
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu po opravě a čištění
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Prosím o kontrolu po opravě a čištění
Myslím ,že problémy nejsou. Aspoň ne ty co jsme řešilo.
Nepoužíváte náhodou Thunderbird? Já nemůžu pomoct, ale čím novější verze tím větší potíže.
Nepoužíváte náhodou Thunderbird? Já nemůžu pomoct, ale čím novější verze tím větší potíže.
Re: Prosím o kontrolu po opravě a čištění
Jestli vás to zajímá tak toto našlo to AVG"
Path: C:\Windows\System32\Drivers\au0o0tr3.SYS Description: Hidden driver filePath: C:\Windows\System32\Drivers\au0o0tr3.SYS Description: Hidden driver file
Path: C:\Windows\System32\Drivers\au0o0tr3.SYS Description: Hidden driver filePath: C:\Windows\System32\Drivers\au0o0tr3.SYS Description: Hidden driver file
Re: Prosím o kontrolu po opravě a čištění
Tu Farmu Vám tam opravdu dal Whistler bootkit, je to takový šikovný mbr rootkit a je to celkem novinka
.
Nepoužíváte Daemon nebo alcohol?

Nepoužíváte Daemon nebo alcohol?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu po opravě a čištění
No po/užívám oboje:
Dameon na virtuální mechaniku
a Alkohol vnitřně
Dameon na virtuální mechaniku
a Alkohol vnitřně

Re: Prosím o kontrolu po opravě a čištění
Takže to bude driver od virtuálky. Pokud začíná na a.. a po restartu má zase jiný název. AVG je známý tím, že ji detekuje jako rootkit, protože tyto virutálky využívají rootkit techniky.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu po opravě a čištění
Ještě bych se chtěl zeptet. Mám si změnit ty hesla? Na hesla používám Keepass.
Re: Prosím o kontrolu po opravě a čištění
Raději změnte 

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu po opravě a čištění
Ahoj.
Log po týdnu. Pro kontrolu:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Milan at 2010-08-14 10:01:38
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 46 GB (30%) free of 151 GB
Total RAM: 3326 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:01:48, on 14.8.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Opera\Opera.exe
C:\Users\Milan\Desktop\RSIT.exe
C:\Program Files\trend micro\Milan.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.0.14.1:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [Thunderbird] C:\Program Files\Mozilla Thunderbird\thunderbird.exe -mail
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{B34111F9-934E-414C-A437-0D91D4D067C2}: NameServer = 212.71.128.9
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\Windows\System32\guard32.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Unknown owner - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (file missing)
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Google Update Service (gupdate1c9de051e6229f3) (gupdate1c9de051e6229f3) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 5483 bytes
======Scheduled tasks folder======
C:\Windows\tasks\1-Click Maintenance.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\User_Feed_Synchronization-{ACD3081E-137A-4415-A280-DF4AC784C662}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - C:\Program Files\Orbitdownloader\orbitcth.dll [2010-05-07 240912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-07-17 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{C55BBCD6-41AD-48AD-9953-3609C48EACC7} - Grab Pro - C:\Program Files\Orbitdownloader\GrabPro.dll [2010-05-07 666816]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-06-28 2837864]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-05-27 102400]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-05-10 4468736]
"itype"=C:\Program Files\Microsoft IntelliType Pro\itype.exe [2008-06-10 1442888]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-08-09 2039240]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Thunderbird"=C:\Program Files\Mozilla Thunderbird\thunderbird.exe [2010-08-06 12746928]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\System32\guard32.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Orbitdownloader\orbitdm.exe"="C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit"
"C:\Program Files\Orbitdownloader\orbitnet.exe"="C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2010-08-14 10:01:38 ----D---- C:\rsit
2010-08-14 09:13:44 ----D---- C:\Program Files\DAEMON Tools Lite
2010-08-14 01:48:20 ----SHD---- C:\$RECYCLE.BIN
2010-08-14 01:48:19 ----D---- C:\Windows\temp
2010-08-11 11:43:40 ----A---- C:\Windows\system32\mshtml.dll
2010-08-11 11:43:40 ----A---- C:\Windows\system32\iertutil.dll
2010-08-11 11:43:39 ----A---- C:\Windows\system32\urlmon.dll
2010-08-11 11:43:39 ----A---- C:\Windows\system32\msfeeds.dll
2010-08-11 11:43:39 ----A---- C:\Windows\system32\ieframe.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\wininet.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\occache.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\mstime.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\msfeedssync.exe
2010-08-11 11:43:19 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\jsproxy.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\ieUnatt.exe
2010-08-11 11:43:19 ----A---- C:\Windows\system32\ieui.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\iesysprep.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\iesetup.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\iernonce.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\iepeers.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\iedkcs32.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\ie4uinit.exe
2010-08-11 11:43:17 ----A---- C:\Windows\system32\msxml3.dll
2010-08-11 11:43:17 ----A---- C:\Windows\system32\iccvid.dll
2010-08-11 11:43:14 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-08-11 11:43:14 ----A---- C:\Windows\system32\drivers\srv.sys
2010-08-11 11:43:13 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-08-11 11:43:12 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-08-11 11:43:11 ----A---- C:\Windows\system32\rtutils.dll
2010-08-11 11:43:10 ----A---- C:\Windows\system32\win32k.sys
2010-08-11 11:43:08 ----A---- C:\Windows\system32\schannel.dll
2010-08-11 11:42:20 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-08-11 01:05:00 ----A---- C:\Windows\VcncDll.INI
2010-08-07 23:44:28 ----D---- C:\Users\Milan\AppData\Roaming\DAEMON Tools Lite
2010-08-07 23:44:20 ----D---- C:\ProgramData\DAEMON Tools Lite
2010-08-07 20:02:26 ----D---- C:\VritualRoot
2010-08-07 10:49:42 ----A---- C:\Windows\system32\TUProgSt.exe
2010-08-07 10:49:38 ----A---- C:\Windows\system32\uxtuneup.dll
2010-08-07 10:49:38 ----A---- C:\Windows\system32\authuitu.dll
2010-08-07 10:49:33 ----A---- C:\Windows\system32\TuneUpDefragService.exe
2010-08-07 10:49:18 ----D---- C:\Program Files\TuneUp Utilities 2009
2010-08-06 20:56:52 ----ASH---- C:\hiberfil.sys
2010-08-06 01:06:16 ----D---- C:\Program Files\Common Files\Java
2010-08-06 01:06:03 ----A---- C:\Windows\system32\javaws.exe
2010-08-06 01:06:03 ----A---- C:\Windows\system32\javaw.exe
2010-08-06 01:06:03 ----A---- C:\Windows\system32\java.exe
2010-08-05 22:56:56 ----D---- C:\Users\Milan\AppData\Roaming\Mael
2010-08-05 15:20:36 ----D---- C:\ProgramData\Sun
2010-08-05 15:20:11 ----A---- C:\Windows\system32\deployJava1.dll
2010-08-05 14:34:31 ----D---- C:\Program Files\trend micro
2010-08-05 00:06:26 ----A---- C:\Windows\system32\browserchoice.exe
2010-08-04 23:56:05 ----A---- C:\Windows\system32\shell32.dll
2010-08-04 17:27:16 ----D---- C:\Users\Milan\AppData\Roaming\Acronis
2010-08-03 15:59:55 ----ASH---- C:\pagefile.sys
2010-07-30 11:29:20 ----A---- C:\Windows\system32\drivers\StarOpen.sys
2010-07-30 11:08:45 ----D---- C:\Program Files\Ashampoo
2010-07-30 10:40:12 ----A---- C:\Windows\system32\QTCF.dll
2010-07-23 13:18:15 ----D---- C:\Users\Milan\AppData\Roaming\vlc
2010-07-22 21:35:45 ----D---- C:\Program Files\GIMP-2.0
2010-07-22 09:04:32 ----D---- C:\Program Files\GIMP 2.7
======List of files/folders modified in the last 1 months======
2010-08-14 10:01:48 ----D---- C:\Windows\Prefetch
2010-08-14 09:26:19 ----D---- C:\Windows
2010-08-14 09:20:42 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-14 09:20:42 ----D---- C:\Program Files\Common Files
2010-08-14 09:20:39 ----SHD---- C:\System Volume Information
2010-08-14 09:18:21 ----D---- C:\Program Files
2010-08-14 09:07:57 ----D---- C:\Windows\System32
2010-08-14 09:07:57 ----D---- C:\Windows\inf
2010-08-14 09:07:57 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-08-14 01:45:24 ----A---- C:\Windows\system.ini
2010-08-14 01:45:13 ----D---- C:\Windows\system32\drivers\etc
2010-08-14 01:41:54 ----D---- C:\Windows\system32\drivers
2010-08-14 01:41:54 ----D---- C:\Windows\AppPatch
2010-08-14 01:30:03 ----D---- C:\Windows\system32\cs-CZ
2010-08-13 22:41:17 ----D---- C:\Users\Milan\AppData\Roaming\Skype
2010-08-13 22:40:48 ----D---- C:\Users\Milan\AppData\Roaming\skypePM
2010-08-13 22:34:44 ----D---- C:\Windows\Tasks
2010-08-13 22:34:40 ----D---- C:\Windows\system32\Tasks
2010-08-13 11:27:14 ----SHD---- C:\Windows\Installer
2010-08-13 11:27:00 ----D---- C:\Program Files\Opera
2010-08-13 00:47:38 ----D---- C:\Users\Milan\AppData\Roaming\Xfire
2010-08-13 00:02:30 ----A---- C:\Windows\system32\PnkBstrB.exe
2010-08-12 00:40:18 ----D---- C:\Windows\Debug
2010-08-12 00:40:18 ----D---- C:\Users\Milan\AppData\Roaming\Media Player Classic
2010-08-12 00:35:34 ----D---- C:\Program Files\Ant Movie Catalog
2010-08-12 00:20:30 ----D---- C:\Users\Milan\AppData\Roaming\gtk-2.0
2010-08-11 23:49:35 ----D---- C:\Program Files\Avidemux 2.5
2010-08-11 22:50:06 ----D---- C:\Windows\winsxs
2010-08-11 13:15:07 ----RSD---- C:\Windows\assembly
2010-08-11 13:15:07 ----D---- C:\Windows\Microsoft.NET
2010-08-11 13:10:39 ----D---- C:\Windows\system32\migration
2010-08-11 13:10:39 ----D---- C:\Program Files\Internet Explorer
2010-08-11 13:10:38 ----D---- C:\Program Files\Movie Maker
2010-08-11 11:44:25 ----D---- C:\Windows\system32\catroot
2010-08-11 11:44:20 ----D---- C:\Program Files\Windows Mail
2010-08-11 11:42:46 ----D---- C:\Windows\system32\catroot2
2010-08-09 18:37:38 ----D---- C:\Users\Milan\AppData\Roaming\dvdcss
2010-08-09 15:14:14 ----A---- C:\Windows\system32\guard32.dll
2010-08-08 23:29:32 ----D---- C:\Users\Milan\AppData\Roaming\Orbit
2010-08-08 11:53:56 ----D---- C:\ProgramData\Spybot - Search & Destroy
2010-08-07 23:44:20 ----D---- C:\ProgramData
2010-08-07 22:45:19 ----D---- C:\downloads
2010-08-07 09:44:10 ----D---- C:\Temp
2010-08-06 22:33:48 ----D---- C:\Program Files\Mozilla Thunderbird
2010-08-06 01:06:02 ----D---- C:\Program Files\Java
2010-08-05 23:54:30 ----D---- C:\Boot
2010-08-05 12:41:53 ----D---- C:\Windows\security
2010-08-05 09:54:19 ----SD---- C:\Users\Milan\AppData\Roaming\Microsoft
2010-08-04 23:43:58 ----D---- C:\Windows\system32\Msdtc
2010-08-04 23:43:56 ----D---- C:\Windows\system32\wbem
2010-08-04 23:43:49 ----D---- C:\Windows\pss
2010-08-04 23:43:12 ----D---- C:\Windows\system32\config
2010-08-04 23:42:47 ----D---- C:\Windows\PolicyDefinitions
2010-08-04 23:42:43 ----D---- C:\Windows\system32\spool
2010-08-04 23:42:43 ----D---- C:\Windows\system32\CodeIntegrity
2010-08-04 23:42:41 ----D---- C:\Windows\rescache
2010-08-04 23:42:34 ----D---- C:\Users\Milan\AppData\Roaming\TS3Client
2010-08-04 23:42:33 ----D---- C:\Users\Milan\AppData\Roaming\Thunderbird
2010-08-04 23:42:33 ----D---- C:\Users\Milan\AppData\Roaming\RapidGet
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\MakeUpPilot
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\KeePass
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\HLSW
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\Hamachi
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\GHISLER
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\DVD Flick
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\DeepBurner
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\DAEMON Tools
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\BeautyPilot
2010-08-04 23:42:27 ----D---- C:\ProgramData\Xfire
2010-08-04 23:42:27 ----D---- C:\ProgramData\Ulead Systems
2010-08-04 23:42:27 ----D---- C:\Program Files\Microsoft Silverlight
2010-08-04 23:42:05 ----D---- C:\Windows\registration
2010-08-04 21:23:37 ----SD---- C:\Windows\Downloaded Program Files
2010-08-04 20:56:53 ----D---- C:\Windows\Minidump
2010-08-04 18:26:38 ----D---- C:\ProgramData\Acronis
2010-08-03 20:09:31 ----A---- C:\Windows\system32\mrt.exe
2010-08-01 18:11:51 ----D---- C:\Program Files\Xfire
2010-07-31 10:22:11 ----D---- C:\Windows\system32\LogFiles
2010-07-30 11:29:20 ----D---- C:\Program Files\CDBurnerXP
2010-07-30 11:25:24 ----D---- C:\Program Files\CCleaner
2010-07-30 11:14:57 ----D---- C:\Users\Milan\AppData\Roaming\Ashampoo
2010-07-30 10:40:20 ----D---- C:\Program Files\QuickTime Alternative
2010-07-26 11:31:38 ----D---- C:\VueScan
2010-07-26 10:24:16 ----D---- C:\Users\Milan\AppData\Roaming\Mozilla
2010-07-23 15:06:04 ----D---- C:\Program Files\FastStone Image Viewer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 hotcore3;hc3ServiceName; C:\Windows\system32\drivers\hotcore3.sys [2010-02-03 40560]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-08-14 691696]
R0 timounter;Acronis True Image Backup Archive Explorer; C:\Windows\system32\DRIVERS\timntr.sys [2010-04-14 441760]
R1 Amfilter;A4Tech Mouse Filter Driver; C:\Windows\system32\DRIVERS\Amfilter.sys [2007-05-15 9216]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2010-06-28 23376]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2010-06-28 165456]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2010-06-28 46672]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2010-08-09 224240]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2010-08-09 30112]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2010-08-09 75944]
R1 Uim_IM;UIM Drive Backup Image Plugin; C:\Windows\System32\Drivers\Uim_IM.sys [2010-02-03 385544]
R1 UimBus;Universal Image Mounter Controller; C:\Windows\system32\DRIVERS\UimBus.sys [2010-02-03 34392]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2008-02-12 232472]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2010-06-28 17744]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2010-06-28 50256]
R2 CX23880;WinFast CX2388x WDM Video Capture.; C:\Windows\system32\drivers\cx88vid.sys [2006-10-18 162944]
R2 CXAVXBAR;WinFast CX2388x WDM Crossbar.; C:\Windows\system32\drivers\cxavxbar.sys [2006-10-18 9728]
R2 CXTUNE;Conexant 2388x Tuner; C:\Windows\system32\drivers\CX88TUNE_IBV32.sys [2006-11-02 17664]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2008-01-21 95744]
R2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2007-08-13 5120]
R2 tifsfilter;Acronis True Image FS Filter; C:\Windows\system32\DRIVERS\tifsfilt.sys [2010-04-14 44384]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-05-27 5550592]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-05-27 176128]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller; C:\Windows\system32\DRIVERS\l160x86.sys [2007-10-31 46592]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-03-09 104464]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-05-10 1775712]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2006-10-18 7680]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2008-02-05 59960]
R3 VRVD302;VRVD302; C:\Windows\system32\DRIVERS\VRVD302.sys [2008-08-31 11296]
S2 DgiVecp;DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [2007-08-13 41984]
S3 a93vb3lf;a93vb3lf; C:\Windows\system32\drivers\a93vb3lf.sys []
S3 ae649d18;ae649d18; C:\Windows\system32\drivers\ae649d18.sys []
S3 Amusbprt;A4Tech HID-compliant Mouse Driver; C:\Windows\system32\DRIVERS\Amusbprt.sys [2007-05-15 14336]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-05-27 5550592]
S3 CrystalSysInfo;CrystalSysInfo; \??\e:\Program Files\MediaCoder\SysInfo.sys []
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 ENTECH;ENTECH; \??\C:\Windows\system32\DRIVERS\ENTECH.sys [2008-05-29 27672]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2008-11-11 25280]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 PSI;PSI; C:\Windows\system32\DRIVERS\psi_mf.sys [2009-06-17 12648]
S3 pwdrvio;pwdrvio; \??\C:\Windows\system32\pwdrvio.sys [2009-12-21 16456]
S3 pwdspio;pwdspio; \??\C:\Windows\system32\pwdspio.sys [2009-12-21 11088]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2009-11-12 7168]
S3 STIrUsb;SigmaTel USB-IrDA Dongle; C:\Windows\system32\DRIVERS\irstusb.sys [2008-01-21 30208]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-04-11 15872]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 WINUSB;Ovladač WinUsb; C:\Windows\system32\DRIVERS\WinUSB.SYS [2009-04-11 31616]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2008-07-03 109056]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-05-27 172032]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-08-09 1778480]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 NMSAccess;NMSAccess; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2010-03-04 71096]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-03-03 75064]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 TuneUp.ProgramStatisticsSvc;@%SystemRoot%\System32\TUProgSt.exe,-1; C:\Windows\System32\TUProgSt.exe [2010-08-07 604488]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-12-13 49152]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
S2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe []
S2 gupdate1c9de051e6229f3;Google Update Service (gupdate1c9de051e6229f3); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-05-26 133104]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-03-30 31048]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 TuneUp.Defrag;@%SystemRoot%\System32\TuneUpDefragService.exe,-1; C:\Windows\System32\TuneUpDefragService.exe [2010-08-07 361288]
-----------------EOF-----------------
Log po týdnu. Pro kontrolu:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Milan at 2010-08-14 10:01:38
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 46 GB (30%) free of 151 GB
Total RAM: 3326 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:01:48, on 14.8.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Opera\Opera.exe
C:\Users\Milan\Desktop\RSIT.exe
C:\Program Files\trend micro\Milan.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.0.14.1:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [Thunderbird] C:\Program Files\Mozilla Thunderbird\thunderbird.exe -mail
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{B34111F9-934E-414C-A437-0D91D4D067C2}: NameServer = 212.71.128.9
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\Windows\System32\guard32.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Unknown owner - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (file missing)
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Google Update Service (gupdate1c9de051e6229f3) (gupdate1c9de051e6229f3) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 5483 bytes
======Scheduled tasks folder======
C:\Windows\tasks\1-Click Maintenance.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\User_Feed_Synchronization-{ACD3081E-137A-4415-A280-DF4AC784C662}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - C:\Program Files\Orbitdownloader\orbitcth.dll [2010-05-07 240912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-07-17 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{C55BBCD6-41AD-48AD-9953-3609C48EACC7} - Grab Pro - C:\Program Files\Orbitdownloader\GrabPro.dll [2010-05-07 666816]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-06-28 2837864]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-05-27 102400]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-05-10 4468736]
"itype"=C:\Program Files\Microsoft IntelliType Pro\itype.exe [2008-06-10 1442888]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-08-09 2039240]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Thunderbird"=C:\Program Files\Mozilla Thunderbird\thunderbird.exe [2010-08-06 12746928]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\System32\guard32.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Orbitdownloader\orbitdm.exe"="C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit"
"C:\Program Files\Orbitdownloader\orbitnet.exe"="C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2010-08-14 10:01:38 ----D---- C:\rsit
2010-08-14 09:13:44 ----D---- C:\Program Files\DAEMON Tools Lite
2010-08-14 01:48:20 ----SHD---- C:\$RECYCLE.BIN
2010-08-14 01:48:19 ----D---- C:\Windows\temp
2010-08-11 11:43:40 ----A---- C:\Windows\system32\mshtml.dll
2010-08-11 11:43:40 ----A---- C:\Windows\system32\iertutil.dll
2010-08-11 11:43:39 ----A---- C:\Windows\system32\urlmon.dll
2010-08-11 11:43:39 ----A---- C:\Windows\system32\msfeeds.dll
2010-08-11 11:43:39 ----A---- C:\Windows\system32\ieframe.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\wininet.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\occache.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\mstime.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\msfeedssync.exe
2010-08-11 11:43:19 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\jsproxy.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\ieUnatt.exe
2010-08-11 11:43:19 ----A---- C:\Windows\system32\ieui.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\iesysprep.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\iesetup.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\iernonce.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\iepeers.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\iedkcs32.dll
2010-08-11 11:43:19 ----A---- C:\Windows\system32\ie4uinit.exe
2010-08-11 11:43:17 ----A---- C:\Windows\system32\msxml3.dll
2010-08-11 11:43:17 ----A---- C:\Windows\system32\iccvid.dll
2010-08-11 11:43:14 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-08-11 11:43:14 ----A---- C:\Windows\system32\drivers\srv.sys
2010-08-11 11:43:13 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-08-11 11:43:12 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-08-11 11:43:11 ----A---- C:\Windows\system32\rtutils.dll
2010-08-11 11:43:10 ----A---- C:\Windows\system32\win32k.sys
2010-08-11 11:43:08 ----A---- C:\Windows\system32\schannel.dll
2010-08-11 11:42:20 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-08-11 01:05:00 ----A---- C:\Windows\VcncDll.INI
2010-08-07 23:44:28 ----D---- C:\Users\Milan\AppData\Roaming\DAEMON Tools Lite
2010-08-07 23:44:20 ----D---- C:\ProgramData\DAEMON Tools Lite
2010-08-07 20:02:26 ----D---- C:\VritualRoot
2010-08-07 10:49:42 ----A---- C:\Windows\system32\TUProgSt.exe
2010-08-07 10:49:38 ----A---- C:\Windows\system32\uxtuneup.dll
2010-08-07 10:49:38 ----A---- C:\Windows\system32\authuitu.dll
2010-08-07 10:49:33 ----A---- C:\Windows\system32\TuneUpDefragService.exe
2010-08-07 10:49:18 ----D---- C:\Program Files\TuneUp Utilities 2009
2010-08-06 20:56:52 ----ASH---- C:\hiberfil.sys
2010-08-06 01:06:16 ----D---- C:\Program Files\Common Files\Java
2010-08-06 01:06:03 ----A---- C:\Windows\system32\javaws.exe
2010-08-06 01:06:03 ----A---- C:\Windows\system32\javaw.exe
2010-08-06 01:06:03 ----A---- C:\Windows\system32\java.exe
2010-08-05 22:56:56 ----D---- C:\Users\Milan\AppData\Roaming\Mael
2010-08-05 15:20:36 ----D---- C:\ProgramData\Sun
2010-08-05 15:20:11 ----A---- C:\Windows\system32\deployJava1.dll
2010-08-05 14:34:31 ----D---- C:\Program Files\trend micro
2010-08-05 00:06:26 ----A---- C:\Windows\system32\browserchoice.exe
2010-08-04 23:56:05 ----A---- C:\Windows\system32\shell32.dll
2010-08-04 17:27:16 ----D---- C:\Users\Milan\AppData\Roaming\Acronis
2010-08-03 15:59:55 ----ASH---- C:\pagefile.sys
2010-07-30 11:29:20 ----A---- C:\Windows\system32\drivers\StarOpen.sys
2010-07-30 11:08:45 ----D---- C:\Program Files\Ashampoo
2010-07-30 10:40:12 ----A---- C:\Windows\system32\QTCF.dll
2010-07-23 13:18:15 ----D---- C:\Users\Milan\AppData\Roaming\vlc
2010-07-22 21:35:45 ----D---- C:\Program Files\GIMP-2.0
2010-07-22 09:04:32 ----D---- C:\Program Files\GIMP 2.7
======List of files/folders modified in the last 1 months======
2010-08-14 10:01:48 ----D---- C:\Windows\Prefetch
2010-08-14 09:26:19 ----D---- C:\Windows
2010-08-14 09:20:42 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-14 09:20:42 ----D---- C:\Program Files\Common Files
2010-08-14 09:20:39 ----SHD---- C:\System Volume Information
2010-08-14 09:18:21 ----D---- C:\Program Files
2010-08-14 09:07:57 ----D---- C:\Windows\System32
2010-08-14 09:07:57 ----D---- C:\Windows\inf
2010-08-14 09:07:57 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-08-14 01:45:24 ----A---- C:\Windows\system.ini
2010-08-14 01:45:13 ----D---- C:\Windows\system32\drivers\etc
2010-08-14 01:41:54 ----D---- C:\Windows\system32\drivers
2010-08-14 01:41:54 ----D---- C:\Windows\AppPatch
2010-08-14 01:30:03 ----D---- C:\Windows\system32\cs-CZ
2010-08-13 22:41:17 ----D---- C:\Users\Milan\AppData\Roaming\Skype
2010-08-13 22:40:48 ----D---- C:\Users\Milan\AppData\Roaming\skypePM
2010-08-13 22:34:44 ----D---- C:\Windows\Tasks
2010-08-13 22:34:40 ----D---- C:\Windows\system32\Tasks
2010-08-13 11:27:14 ----SHD---- C:\Windows\Installer
2010-08-13 11:27:00 ----D---- C:\Program Files\Opera
2010-08-13 00:47:38 ----D---- C:\Users\Milan\AppData\Roaming\Xfire
2010-08-13 00:02:30 ----A---- C:\Windows\system32\PnkBstrB.exe
2010-08-12 00:40:18 ----D---- C:\Windows\Debug
2010-08-12 00:40:18 ----D---- C:\Users\Milan\AppData\Roaming\Media Player Classic
2010-08-12 00:35:34 ----D---- C:\Program Files\Ant Movie Catalog
2010-08-12 00:20:30 ----D---- C:\Users\Milan\AppData\Roaming\gtk-2.0
2010-08-11 23:49:35 ----D---- C:\Program Files\Avidemux 2.5
2010-08-11 22:50:06 ----D---- C:\Windows\winsxs
2010-08-11 13:15:07 ----RSD---- C:\Windows\assembly
2010-08-11 13:15:07 ----D---- C:\Windows\Microsoft.NET
2010-08-11 13:10:39 ----D---- C:\Windows\system32\migration
2010-08-11 13:10:39 ----D---- C:\Program Files\Internet Explorer
2010-08-11 13:10:38 ----D---- C:\Program Files\Movie Maker
2010-08-11 11:44:25 ----D---- C:\Windows\system32\catroot
2010-08-11 11:44:20 ----D---- C:\Program Files\Windows Mail
2010-08-11 11:42:46 ----D---- C:\Windows\system32\catroot2
2010-08-09 18:37:38 ----D---- C:\Users\Milan\AppData\Roaming\dvdcss
2010-08-09 15:14:14 ----A---- C:\Windows\system32\guard32.dll
2010-08-08 23:29:32 ----D---- C:\Users\Milan\AppData\Roaming\Orbit
2010-08-08 11:53:56 ----D---- C:\ProgramData\Spybot - Search & Destroy
2010-08-07 23:44:20 ----D---- C:\ProgramData
2010-08-07 22:45:19 ----D---- C:\downloads
2010-08-07 09:44:10 ----D---- C:\Temp
2010-08-06 22:33:48 ----D---- C:\Program Files\Mozilla Thunderbird
2010-08-06 01:06:02 ----D---- C:\Program Files\Java
2010-08-05 23:54:30 ----D---- C:\Boot
2010-08-05 12:41:53 ----D---- C:\Windows\security
2010-08-05 09:54:19 ----SD---- C:\Users\Milan\AppData\Roaming\Microsoft
2010-08-04 23:43:58 ----D---- C:\Windows\system32\Msdtc
2010-08-04 23:43:56 ----D---- C:\Windows\system32\wbem
2010-08-04 23:43:49 ----D---- C:\Windows\pss
2010-08-04 23:43:12 ----D---- C:\Windows\system32\config
2010-08-04 23:42:47 ----D---- C:\Windows\PolicyDefinitions
2010-08-04 23:42:43 ----D---- C:\Windows\system32\spool
2010-08-04 23:42:43 ----D---- C:\Windows\system32\CodeIntegrity
2010-08-04 23:42:41 ----D---- C:\Windows\rescache
2010-08-04 23:42:34 ----D---- C:\Users\Milan\AppData\Roaming\TS3Client
2010-08-04 23:42:33 ----D---- C:\Users\Milan\AppData\Roaming\Thunderbird
2010-08-04 23:42:33 ----D---- C:\Users\Milan\AppData\Roaming\RapidGet
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\MakeUpPilot
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\KeePass
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\HLSW
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\Hamachi
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\GHISLER
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\DVD Flick
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\DeepBurner
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\DAEMON Tools
2010-08-04 23:42:32 ----D---- C:\Users\Milan\AppData\Roaming\BeautyPilot
2010-08-04 23:42:27 ----D---- C:\ProgramData\Xfire
2010-08-04 23:42:27 ----D---- C:\ProgramData\Ulead Systems
2010-08-04 23:42:27 ----D---- C:\Program Files\Microsoft Silverlight
2010-08-04 23:42:05 ----D---- C:\Windows\registration
2010-08-04 21:23:37 ----SD---- C:\Windows\Downloaded Program Files
2010-08-04 20:56:53 ----D---- C:\Windows\Minidump
2010-08-04 18:26:38 ----D---- C:\ProgramData\Acronis
2010-08-03 20:09:31 ----A---- C:\Windows\system32\mrt.exe
2010-08-01 18:11:51 ----D---- C:\Program Files\Xfire
2010-07-31 10:22:11 ----D---- C:\Windows\system32\LogFiles
2010-07-30 11:29:20 ----D---- C:\Program Files\CDBurnerXP
2010-07-30 11:25:24 ----D---- C:\Program Files\CCleaner
2010-07-30 11:14:57 ----D---- C:\Users\Milan\AppData\Roaming\Ashampoo
2010-07-30 10:40:20 ----D---- C:\Program Files\QuickTime Alternative
2010-07-26 11:31:38 ----D---- C:\VueScan
2010-07-26 10:24:16 ----D---- C:\Users\Milan\AppData\Roaming\Mozilla
2010-07-23 15:06:04 ----D---- C:\Program Files\FastStone Image Viewer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 hotcore3;hc3ServiceName; C:\Windows\system32\drivers\hotcore3.sys [2010-02-03 40560]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-08-14 691696]
R0 timounter;Acronis True Image Backup Archive Explorer; C:\Windows\system32\DRIVERS\timntr.sys [2010-04-14 441760]
R1 Amfilter;A4Tech Mouse Filter Driver; C:\Windows\system32\DRIVERS\Amfilter.sys [2007-05-15 9216]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2010-06-28 23376]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2010-06-28 165456]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2010-06-28 46672]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2010-08-09 224240]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2010-08-09 30112]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2010-08-09 75944]
R1 Uim_IM;UIM Drive Backup Image Plugin; C:\Windows\System32\Drivers\Uim_IM.sys [2010-02-03 385544]
R1 UimBus;Universal Image Mounter Controller; C:\Windows\system32\DRIVERS\UimBus.sys [2010-02-03 34392]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2008-02-12 232472]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2010-06-28 17744]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2010-06-28 50256]
R2 CX23880;WinFast CX2388x WDM Video Capture.; C:\Windows\system32\drivers\cx88vid.sys [2006-10-18 162944]
R2 CXAVXBAR;WinFast CX2388x WDM Crossbar.; C:\Windows\system32\drivers\cxavxbar.sys [2006-10-18 9728]
R2 CXTUNE;Conexant 2388x Tuner; C:\Windows\system32\drivers\CX88TUNE_IBV32.sys [2006-11-02 17664]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2008-01-21 95744]
R2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2007-08-13 5120]
R2 tifsfilter;Acronis True Image FS Filter; C:\Windows\system32\DRIVERS\tifsfilt.sys [2010-04-14 44384]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-05-27 5550592]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-05-27 176128]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller; C:\Windows\system32\DRIVERS\l160x86.sys [2007-10-31 46592]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-03-09 104464]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-05-10 1775712]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2006-10-18 7680]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2008-02-05 59960]
R3 VRVD302;VRVD302; C:\Windows\system32\DRIVERS\VRVD302.sys [2008-08-31 11296]
S2 DgiVecp;DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [2007-08-13 41984]
S3 a93vb3lf;a93vb3lf; C:\Windows\system32\drivers\a93vb3lf.sys []
S3 ae649d18;ae649d18; C:\Windows\system32\drivers\ae649d18.sys []
S3 Amusbprt;A4Tech HID-compliant Mouse Driver; C:\Windows\system32\DRIVERS\Amusbprt.sys [2007-05-15 14336]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-05-27 5550592]
S3 CrystalSysInfo;CrystalSysInfo; \??\e:\Program Files\MediaCoder\SysInfo.sys []
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 ENTECH;ENTECH; \??\C:\Windows\system32\DRIVERS\ENTECH.sys [2008-05-29 27672]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2008-11-11 25280]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 PSI;PSI; C:\Windows\system32\DRIVERS\psi_mf.sys [2009-06-17 12648]
S3 pwdrvio;pwdrvio; \??\C:\Windows\system32\pwdrvio.sys [2009-12-21 16456]
S3 pwdspio;pwdspio; \??\C:\Windows\system32\pwdspio.sys [2009-12-21 11088]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2009-11-12 7168]
S3 STIrUsb;SigmaTel USB-IrDA Dongle; C:\Windows\system32\DRIVERS\irstusb.sys [2008-01-21 30208]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-04-11 15872]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 WINUSB;Ovladač WinUsb; C:\Windows\system32\DRIVERS\WinUSB.SYS [2009-04-11 31616]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2008-07-03 109056]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-05-27 172032]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-08-09 1778480]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 NMSAccess;NMSAccess; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2010-03-04 71096]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-03-03 75064]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 TuneUp.ProgramStatisticsSvc;@%SystemRoot%\System32\TUProgSt.exe,-1; C:\Windows\System32\TUProgSt.exe [2010-08-07 604488]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-12-13 49152]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
S2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe []
S2 gupdate1c9de051e6229f3;Google Update Service (gupdate1c9de051e6229f3); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-05-26 133104]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-03-30 31048]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 TuneUp.Defrag;@%SystemRoot%\System32\TuneUpDefragService.exe,-1; C:\Windows\System32\TuneUpDefragService.exe [2010-08-07 361288]
-----------------EOF-----------------
Re: Prosím o kontrolu po opravě a čištění

Kód: Vybrat vše
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=-
klikněte na uložit, pak na soubor standardně 2X klikněte a potvrďte dialogové okno.

C:\Windows\VcncDll.INI
Jsou s pc nějaké problémy?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu po opravě a čištění
Ahoj. PC nezlobí, chtěl raději kontrolu jestli se něco nevrátilo.
Provedl jsem vše. To s těma registrama jsme už dělali, co to je? A ten soubor s windows?
Dík za kontrolu.
Provedl jsem vše. To s těma registrama jsme už dělali, co to je? A ten soubor s windows?
Dík za kontrolu.
Re: Prosím o kontrolu po opravě a čištění
To byl prázdný klíč v registru a soubor neznám, byl zbytečný.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.