTP/pproi

Informace o procesu:
ID procesu: 0x15b4
Název procesu: C:\Program Files\Internet Explorer\iexplore.exe

Informace o síti:
Síťová adresa: -
Port: -

Tato událost je generována, pokud se proces pokusí přihlásit k účtu explicitním zadáním pověření tohoto účtu. K tomu nejčastěji dochází v dávkových konfiguracích, například naplánovaných úlohách, nebo při použití příkazu RUNAS.
Record Number: 175286
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101015094527.176400-000
Event Type: Úspěch auditu
User:

Computer Name: KratkyJvn
Event Code: 4648
Message: Došlo k pokusu o přihlášení pomocí explicitního pověření.

Předmět:
ID zabezpečení: S-1-5-21-3634038287-2164415200-2504289352-1000
Název účtu: KratkyJ
Doména účtu: KratkyJvn
ID přihlášení: 0xa85b9
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Účet, jehož pověření bylo použito:
Název účtu: kratkyj
Doména účtu: HZAP.LOCAL
GUID přihlášení: {643F7CF2-16FB-A995-9078-F36ED6068947}

Cílový server:
Název cílového serveru: pproi
Další informace: HTTP/pproi

Informace o procesu:
ID procesu: 0x15b4
Název procesu: C:\Program Files\Internet Explorer\iexplore.exe

Informace o síti:
Síťová adresa: -
Port: -

Tato událost je generována, pokud se proces pokusí přihlásit k účtu explicitním zadáním pověření tohoto účtu. K tomu nejčastěji dochází v dávkových konfiguracích, například naplánovaných úlohách, nebo při použití příkazu RUNAS.
Record Number: 175285
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101015094527.145200-000
Event Type: Úspěch auditu
User:

Computer Name: KratkyJvn
Event Code: 4648
Message: Došlo k pokusu o přihlášení pomocí explicitního pověření.

Předmět:
ID zabezpečení: S-1-5-21-3634038287-2164415200-2504289352-1000
Název účtu: KratkyJ
Doména účtu: KratkyJvn
ID přihlášení: 0xa85b9
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Účet, jehož pověření bylo použito:
Název účtu: kratkyj
Doména účtu: HZAP.LOCAL
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Cílový server:
Název cílového serveru: pproi
Další informace: HTTP/pproi

Informace o procesu:
ID procesu: 0x15b4
Název procesu: C:\Program Files\Internet Explorer\iexplore.exe

Informace o síti:
Síťová adresa: -
Port: -

Tato událost je generována, pokud se proces pokusí přihlásit k účtu explicitním zadáním pověření tohoto účtu. K tomu nejčastěji dochází v dávkových konfiguracích, například naplánovaných úlohách, nebo při použití příkazu RUNAS.
Record Number: 175284
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101015094526.929000-000
Event Type: Úspěch auditu
User:

Computer Name: KratkyJvn
Event Code: 4648
Message: Došlo k pokusu o přihlášení pomocí explicitního pověření.

Předmět:
ID zabezpečení: S-1-5-21-3634038287-2164415200-2504289352-1000
Název účtu: KratkyJ
Doména účtu: KratkyJvn
ID přihlášení: 0xa85b9
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Účet, jehož pověření bylo použito:
Název účtu: kratkyj
Doména účtu: HZAP.LOCAL
GUID přihlášení: {643F7CF2-16FB-A995-9078-F36ED6068947}

Cílový server:
Název cílového serveru: pproi
Další informace: HTTP/pproi

Informace o procesu:
ID procesu: 0x15b4
Název procesu: C:\Program Files\Internet Explorer\iexplore.exe

Informace o síti:
Síťová adresa: -
Port: -

Tato událost je generována, pokud se proces pokusí přihlásit k účtu explicitním zadáním pověření tohoto účtu. K tomu nejčastěji dochází v dávkových konfiguracích, například naplánovaných úlohách, nebo při použití příkazu RUNAS.
Record Number: 175283
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101015094526.895000-000
Event Type: Úspěch auditu
User:

Computer Name: KratkyJvn
Event Code: 4648
Message: Došlo k pokusu o přihlášení pomocí explicitního pověření.

Předmět:
ID zabezpečení: S-1-5-21-3634038287-2164415200-2504289352-1000
Název účtu: KratkyJ
Doména účtu: KratkyJvn
ID přihlášení: 0xa85b9
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Účet, jehož pověření bylo použito:
Název účtu: kratkyj
Doména účtu: HZAP.LOCAL
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Cílový server:
Název cílového serveru: pproi
Další informace: HTTP/pproi

Informace o procesu:
ID procesu: 0x15b4
Název procesu: C:\Program Files\Internet Explorer\iexplore.exe

Informace o síti:
Síťová adresa: -
Port: -

Tato událost je generována, pokud se proces pokusí přihlásit k účtu explicitním zadáním pověření tohoto účtu. K tomu nejčastěji dochází v dávkových konfiguracích, například naplánovaných úlohách, nebo při použití příkazu RUNAS.
Record Number: 175282
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101015093934.607400-000
Event Type: Úspěch auditu
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files\NVIDIA Corporation\PhysX\Common;C:\Program Files\PC Connectivity Solution;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\PROGRA~1\IBM\CLIENT~1;C:\PROGRA~1\IBM\CLIENT~1\Shared;C:\PROGRA~1\IBM\CLIENT~1\Emulator;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Intel\WiFi\bin;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0;C:\Program Files\Windows Live\Shared
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=1706
"NUMBER_OF_PROCESSORS"=2
"TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
"DFSTRACINGON"=FALSE
"configsetroot"=%SystemRoot%\ConfigSetRoot
"CLASSPATH"=.;C:\Program Files\Java\j2re1.4.2\lib\ext\QTJava.zip;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\

-----------------EOF-----------------

Re: Kontrola logu

Napsal: 07 pro 2010 07:06
od shorty1963
Logfile of random's system information tool 1.08 (written by random/random)
Run by KratkyJ at 2010-12-07 06:54:49
Microsoft® Windows Vista™ Business Service Pack 2
System drive C: has 27 GB (20%) free of 137 GB
Total RAM: 3070 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:55:11, on 7.12.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\NetTime\NetTime.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Synaptics\SynTP\SynAsus.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\notes\NLNOTES.EXE
C:\notes\ntaskldr.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\KratkyJ\Downloads\SOS\RSIT.exe
C:\Program Files\trend micro\KratkyJ.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://kompas.hzap.local/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Notes Link - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.11.9.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [Client Access Service] "C:\Program Files\IBM\Client Access\cwbsvstr.exe"
O4 - HKLM\..\Run: [Client Access Check Version] "C:\Program Files\IBM\Client Access\cwbckver.exe" LOGIN
O4 - HKLM\..\Run: [Client Access Express Welcome] "C:\Program Files\IBM\Client Access\cwbwlwiz.exe"
O4 - HKLM\..\Run: [Client Access PC5250 Sound] "C:\Program Files\IBM\Client Access\Emulator\pcssnd.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NetTime] C:\Program Files\NetTime\NetTime.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.4.11.9.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O15 - Trusted Zone: http://*.ntsd01
O15 - Trusted Zone: http://*.pproi
O16 - DPF: {0D221D00-A6ED-477C-8A91-41F3B660A832} (RSClientPrint 2005 Class) - http://ntsd01/ReportServer/Reserved.Rep ... e=PrintCab
O16 - DPF: {41861299-EAB2-4DCC-986C-802AE12AC499} (RSClientPrint 2005 Class) - http://ntsd01/ReportServer/Reserved.Rep ... e=PrintCab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: iSeries Access for Windows Remote Command (Cwbrxd) - IBM Corporation - C:\Windows\CWBRXD.EXE
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Kerio VPN Client Service (KVPNCSvc) - Kerio Technologies Inc. - C:\Program Files\Kerio\VPN Client\kvpncsvc.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\notes\ntmulti.exe
O23 - Service: NetTime (NetTimeSvc) - Subjective Software - C:\Program Files\NetTime\NeTmSvNT.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SolidConverterPDFReadSpool (SCPDFReadSpool) - Solid Documents, LLC - C:\Windows\Installer\MSI357.tmp
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Aplikace Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Aplikace Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe

--
End of file - 11596 bytes

======Scheduled tasks folder======

C:\Windows\tasks\User_Feed_Synchronization-{5BE08792-9337-42D5-8B1C-76BA4E5D1B15}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2009-04-22 520192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.4.11.9.dll [2010-11-09 766768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22 191792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-09-22 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-08 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2009-04-22 520192]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"=C:\Program Files\ATKOSD2\ATKOSD2.exe [2008-01-23 7766016]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-11-16 1029416]
"ATKMEDIA"=C:\Program Files\ASUS\ATK Media\DMEDIA.EXE [2008-02-01 61440]
"Client Access Service"=C:\Program Files\IBM\Client Access\cwbsvstr.exe [2005-06-09 20530]
"Client Access Check Version"=C:\Program Files\IBM\Client Access\cwbckver.exe [2005-06-09 45106]
"Client Access Express Welcome"=C:\Program Files\IBM\Client Access\cwbwlwiz.exe [2005-06-09 20480]
"Client Access PC5250 Sound"=C:\Program Files\IBM\Client Access\Emulator\pcssnd.exe [2005-06-09 40960]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2010-11-25 115560]
"NetTime"=C:\Program Files\NetTime\NetTime.exe [2003-01-30 3791032]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-09-11 218032]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2010-05-14 1479680]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EvtMgr6]
C:\Program Files\Logitech\SetPointP\SetPoint.exe [2010-10-29 1352272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2010-01-08 186904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2010-05-14 1479680]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2010-09-08 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-11-02 9808488]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^KratkyJ^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Registrace produktu.lnk]
C:\PROGRA~1\COMMON~1\Logishrd\eReg\SetPoint\eReg.exe [2009-11-16 517384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ccEvtMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ccSetMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sdauxservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sdcoreservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmcService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Symantec Antivirus]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveTrack"=1
"NoDrives"=0
"NoInstrumentation"=0x01

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveTrack"=1
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2010-12-07 06:54:49 ----D---- C:\rsit
2010-12-07 06:38:10 ----D---- C:\Users\KratkyJ\AppData\Roaming\smkits
2010-12-07 06:31:21 ----ASH---- C:\hiberfil.sys
2010-12-07 06:24:57 ----A---- C:\Windows\zip.exe
2010-12-07 06:24:57 ----A---- C:\Windows\SWSC.exe
2010-12-07 06:24:57 ----A---- C:\Windows\SWREG.exe
2010-12-07 06:24:57 ----A---- C:\Windows\sed.exe
2010-12-07 06:24:57 ----A---- C:\Windows\PEV.exe
2010-12-07 06:24:57 ----A---- C:\Windows\NIRCMD.exe
2010-12-07 06:24:57 ----A---- C:\Windows\MBR.exe
2010-12-07 06:24:57 ----A---- C:\Windows\grep.exe
2010-12-07 06:24:48 ----SD---- C:\ComboFix
2010-12-07 06:24:27 ----D---- C:\Qoobox
2010-12-07 06:24:13 ----A---- C:\Windows\SWXCACLS.exe
2010-12-07 06:15:31 ----A---- C:\Windows\ntbtlog.txt
2010-12-06 15:54:25 ----AD---- C:\Windows\rundll16.exe
2010-12-06 15:54:25 ----AD---- C:\Windows\logo1_.exe
2010-12-06 15:49:29 ----A---- C:\Windows\system32\TASKMGR.COM
2010-12-06 15:49:29 ----A---- C:\Windows\REGEDIT.COM
2010-12-05 19:55:08 ----SHD---- C:\$RECYCLE.BIN
2010-12-05 19:55:05 ----D---- C:\Windows\temp
2010-12-05 15:05:45 ----A---- C:\Windows\system32\T.COM
2010-12-05 15:05:45 ----A---- C:\Windows\R.COM
2010-12-05 10:08:55 ----A---- C:\Windows\system32\drivers\rkhdrv40.sys
2010-12-05 10:08:30 ----N---- C:\Windows\system32\SAVRKBootTasks.sys
2010-11-29 11:46:48 ----A---- C:\Windows\system32\drivers\wpshelper.sys
2010-11-29 11:45:27 ----A---- C:\Windows\system32\drivers\SysPlant.sys
2010-11-29 11:45:08 ----A---- C:\Windows\system32\drivers\SYMEVENT.SYS
2010-11-29 11:44:02 ----A---- C:\Windows\system32\capicom.dll
2010-11-29 11:43:34 ----D---- C:\ProgramData\Symantec
2010-11-29 11:43:34 ----D---- C:\Program Files\Symantec
2010-11-29 11:43:34 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-11-26 13:44:19 ----D---- C:\Program Files\Logitech
2010-11-26 13:39:21 ----A---- C:\Windows\system32\RtNicProp32.dll
2010-11-26 13:39:21 ----A---- C:\Windows\system32\drivers\Rtlh86.sys
2010-11-26 13:37:41 ----D---- C:\Windows\system32\RTCOM
2010-11-26 13:36:10 ----A---- C:\Windows\system32\WavesLib.dll
2010-11-26 13:36:10 ----A---- C:\Windows\system32\WavesGUILib.dll
2010-11-26 13:36:10 ----A---- C:\Windows\system32\SRSWOW.dll
2010-11-26 13:36:10 ----A---- C:\Windows\system32\SRSTSXT.dll
2010-11-26 13:36:10 ----A---- C:\Windows\system32\SRSTSHD.dll
2010-11-26 13:36:10 ----A---- C:\Windows\system32\SRSHP360.dll
2010-11-26 13:36:09 ----A---- C:\Windows\system32\SFNHK.dll
2010-11-26 13:36:09 ----A---- C:\Windows\system32\SFCOM.dll
2010-11-26 13:36:09 ----A---- C:\Windows\system32\SFAPO.dll
2010-11-26 13:36:09 ----A---- C:\Windows\system32\RtkPgExt.dll
2010-11-26 13:36:09 ----A---- C:\Windows\system32\RtkCoInst.dll
2010-11-26 13:36:09 ----A---- C:\Windows\system32\RtkApoApi.dll
2010-11-26 13:36:09 ----A---- C:\Windows\system32\RtkAPO.dll
2010-11-26 13:36:09 ----A---- C:\Windows\system32\drivers\RTKVHDA.sys
2010-11-26 13:36:08 ----A---- C:\Windows\system32\RTEEP32A.dll
2010-11-26 13:36:08 ----A---- C:\Windows\system32\RTEEL32A.dll
2010-11-26 13:36:08 ----A---- C:\Windows\system32\RTEEG32A.dll
2010-11-26 13:36:08 ----A---- C:\Windows\system32\RTEED32A.dll
2010-11-26 13:36:08 ----A---- C:\Windows\system32\RP3DHT32.dll
2010-11-26 13:36:08 ----A---- C:\Windows\system32\RP3DAA32.dll
2010-11-26 13:36:08 ----A---- C:\Windows\system32\R4EEP32A.dll
2010-11-26 13:36:08 ----A---- C:\Windows\system32\R4EEL32A.dll
2010-11-26 13:36:08 ----A---- C:\Windows\system32\R4EEG32A.dll
2010-11-26 13:36:08 ----A---- C:\Windows\system32\R4EED32A.dll
2010-11-26 13:36:08 ----A---- C:\Windows\system32\R4EEA32A.dll
2010-11-26 13:36:08 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2010-11-26 13:36:08 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2010-11-26 13:36:08 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2010-11-26 13:36:08 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2010-11-26 13:36:08 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2010-11-26 13:36:08 ----A---- C:\Windows\system32\MaxxAudioAPO.dll
2010-11-26 13:36:06 ----A---- C:\Windows\system32\FMAPO.dll
2010-11-26 13:36:06 ----A---- C:\Windows\system32\DTSVoiceClarityDLL.dll
2010-11-26 13:36:06 ----A---- C:\Windows\system32\DTSSymmetryDLL.dll
2010-11-26 13:36:06 ----A---- C:\Windows\system32\DTSS2SpeakerDLL.dll
2010-11-26 13:36:06 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL.dll
2010-11-26 13:36:06 ----A---- C:\Windows\system32\DTSNeoPCDLL.dll
2010-11-26 13:36:06 ----A---- C:\Windows\system32\DTSLimiterDLL.dll
2010-11-26 13:36:06 ----A---- C:\Windows\system32\DTSLFXAPO.dll
2010-11-26 13:36:06 ----A---- C:\Windows\system32\DTSGFXAPONS.dll
2010-11-26 13:36:06 ----A---- C:\Windows\system32\DTSGFXAPO.dll
2010-11-26 13:36:06 ----A---- C:\Windows\system32\DTSGainCompensatorDLL.dll
2010-11-26 13:36:06 ----A---- C:\Windows\system32\DTSBoostDLL.dll
2010-11-26 13:36:06 ----A---- C:\Windows\system32\DTSBassEnhancementDLL.dll
2010-11-26 13:36:06 ----A---- C:\Windows\system32\AERTARen.dll
2010-11-26 13:36:06 ----A---- C:\Windows\system32\AERTACap.dll
2010-11-26 13:36:02 ----A---- C:\Windows\RtlExUpd.dll
2010-11-26 13:20:04 ----A---- C:\Windows\system32\nvhdap32.dll
2010-11-26 13:20:04 ----A---- C:\Windows\system32\nvgenco32.dll
2010-11-26 13:20:04 ----A---- C:\Windows\system32\nvapo32v.dll
2010-11-26 13:20:04 ----A---- C:\Windows\system32\drivers\nvhda32v.sys
2010-11-26 13:20:02 ----A---- C:\Windows\system32\nvoglv32.dll
2010-11-26 13:20:01 ----A---- C:\Windows\system32\OpenCL.dll
2010-11-26 13:20:01 ----A---- C:\Windows\system32\nvgenco322030.dll
2010-11-26 13:20:01 ----A---- C:\Windows\system32\nvdispco322050.dll
2010-11-26 13:20:01 ----A---- C:\Windows\system32\nvcuvenc.dll
2010-11-26 13:20:01 ----A---- C:\Windows\system32\nvcuda.dll
2010-11-26 13:20:01 ----A---- C:\Windows\system32\nvcompiler.dll
2010-11-26 13:20:01 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2010-11-26 13:20:00 ----A---- C:\Windows\system32\nvcuvid.dll
2010-11-26 13:19:02 ----D---- C:\NVIDIA
2010-11-26 12:58:45 ----D---- C:\Program Files\Driver-Soft
2010-11-25 11:54:56 ----A---- C:\Windows\system32\sysfer.dll
2010-11-25 11:54:56 ----A---- C:\Windows\system32\SymVPN.dll
2010-11-25 11:54:56 ----A---- C:\Windows\system32\FwsVpn.dll
2010-11-25 11:54:56 ----A---- C:\Windows\system32\drivers\WPSDRVnt.sys
2010-11-25 11:54:56 ----A---- C:\Windows\system32\atl71.dll
2010-11-25 11:54:53 ----A---- C:\Windows\system32\drivers\srtspx.sys
2010-11-25 11:54:53 ----A---- C:\Windows\system32\drivers\srtspl.sys
2010-11-25 11:54:53 ----A---- C:\Windows\system32\drivers\srtsp.sys
2010-11-25 11:54:52 ----A---- C:\Windows\system32\drivers\Teefer2.sys
2010-11-25 11:54:47 ----A---- C:\Windows\system32\drivers\symtdi.sys
2010-11-25 11:54:47 ----A---- C:\Windows\system32\drivers\symredrv.sys
2010-11-25 11:54:47 ----A---- C:\Windows\system32\drivers\symndisv.sys
2010-11-25 11:54:46 ----A---- C:\Windows\system32\drivers\symids.sys
2010-11-25 11:54:46 ----A---- C:\Windows\system32\drivers\symfw.sys
2010-11-25 11:54:46 ----A---- C:\Windows\system32\drivers\symdns.sys
2010-11-25 11:54:45 ----A---- C:\Windows\system32\drivers\COH_Mon.sys
2010-11-21 08:48:10 ----D---- C:\Users\KratkyJ\AppData\Roaming\BitComet
2010-11-21 08:44:43 ----D---- C:\Users\KratkyJ\AppData\Roaming\Zbshareware Lab

======List of files/folders modified in the last 1 months======

2010-12-07 06:54:58 ----D---- C:\Program Files\trend micro
2010-12-07 06:31:59 ----D---- C:\ProgramData\NVIDIA
2010-12-07 06:28:29 ----D---- C:\Windows\system32\drivers
2010-12-07 06:28:26 ----D---- C:\Windows\System32
2010-12-07 06:28:26 ----AD---- C:\Windows
2010-12-07 06:06:18 ----D---- C:\Windows\Prefetch
2010-12-06 15:35:27 ----AD---- C:\ProgramData\TEMP
2010-12-06 15:34:24 ----SHD---- C:\System Volume Information
2010-12-06 15:20:09 ----D---- C:\ProgramData\Kaspersky Lab
2010-12-05 19:51:35 ----A---- C:\Windows\system.ini
2010-12-05 19:51:28 ----D---- C:\Windows\system32\drivers\etc
2010-12-05 19:47:11 ----D---- C:\Windows\AppPatch
2010-12-05 19:47:10 ----D---- C:\Program Files\Common Files
2010-12-05 19:31:23 ----D---- C:\Windows\ERDNT
2010-12-05 17:34:29 ----D---- C:\Program Files\CCleaner
2010-12-05 16:24:43 ----D---- C:\Windows\system32\catroot2
2010-12-05 14:53:48 ----D---- C:\Windows\Minidump
2010-12-05 08:14:44 ----D---- C:\Program Files
2010-12-04 21:51:20 ----D---- C:\Users\KratkyJ\AppData\Roaming\ICQ
2010-12-04 19:40:00 ----D---- C:\Windows\inf
2010-12-04 19:40:00 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-04 19:36:50 ----D---- C:\Windows\system32\catroot
2010-12-04 11:16:31 ----D---- C:\Program Files\PowerArchiver
2010-12-03 22:40:37 ----D---- C:\Program Files\Spyware Doctor
2010-12-03 11:55:49 ----HD---- C:\Program Files\InstallShield Installation Information
2010-12-03 10:33:28 ----D---- C:\Windows\Tasks
2010-12-02 15:16:13 ----D---- C:\Windows\Downloaded Installations
2010-12-02 12:22:17 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-12-02 10:30:28 ----D---- C:\Windows\system32\Tasks
2010-11-30 15:00:47 ----D---- C:\ProgramData\Spybot - Search & Destroy
2010-11-29 11:46:50 ----SHD---- C:\Windows\Installer
2010-11-29 11:45:19 ----D---- C:\notes
2010-11-29 11:44:14 ----D---- C:\ProgramData
2010-11-26 13:45:49 ----SD---- C:\Users\KratkyJ\AppData\Roaming\Microsoft
2010-11-26 13:45:29 ----D---- C:\Program Files\Common Files\Logishrd
2010-11-26 13:44:28 ----D---- C:\ProgramData\Logishrd
2010-11-26 13:39:21 ----D---- C:\Program Files\Realtek
2010-11-26 13:38:25 ----HD---- C:\Program Files\Temp
2010-11-26 13:36:13 ----A---- C:\Windows\DIFxAPI.dll
2010-11-26 13:31:55 ----D---- C:\Windows\system32\WDI
2010-11-26 13:24:17 ----D---- C:\Program Files\NVIDIA Corporation
2010-11-26 13:24:04 ----D---- C:\Program Files\AGEIA Technologies
2010-11-24 15:14:05 ----D---- C:\Windows\winsxs
2010-11-24 15:14:05 ----D---- C:\Program Files\Internet Explorer
2010-11-21 08:48:10 ----D---- C:\Program Files\BitComet
2010-11-21 08:46:14 ----D---- C:\Program Files\USB Disk Security
2010-11-21 08:44:33 ----D---- C:\ProgramData\Zbshareware Lab
2010-11-10 17:52:56 ----D---- C:\Windows\Debug
2010-11-10 08:07:41 ----D---- C:\ProgramData\Microsoft Help
2010-11-10 08:07:03 ----D---- C:\Program Files\Windows Mail
2010-11-10 08:04:33 ----A---- C:\Windows\system32\mrt.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-01-08 331288]
R0 PCTCore;PCTools KDS; C:\Windows\system32\drivers\PCTCore.sys [2010-01-15 206256]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2010-12-07 371248]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2008-07-21 24392]
R1 SAVRKBootTasks;Boot Tasks Driver; \??\C:\Windows\system32\SAVRKBootTasks.sys [2009-06-18 18816]
R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [2010-11-25 421424]
R1 SRTSP;SRTSP; C:\Windows\System32\Drivers\SRTSP.SYS [2010-11-25 283184]
R1 SRTSPX;SRTSPX; C:\Windows\System32\Drivers\SRTSPX.SYS [2010-11-25 43696]
R1 SYMTDI;SYMTDI; C:\Windows\System32\Drivers\SYMTDI.SYS [2010-11-25 188080]
R1 WPS;WPS; \??\C:\Windows\system32\drivers\wpsdrvnt.sys [2010-11-25 43336]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2009-06-25 48128]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2009-06-25 44544]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2009-06-25 38400]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-21 1203776]
R3 AnyDVD;AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [2008-09-04 99648]
R3 ATSWPDRV;AuthenTec TruePrint USB Driver (SwipeSensor); C:\Windows\system32\DRIVERS\ATSwpDrv.sys [2007-06-16 146824]
R3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2008-03-17 81960]
R3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2008-03-17 100392]
R3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2008-01-29 29736]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2008-03-17 17320]
R3 DCamUSBET;USB2.0 1.3M UVC WebCam; C:\Windows\system32\DRIVERS\etDevice.sys [2008-10-20 138920]
R3 ElbyCDFL;ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [2007-02-16 34760]
R3 ElbyDelay;ElbyDelay; C:\Windows\System32\Drivers\ElbyDelay.sys [2007-02-16 11984]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-12-03 102448]
R3 FiltUSBET;ET USB Device Lower Filter; C:\Windows\system32\DRIVERS\etFilter.sys [2008-10-20 21544]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2010-11-02 3228712]
R3 itecir;ITECIR Infrared Receiver; C:\Windows\system32\DRIVERS\itecir.sys [2007-12-18 54784]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2008-11-03 13880]
R3 kvnet;Kerio Virtual Network Adapter; C:\Windows\system32\DRIVERS\kvnet.sys [2009-03-23 26624]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\System32\Drivers\LEqdUsb.Sys [2010-08-24 40912]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\System32\Drivers\LHidEqd.Sys [2010-08-24 10448]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2010-08-24 38864]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2010-08-24 37328]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2010-11-29 20952]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys [2008-01-21 18432]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680]
R3 NAVENG;NAVENG; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20101206.024\NAVENG.SYS [2010-12-07 86064]
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20101206.024\NAVEX15.SYS [2010-12-07 1371184]
R3 NETwNv32;___ Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETwNv32.sys [2010-10-18 6959616]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2010-09-07 123496]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2010-10-16 10084360]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2010-08-25 263272]
R3 ScanUSBET;ET USB Still Image Capture Device; C:\Windows\system32\DRIVERS\etScan.sys [2008-10-20 13224]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2010-11-29 124976]
R3 SYMREDRV;SYMREDRV; C:\Windows\System32\Drivers\SYMREDRV.SYS [2010-11-25 26416]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-11-16 195760]
R3 Teefer2;Teefer2 Miniport; C:\Windows\system32\DRIVERS\teefer2.sys [2010-11-25 67472]
R3 WpsHelper;WpsHelper; \??\C:\Windows\system32\drivers\WpsHelper.sys [2010-11-29 167936]
R3 WudfPf;User Mode Driver Frameworks Platform Driver; C:\Windows\system32\drivers\WudfPf.sys [2009-07-14 92672]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2009-07-14 132224]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 catchme;catchme; \??\C:\Users\KratkyJ\AppData\Local\Temp\catchme.sys []
S3 COH_Mon;COH_Mon; \??\C:\Windows\system32\Drivers\COH_Mon.sys [2010-11-25 23888]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-22 39272]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
S3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2010-03-18 28624]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NETw5v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw5v32.sys [2010-01-13 6628352]
S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 rkhdrv40;Rootkit Unhooker Driver; C:\Windows\system32\drivers\rkhdrv40.sys [2010-12-05 24448]
S3 Ser2pl;Prolific2 Serial port driver; C:\Windows\system32\DRIVERS\ser2pl.sys [2005-11-04 48640]
S3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-02 1010560]
S3 SRTSPL;SRTSPL; C:\Windows\System32\Drivers\SRTSPL.SYS [2010-11-25 320944]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbser;USB Modem Driver; C:\Windows\system32\DRIVERS\usbser.sys [2009-04-11 27648]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 SysPlant;SysPlant for NT; C:\Windows\SYSTEM32\Drivers\SysPlant.sys [2010-11-25 97096]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2008-03-18 13312]
R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-10-02 94208]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-07 94208]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-04-10 518696]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2010-11-25 108392]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2010-11-25 108392]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2009-02-27 870672]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2010-01-08 354840]
R2 KVPNCSvc;Kerio VPN Client Service; C:\Program Files\Kerio\VPN Client\kvpncsvc.exe [2009-10-26 972648]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-03-17 73728]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-11-29 363344]
R2 Multi-user Cleanup Service;Multi-user Cleanup Service; C:\notes\ntmulti.exe [2009-03-24 53248]
R2 NetTimeSvc;NetTime; C:\Program Files\NetTime\NeTmSvNT.exe [2003-01-30 452096]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-10-16 600680]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2009-02-27 473360]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-01-09 272024]
R2 SCPDFReadSpool;SolidConverterPDFReadSpool; C:\Windows\Installer\MSI357.tmp [2010-01-22 189696]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136]
R2 SmcService;Aplikace Symantec Management Client; C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe [2010-11-25 1881368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
R2 Symantec AntiVirus;Aplikace Symantec Endpoint Protection; C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe [2010-11-25 1831024]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-09-29 616448]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 Cwbrxd;iSeries Access for Windows Remote Command; C:\Windows\CWBRXD.EXE [2005-06-09 57344]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-22 1493352]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2010-10-28 293456]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2010-02-17 3093880]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 sdAuxService;PC Tools Auxiliary Service; C:\Program Files\Spyware Doctor\pctsAuxs.exe [2009-01-07 348752]
S3 sdCoreService;PC Tools Security Service; C:\Program Files\Spyware Doctor\pctsSvc.exe [2009-07-22 1097096]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 SNAC;Aplikace Symantec Network Access Control ; C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE [2010-11-25 349512]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

-----------------EOF-----------------