Stránka 3 z 7

Re: Motji: Prosím o kontrolu logu

Napsal: 04 kvě 2011 18:32
od PATWIST
Mal som 63 % a vtedy mi Windows oznámil to čo som už dlho nevidel že aktualizácie po reštarte. Tak som chcel reštartovať. Tak som vypol program ale predtým ako som klikol na koniec som klikol na Zastaviť kontrolu :( . A aktualizácie stále nejdu.
Dnes tu budem ale potom až 08.04.2011. Ide to rýchlo - zrejme preto lebo to už niečo zmazalo :)
19:30 1%
19:50 5%
20:20 30%
20:26 40%
20:40 57%
20:42 62%
22:00 85 %

Re: Motji: Prosím o kontrolu logu

Napsal: 04 kvě 2011 19:42
od motji
Spíš pomalu :D , vydržte, jak dojede, spustíte znovu combouše a uvidíme :)

Re: Motji: Prosím o kontrolu logu

Napsal: 04 kvě 2011 21:55
od PATWIST
Na 86% som si všimol že to skenuje aj J:\ teda Externý harddisk tak som ho odpojil a :o no proste zas by som začínal na 1% :oops:

LOG S COMBOFIX (po AVP):

ComboFix 11-05-04.02 - PATOWIST . 05. 2011 22:43:05.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1023.433 [GMT 2:00]
Spuštěný z: c:\documents and settings\PATOWIST\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\PATOWIST\Local Settings\Temporary Internet Files\10506bbe
c:\documents and settings\PATOWIST\Local Settings\Temporary Internet Files\8889633f
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-04 do 2011-05-04 )))))))))))))))))))))))))))))))
.
.
2011-05-03 21:10 . 2011-05-03 21:10 -------- d-----w- c:\program files\Speccy
2011-05-03 20:55 . 2009-10-22 11:54 37392 ----a-w- c:\windows\system32\drivers\87329312.sys
2011-05-03 20:55 . 2009-10-09 21:31 315408 ----a-w- c:\windows\system32\drivers\8732931.sys
2011-05-03 20:55 . 2009-09-25 15:59 128016 ----a-w- c:\windows\system32\drivers\87329311.sys
2011-05-03 19:27 . 2011-05-03 19:27 -------- d-----w- C:\_OTL
2011-05-03 17:45 . 2011-05-03 18:41 512 ----a-w- C:\PhysicalMBR.bin
2011-05-02 17:47 . 2011-05-02 17:48 -------- d-----w- c:\documents and settings\PATOWIST\Data aplikací\TS3Client
2011-04-27 18:58 . 2011-04-18 17:17 307288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-04-27 18:58 . 2011-04-18 17:12 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-04-27 18:58 . 2011-04-18 17:17 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-04-27 18:58 . 2011-04-18 17:16 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-04-27 18:58 . 2011-04-18 17:13 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-04-27 18:58 . 2011-04-18 17:16 102488 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-04-27 18:58 . 2011-04-18 17:16 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-04-27 18:58 . 2011-04-18 17:13 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-04-27 18:57 . 2011-04-18 17:25 40112 ----a-w- c:\windows\avastSS.scr
2011-04-27 18:57 . 2011-04-18 17:25 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-04-27 18:56 . 2011-04-27 18:56 -------- d-----w- c:\program files\AVAST Software
2011-04-27 18:56 . 2011-04-27 18:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2011-04-17 23:11 . 2011-04-17 23:11 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-04-17 21:59 . 2011-04-17 21:59 -------- d-----w- c:\documents and settings\PATOWIST\Local Settings\Data aplikací\Sunbelt Software
2011-04-17 21:55 . 2011-04-17 21:55 -------- dc-h--w- c:\documents and settings\All Users\Data aplikací\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2011-04-17 01:43 . 2011-04-27 19:37 -------- d-sh--r- c:\windows\system32\rpcnetp
2011-04-15 15:41 . 2011-04-15 15:41 -------- d-----w- c:\documents and settings\All Users\Data aplikací\regid.1986-12.com.adobe
2011-04-15 15:33 . 2011-04-15 15:33 -------- d-----w- c:\program files\Adobe Media Player
2011-04-15 14:19 . 2011-04-15 14:19 -------- d-----w- c:\documents and settings\All Users\Data aplikací\HP Product Assistant
2011-04-15 14:16 . 2011-04-15 14:20 -------- d-----w- c:\program files\HP
2011-04-14 23:37 . 2011-04-15 00:08 -------- d-----w- c:\documents and settings\PATOWIST\Data aplikací\MyPhoneExplorer
2011-04-14 15:34 . 2010-02-04 08:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2011-04-14 15:34 . 2010-02-04 08:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2011-04-14 15:34 . 2010-02-04 08:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2011-04-14 15:34 . 2010-02-04 08:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2011-04-14 15:30 . 2011-04-14 15:30 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2011-04-14 15:30 . 2011-04-14 15:30 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2011-04-14 15:30 . 2011-04-14 15:30 -------- d-----w- c:\program files\OpenAL
2011-04-14 14:10 . 2011-04-15 15:11 7 ----a-w- c:\windows\treeskp.sys
2011-04-14 14:10 . 2011-04-15 15:11 7 ----a-w- c:\windows\sbacknt.bin
2011-04-14 13:10 . 2011-04-14 13:10 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Avanquest
2011-04-14 13:10 . 2011-04-14 13:10 -------- d-----w- c:\documents and settings\All Users\Data aplikací\BVRP Software
2011-04-14 01:14 . 2011-04-17 12:55 253112 ----a-w- c:\windows\system32\nvdrsdb0.bin
2011-04-14 01:14 . 2011-04-17 12:55 1 ----a-w- c:\windows\system32\nvdrssel.bin
2011-04-14 01:14 . 2011-04-17 12:55 253104 ----a-w- c:\windows\system32\nvdrsdb1.bin
2011-04-14 01:14 . 2011-01-08 03:27 941160 ----a-w- c:\windows\system32\nvdispco322090.dll
2011-04-14 01:14 . 2011-01-08 03:27 837736 ----a-w- c:\windows\system32\nvgenco322040.dll
2011-04-14 01:14 . 2011-01-08 03:27 61440 ----a-w- c:\windows\system32\OpenCL.dll
2011-04-14 01:14 . 2011-01-08 03:27 13004800 ----a-w- c:\windows\system32\nvcompiler.dll
2011-04-13 23:02 . 2011-04-13 23:02 -------- d-----w- c:\documents and settings\PATOWIST\Data aplikací\Chirurgie Simulation
2011-04-13 10:20 . 2011-03-16 13:34 2634240 ----a-w- c:\program files\Mozilla Firefox\extensions\{12d2b889-7ccb-0af6-4126-806f13689ed0}\components\71460a96.dll
2011-04-12 15:06 . 2011-04-17 16:15 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype Extras
2011-04-12 14:57 . 2011-04-12 14:57 -------- d-----w- c:\program files\Common Files\Skype
2011-04-12 14:56 . 2011-04-12 14:57 -------- d-----r- c:\program files\Skype
2011-04-12 14:44 . 2011-04-17 21:12 -------- d-----w- c:\documents and settings\PATOWIST\Data aplikací\ICQ
2011-04-12 14:44 . 2011-04-12 15:29 -------- d-----w- c:\program files\ICQ7.4
2011-04-12 14:22 . 2011-04-12 14:22 -------- d-----w- c:\program files\Opera
2011-04-11 13:03 . 2011-04-11 13:03 -------- d-----w- c:\documents and settings\All Users\Uniblue
2011-04-11 10:27 . 2011-04-11 10:27 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\Hagel Technologies
2011-04-10 20:50 . 2011-04-10 23:12 -------- d-----w- c:\documents and settings\PATOWIST\Local Settings\Data aplikací\NFS Underground 2
2011-04-10 19:44 . 2011-04-10 19:44 -------- d-----w- c:\documents and settings\PATOWIST\Local Settings\Data aplikací\Electronic_Arts_Inc
2011-04-10 18:57 . 2011-02-02 19:40 472808 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-04-10 18:57 . 2011-02-02 19:40 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-04-09 20:41 . 2011-04-09 20:49 -------- d-----w- c:\documents and settings\PATOWIST\Data aplikací\Mp3tag
2011-04-08 17:28 . 2011-04-08 17:28 -------- d-----w- c:\documents and settings\NetworkService\Data aplikací\TuneUp Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-17 23:11 . 2009-09-16 17:06 15880 ----a-w- c:\windows\system32\lsdelete.exe
2011-03-26 14:09 . 2011-03-26 14:09 1409 ----a-w- c:\windows\QTFont.for
2011-03-04 15:32 . 2011-03-29 19:24 31552 ----a-w- c:\windows\system32\TURegOpt.exe
2011-03-04 15:28 . 2011-03-29 19:24 29504 ----a-w- c:\windows\system32\uxtuneup.dll
2011-02-17 17:06 . 2011-03-22 21:01 160560 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2011-02-17 17:06 . 2011-03-22 21:00 44784 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2011-02-17 17:06 . 2011-02-17 17:06 122032 ----a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
2011-02-17 17:06 . 2011-02-17 17:06 135472 ----a-w- c:\windows\system32\VBoxNetFltNotify.dll
2005-10-07 17:14 308224 --sha-r- c:\windows\system32\avisynth.dll
2005-07-14 10:31 27648 --sha-r- c:\windows\system32\AVSredirect.dll
2005-06-26 13:32 616448 --sha-r- c:\windows\system32\cygwin1.dll
2005-06-21 20:37 45568 --sha-r- c:\windows\system32\cygz.dll
2005-12-22 18:23 816640 --sha-r- c:\windows\system32\smab.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-05-03_19.15.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-04 20:29 . 2011-05-04 20:29 16384 c:\windows\Temp\Perflib_Perfdata_294.dat
- 2011-03-24 18:04 . 2011-04-16 12:07 35088 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
+ 2011-03-24 18:04 . 2011-05-04 17:23 35088 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
+ 2011-03-24 18:04 . 2011-05-04 17:23 18704 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\mspicons.exe
- 2011-03-24 18:04 . 2011-04-16 12:07 18704 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\mspicons.exe
- 2011-03-24 18:04 . 2011-04-16 12:07 20240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\cagicon.exe
+ 2011-03-24 18:04 . 2011-05-04 17:23 20240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\cagicon.exe
+ 2011-05-03 19:45 . 2011-05-03 19:45 10576 c:\windows\assembly\GAC\Policy.11.0.office\12.0.0.0__71e9bce111e9429c\Policy.11.0.Office.dll
+ 2011-05-03 19:45 . 2011-05-03 19:45 11112 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Vbe.Interop.dll
+ 2011-05-03 19:45 . 2011-05-03 19:45 11128 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll
+ 2011-05-03 19:45 . 2011-05-03 19:45 11136 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll
+ 2011-05-03 19:45 . 2011-05-03 19:45 11152 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll
+ 2011-05-03 19:45 . 2011-05-03 19:45 11128 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Graph.dll
+ 2011-05-03 19:45 . 2011-05-03 19:45 11144 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Excel.dll
+ 2011-05-03 19:45 . 2011-05-03 19:45 63336 c:\windows\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2011-05-03 19:45 . 2011-05-03 19:45 19320 c:\windows\assembly\GAC\Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
+ 2011-05-03 21:10 . 2011-05-03 21:10 5120 c:\windows\Installer\{789289CA-F73A-4A16-A331-54D498CE069F}\Icon789289CA.exe
- 2011-04-15 22:11 . 2011-04-15 22:11 5120 c:\windows\Installer\{789289CA-F73A-4A16-A331-54D498CE069F}\Icon789289CA.exe
+ 2010-08-04 13:13 . 2010-08-04 13:13 686080 c:\windows\Installer\e77a46.msp
+ 2009-05-26 16:53 . 2009-05-26 16:53 579072 c:\windows\Installer\e77945.msp
+ 2010-07-22 23:03 . 2010-07-22 23:03 338432 c:\windows\Installer\e77903.msp
+ 2009-04-04 15:14 . 2009-04-04 15:14 971776 c:\windows\Installer\7ccd7.msp
+ 2011-03-24 18:04 . 2011-05-04 17:23 888080 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
- 2011-03-24 18:04 . 2011-04-16 12:07 888080 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
+ 2011-03-24 18:04 . 2011-05-04 17:23 272648 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pubs.exe
- 2011-03-24 18:04 . 2011-04-16 12:07 272648 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pubs.exe
+ 2011-03-24 18:04 . 2011-05-04 17:23 922384 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pptico.exe
- 2011-03-24 18:04 . 2011-04-16 12:07 922384 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pptico.exe
+ 2011-03-24 18:04 . 2011-05-04 17:23 845584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
- 2011-03-24 18:04 . 2011-04-16 12:07 845584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
+ 2011-03-24 18:04 . 2011-05-04 17:23 217864 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\misc.exe
- 2011-03-24 18:04 . 2011-04-16 12:07 217864 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\misc.exe
+ 2011-03-24 18:04 . 2011-05-04 17:23 159504 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\inficon.exe
- 2011-03-24 18:04 . 2011-04-16 12:07 159504 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\inficon.exe
+ 2011-05-03 19:45 . 2011-05-03 19:45 609160 c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll
+ 2011-05-04 17:16 . 2011-05-04 17:16 117144 c:\windows\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
+ 2011-05-03 19:45 . 2011-05-03 19:45 423784 c:\windows\assembly\GAC\office\12.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2011-05-03 19:45 . 2011-05-03 19:45 870256 c:\windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
+ 2011-05-04 17:18 . 2011-05-04 17:18 350064 c:\windows\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2011-05-03 19:45 . 2011-05-03 19:45 149352 c:\windows\assembly\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
+ 2009-08-17 21:33 . 2009-08-17 21:33 1193832 c:\windows\system32\FM20.DLL
+ 2011-01-11 15:49 . 2011-01-11 15:49 9003008 c:\windows\Installer\e77a91.msp
+ 2010-10-21 16:10 . 2010-10-21 16:10 3995136 c:\windows\Installer\e77a7b.msp
+ 2010-08-13 16:02 . 2010-08-13 16:02 2545664 c:\windows\Installer\e77a5c.msp
+ 2010-08-13 16:00 . 2010-08-13 16:00 9404928 c:\windows\Installer\e77a2f.msp
+ 2010-11-20 21:32 . 2010-11-20 21:32 4165120 c:\windows\Installer\e77a17.msp
+ 2009-08-05 05:49 . 2009-08-05 05:49 3457024 c:\windows\Installer\e779ff.msp
+ 2010-03-24 16:54 . 2010-03-24 16:54 3126272 c:\windows\Installer\e779e6.msp
+ 2010-03-24 16:54 . 2010-03-24 16:54 2516992 c:\windows\Installer\e779e5.msp
+ 2009-07-27 02:31 . 2009-07-27 02:31 3738624 c:\windows\Installer\e779ca.msp
+ 2011-03-17 18:01 . 2011-03-17 18:01 9563648 c:\windows\Installer\e779b4.msp
+ 2010-05-20 17:57 . 2010-05-20 17:57 4989952 c:\windows\Installer\e7797b.msp
+ 2010-05-20 17:57 . 2010-05-20 17:57 5907456 c:\windows\Installer\e7797a.msp
+ 2009-10-16 05:08 . 2009-10-16 05:08 2237952 c:\windows\Installer\e7795b.msp
+ 2011-01-11 15:50 . 2011-01-11 15:50 8177152 c:\windows\Installer\e7792f.msp
+ 2009-08-18 11:08 . 2009-08-18 11:08 1373696 c:\windows\Installer\e77919.msp
+ 2010-11-20 21:33 . 2010-11-20 21:33 1980928 c:\windows\Installer\e778ed.msp
+ 2009-04-04 15:10 . 2009-04-04 15:10 2439680 c:\windows\Installer\7cccf.msp
+ 2009-04-04 15:10 . 2009-04-04 15:10 9926144 c:\windows\Installer\7ccc5.msp
+ 2009-04-04 15:09 . 2009-04-04 15:09 2364928 c:\windows\Installer\7ccad.msp
+ 2011-03-24 18:04 . 2011-05-04 17:23 1172240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
- 2011-03-24 18:04 . 2011-04-16 12:07 1172240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
- 2011-03-24 18:04 . 2011-04-16 12:07 1165584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
+ 2011-03-24 18:04 . 2011-05-04 17:23 1165584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
+ 2011-05-03 19:45 . 2011-05-03 19:45 1279848 c:\windows\assembly\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
+ 2010-12-21 11:06 . 2010-12-21 11:06 11570688 c:\windows\Installer\e7799e.msp
+ 2010-07-22 23:04 . 2010-07-22 23:04 11395072 c:\windows\Installer\e778d6.msp
+ 2009-04-04 15:09 . 2009-04-04 15:09 10874880 c:\windows\Installer\7ccb9.msp
+ 2009-04-04 15:08 . 2009-04-04 15:08 343058432 c:\windows\Installer\7cca4.msp
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-04-18 17:25 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sony Ericsson PC Companion"="c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" [2011-02-28 427008]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-04 16120832]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2011-04-17 928496]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-01-07 111208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-01-07 13880424]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-11-04 1753192]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-04-18 3460784]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
"Nokia.PCSync"="d:\programy\Nokia PC Suite\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
.
c:\documents and settings\PATOWIST\Nabˇdka Start\Programy\Po spuçtŘnˇ\
setup_9.0.0.722_03.05.2011_23-34.lnk - d:\programy\Virus Removal Tool\setup_9.0.0.722_03.05.2011_23-34\startup.exe [2011-5-3 72208]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 11 (0xb)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\RAinit]
2008-07-03 13:12 58704 ----a-w- c:\windows\system32\RAinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-12-15 20:07 1242448 ----a-w- d:\programy\Steam\steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mnmsrvc"=3 (0x3)
"Abel"=2 (0x2)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Steam"=d:\programy\Steam\steam.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"ICQ"="c:\program files\ICQ7.4\ICQ.exe" silent loginmode=4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"nwiz"=c:\program files\NVIDIA Corporation\nView\nwiz.exe /install
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"VMonitorVMUVC"="c:\program files\Vimicro Corporation\VMUVC\VMonitor.exe" VMUVC
"sdodcoectjloen"=c:\windows\System32\regsvr32.exe /s "c:\windows\system32\bjdooocacko.dll"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"SwitchBoard"=c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"qeykvoic¨"=c:\windows\System32\qeykvoic¨.exe
"PCSuiteTrayApplication"=d:\programy\Nokia PC Suite\Nokia PC Suite 6\LaunchApplication.exe -startup
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"d:\\Programy\\Steam\\steamapps\\patwist\\condition zero\\hl.exe"=
"d:\\Programy\\Steam\\Steam.exe"=
"d:\\Programy\\Steam\\steamapps\\patwist\\dedicated server\\hlds.exe"=
"d:\\Programy\\Steam\\steamapps\\patwist\\dedicated server\\hltv.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Java\\jre1.6.0_01\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"d:\\Programy\\totalcmd\\TOTALCMD.EXE"=
"d:\\Games\\Counter Strike 1.6 Non Steam\\hl.exe"=
"d:\\Games\\Counter Strike 1.6 Non Steam\\hlds.exe"=
"d:\\Games\\Counter Strike 1.6 Non Steam\\cstrike.exe"=
"d:\\Games\\stahujem\\OTHERS\\HTML\\Prizee\\Prizee Offline\\serwer_prizee.exe"=
"d:\\Games\\stahujem\\OTHERS\\HTML\\Prizee\\Prizee Offline\\http_prizee.exe"=
"d:\\Games\\Counter Strike 1.6 Non Steam\\hltv.exe"=
"d:\\Programy\\uTorrent\\utorrent.exe"=
"d:\\Programy\\Phone Remote Control\\PhoneRemoteControl.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"d:\\Games\\stahujem\\hack\\Ovladanie PC\\Net Control\\Osa9.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\InterVideo\\DVD8\\WinDVD.exe"=
"d:\\Programy\\Unified Remote\\UnifiedRemoteServer.exe"=
"d:\\Games\\stahujem\\hack\\realhack\\aa\\DoS attack by marsmela - posterus.cz DOWN programs\\SuperScan.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\ICQ7.4\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Programy\\MyPhoneExplorer\\MyPhoneExplorer.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"d:\\Games\\stahujem\\Software\\Tlaciaren\\setup\\hpznui01.exe"=
"d:\\Programy\\Steam\\steamapps\\patwist\\counter-strike\\hl.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:Remote Desktop
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
.
R0 87329312;87329312 Boot Guard Driver;c:\windows\system32\drivers\87329312.sys [3. 5. 2011 22:55 37392]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [16. 9. 2009 16:43 64288]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5. 1. 2009 10:32 717296]
R1 87329311;87329311;c:\windows\system32\drivers\87329311.sys [3. 5. 2011 22:55 128016]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [27. 4. 2011 20:58 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [27. 4. 2011 20:58 307288]
R1 setup_9.0.0.722_03.05.2011_23-34drv;setup_9.0.0.722_03.05.2011_23-34drv;c:\windows\system32\drivers\8732931.sys [3. 5. 2011 22:55 315408]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [27. 4. 2011 20:58 19544]
R2 RARfsDriver;RemotelyAnywhere Remote File System Driver;c:\windows\system32\drivers\RARfsDriver.sys [8. 10. 2008 23:07 46000]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [4. 3. 2011 17:30 1523008]
R3 ramirr;ramirr;c:\windows\system32\drivers\ramirr.sys [17. 4. 2007 14:00 10168]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [17. 2. 2011 19:06 122032]
R3 VMUVC;Vimicro Camera Service VMUVC;c:\windows\system32\drivers\VMUVC.sys [21. 12. 2010 23:58 256512]
R3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\windows\system32\drivers\vvftUVC.sys [21. 12. 2010 23:58 398720]
R3 xcpip;Ovladač protokolu TCP/IP;c:\windows\system32\drivers\xcpip.sys --> c:\windows\system32\drivers\xcpip.sys [?]
R3 xpsec;Ovladač IPSEC;c:\windows\system32\drivers\xpsec.sys --> c:\windows\system32\drivers\xpsec.sys [?]
S0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [27. 10. 2007 12:18 155136]
S0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [27. 10. 2007 12:18 5248]
S2 gupdate1c9feeb4d770e2c;Služba Google Update (gupdate1c9feeb4d770e2c);c:\program files\Google\Update\GoogleUpdate.exe [2. 2. 2011 21:23 136176]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12. 8. 2010 14:15 1378040]
S2 NetControl2.AdminHelper;Net Control 2 Administrator. Helper Service.;d:\programy\Hack\Net Control 2\ahs.exe --> d:\programy\Hack\Net Control 2\ahs.exe [?]
S2 RAInfo;RemotelyAnywhere Kernel Information Provider;\??\d:\programy\RemotelyAnywhere\x86\RaInfo.sys --> d:\programy\RemotelyAnywhere\x86\RaInfo.sys [?]
S3 BTCAMDRV;Mobiola Web Camera driver;c:\windows\system32\drivers\BTCamDrv.sys [26. 1. 2008 0:25 219264]
S3 cpuz;cpuz;\??\c:\docume~1\patwistt\LOCALS~1\Temp\cpuz.sys --> c:\docume~1\patwistt\LOCALS~1\Temp\cpuz.sys [?]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [15. 12. 2010 18:31 13224]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2. 2. 2011 21:23 136176]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [12. 8. 2010 14:15 15264]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;"c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe" --> c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [?]
S3 ncvhook;ncvhook;c:\windows\system32\drivers\ncvhook.sys [1. 9. 2009 21:52 6896]
S3 ntportio;ntportio;\??\c:\docume~1\PATOWIST\LOCALS~1\Temp\u\1267129103\ntportio.sys --> c:\docume~1\PATOWIST\LOCALS~1\Temp\u\1267129103\ntportio.sys [?]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [15. 12. 2010 18:25 150528]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19. 2. 2010 13:37 517096]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [10. 2. 2011 10:22 10064]
S4 RARfsClientNP;RARfsClientNP; [x]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
.
2011-05-04 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-08-12 23:11]
.
2011-04-18 c:\windows\Tasks\AdobeAAMUpdater-1.0-PATWIST-PATOWIST.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-04-15 15:24]
.
2011-05-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-02 19:23]
.
2011-05-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-02 19:23]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.sk/
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe
FF - ProfilePath - c:\documents and settings\PATOWIST\Data aplikací\Mozilla\Firefox\Profiles\f9ppzm5s.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.sk
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: z: {12d2b889-7ccb-0af6-4126-806f13689ed0} - c:\program files\Mozilla Firefox\extensions\{12d2b889-7ccb-0af6-4126-806f13689ed0}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\DivX\DivX Plus Web Player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files\DivX\DivX Plus Web Player\firefox\wpa
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Easy Youtube Video Downloader: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b} - %profile%\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: TinEye Reverse Image Search: tineye@ideeinc.com - %profile%\extensions\tineye@ideeinc.com
FF - Ext: ReloadEvery: {888d99e7-e8b5-46a3-851e-1ec45da1e644} - %profile%\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-04 22:50
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-220523388-776561741-839522115-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(984)
c:\windows\system32\RAinit.dll
c:\windows\system32\RARfsClientNP.dll
.
Celkový čas: 2011-05-04 22:53:04
ComboFix-quarantined-files.txt 2011-05-04 20:53
ComboFix2.txt 2011-05-03 20:21
ComboFix3.txt 2011-05-03 19:20
.
Před spuštěním: 1 149 546 496
Po spuštění: 1 106 386 944
.
- - End Of File - - 324E161A36444DE03ADDA9D4F684608E

Re: Motji: Prosím o kontrolu logu

Napsal: 05 kvě 2011 05:49
od motji
:arrow: Pokud nemáte, přesuňte Combofix na plochu
-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka

Kód: Vybrat vše

KillAll::

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"=-
"52344:TCP"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"sdodcoectjloen"=-
"qeykvoic¨"=-
"DivXUpdate"=-

Driver::
SetupNTGLM7X
ntportio

File::
e:\ntglm7x.sys
c:\docume~1\PATOWIST\LOCALS~1\Temp\u\1267129103\ntportio.sys 

Collect::
c:\windows\System32\qeykvoic¨.exe
c:\windows\system32\bjdooocacko.dll

-uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

Obrázek


-po aplikaci na Vás vypadne další log,vložte ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci

Re: Motji: Prosím o kontrolu logu

Napsal: 08 kvě 2011 16:40
od PATWIST
Dobrý deň, ešte skúsim spraviť aj ten AVP sken (34%), v šimol som si že tam ako na konci logu je Před spuštěním a Po spuštění tak to kleslo z približne 1 100 000 na 910 000 000.

LOG S COMBOFIX:

ComboFix 11-05-07.02 - PATOWIST . 05. 2011 17:19:01.4.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1023.410 [GMT 2:00]
Spuštěný z: c:\documents and settings\PATOWIST\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\PATOWIST\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
FILE ::
"c:\docume~1\PATOWIST\LOCALS~1\Temp\u\1267129103\ntportio.sys"
"e:\ntglm7x.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\PATOWIST\Local Settings\Temporary Internet Files\10506bbe
c:\documents and settings\PATOWIST\Local Settings\Temporary Internet Files\8889633f
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_SETUPNTGLM7X
-------\Service_ntportio
-------\Service_SetupNTGLM7X
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-08 do 2011-05-08 )))))))))))))))))))))))))))))))
.
.
2011-05-03 21:10 . 2011-05-03 21:10 -------- d-----w- c:\program files\Speccy
2011-05-03 20:55 . 2009-10-22 11:54 37392 ----a-w- c:\windows\system32\drivers\87329312.sys
2011-05-03 20:55 . 2009-10-09 21:31 315408 ----a-w- c:\windows\system32\drivers\8732931.sys
2011-05-03 20:55 . 2009-09-25 15:59 128016 ----a-w- c:\windows\system32\drivers\87329311.sys
2011-05-03 19:27 . 2011-05-03 19:27 -------- d-----w- C:\_OTL
2011-05-03 17:45 . 2011-05-03 18:41 512 ----a-w- C:\PhysicalMBR.bin
2011-05-02 17:47 . 2011-05-02 17:48 -------- d-----w- c:\documents and settings\PATOWIST\Data aplikací\TS3Client
2011-04-27 18:58 . 2011-04-18 17:17 307288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-04-27 18:58 . 2011-04-18 17:12 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-04-27 18:58 . 2011-04-18 17:17 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-04-27 18:58 . 2011-04-18 17:16 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-04-27 18:58 . 2011-04-18 17:13 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-04-27 18:58 . 2011-04-18 17:16 102488 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-04-27 18:58 . 2011-04-18 17:16 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-04-27 18:58 . 2011-04-18 17:13 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-04-27 18:57 . 2011-04-18 17:25 40112 ----a-w- c:\windows\avastSS.scr
2011-04-27 18:57 . 2011-04-18 17:25 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-04-27 18:56 . 2011-04-27 18:56 -------- d-----w- c:\program files\AVAST Software
2011-04-27 18:56 . 2011-04-27 18:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2011-04-17 23:11 . 2011-04-17 23:11 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-04-17 21:59 . 2011-04-17 21:59 -------- d-----w- c:\documents and settings\PATOWIST\Local Settings\Data aplikací\Sunbelt Software
2011-04-17 21:55 . 2011-04-17 21:55 -------- dc-h--w- c:\documents and settings\All Users\Data aplikací\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2011-04-17 01:43 . 2011-04-27 19:37 -------- d-sh--r- c:\windows\system32\rpcnetp
2011-04-15 15:41 . 2011-04-15 15:41 -------- d-----w- c:\documents and settings\All Users\Data aplikací\regid.1986-12.com.adobe
2011-04-15 15:33 . 2011-04-15 15:33 -------- d-----w- c:\program files\Adobe Media Player
2011-04-15 14:19 . 2011-04-15 14:19 -------- d-----w- c:\documents and settings\All Users\Data aplikací\HP Product Assistant
2011-04-15 14:16 . 2011-04-15 14:20 -------- d-----w- c:\program files\HP
2011-04-14 23:37 . 2011-04-15 00:08 -------- d-----w- c:\documents and settings\PATOWIST\Data aplikací\MyPhoneExplorer
2011-04-14 15:34 . 2010-02-04 08:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2011-04-14 15:34 . 2010-02-04 08:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2011-04-14 15:34 . 2010-02-04 08:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2011-04-14 15:34 . 2010-02-04 08:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2011-04-14 15:30 . 2011-04-14 15:30 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2011-04-14 15:30 . 2011-04-14 15:30 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2011-04-14 15:30 . 2011-04-14 15:30 -------- d-----w- c:\program files\OpenAL
2011-04-14 14:10 . 2011-04-15 15:11 7 ----a-w- c:\windows\treeskp.sys
2011-04-14 14:10 . 2011-04-15 15:11 7 ----a-w- c:\windows\sbacknt.bin
2011-04-14 13:10 . 2011-04-14 13:10 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Avanquest
2011-04-14 13:10 . 2011-04-14 13:10 -------- d-----w- c:\documents and settings\All Users\Data aplikací\BVRP Software
2011-04-14 01:14 . 2011-04-17 12:55 253112 ----a-w- c:\windows\system32\nvdrsdb0.bin
2011-04-14 01:14 . 2011-04-17 12:55 1 ----a-w- c:\windows\system32\nvdrssel.bin
2011-04-14 01:14 . 2011-04-17 12:55 253104 ----a-w- c:\windows\system32\nvdrsdb1.bin
2011-04-14 01:14 . 2011-01-08 03:27 941160 ----a-w- c:\windows\system32\nvdispco322090.dll
2011-04-14 01:14 . 2011-01-08 03:27 837736 ----a-w- c:\windows\system32\nvgenco322040.dll
2011-04-14 01:14 . 2011-01-08 03:27 61440 ----a-w- c:\windows\system32\OpenCL.dll
2011-04-14 01:14 . 2011-01-08 03:27 13004800 ----a-w- c:\windows\system32\nvcompiler.dll
2011-04-13 23:02 . 2011-04-13 23:02 -------- d-----w- c:\documents and settings\PATOWIST\Data aplikací\Chirurgie Simulation
2011-04-13 10:20 . 2011-03-16 13:34 2634240 ----a-w- c:\program files\Mozilla Firefox\extensions\{12d2b889-7ccb-0af6-4126-806f13689ed0}\components\71460a96.dll
2011-04-12 15:06 . 2011-04-17 16:15 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype Extras
2011-04-12 14:57 . 2011-04-12 14:57 -------- d-----w- c:\program files\Common Files\Skype
2011-04-12 14:56 . 2011-04-12 14:57 -------- d-----r- c:\program files\Skype
2011-04-12 14:44 . 2011-04-17 21:12 -------- d-----w- c:\documents and settings\PATOWIST\Data aplikací\ICQ
2011-04-12 14:44 . 2011-04-12 15:29 -------- d-----w- c:\program files\ICQ7.4
2011-04-12 14:22 . 2011-04-12 14:22 -------- d-----w- c:\program files\Opera
2011-04-11 13:03 . 2011-04-11 13:03 -------- d-----w- c:\documents and settings\All Users\Uniblue
2011-04-11 10:27 . 2011-04-11 10:27 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\Hagel Technologies
2011-04-10 20:50 . 2011-04-10 23:12 -------- d-----w- c:\documents and settings\PATOWIST\Local Settings\Data aplikací\NFS Underground 2
2011-04-10 19:44 . 2011-04-10 19:44 -------- d-----w- c:\documents and settings\PATOWIST\Local Settings\Data aplikací\Electronic_Arts_Inc
2011-04-10 18:57 . 2011-02-02 19:40 472808 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-04-10 18:57 . 2011-02-02 19:40 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-04-09 20:41 . 2011-04-09 20:49 -------- d-----w- c:\documents and settings\PATOWIST\Data aplikací\Mp3tag
2011-04-08 17:28 . 2011-04-08 17:28 -------- d-----w- c:\documents and settings\NetworkService\Data aplikací\TuneUp Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-17 23:11 . 2009-09-16 17:06 15880 ----a-w- c:\windows\system32\lsdelete.exe
2011-03-26 14:09 . 2011-03-26 14:09 1409 ----a-w- c:\windows\QTFont.for
2011-03-04 15:32 . 2011-03-29 19:24 31552 ----a-w- c:\windows\system32\TURegOpt.exe
2011-03-04 15:28 . 2011-03-29 19:24 29504 ----a-w- c:\windows\system32\uxtuneup.dll
2011-02-17 17:06 . 2011-03-22 21:01 160560 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2011-02-17 17:06 . 2011-03-22 21:00 44784 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2011-02-17 17:06 . 2011-02-17 17:06 122032 ----a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
2011-02-17 17:06 . 2011-02-17 17:06 135472 ----a-w- c:\windows\system32\VBoxNetFltNotify.dll
2005-10-07 17:14 308224 --sha-r- c:\windows\system32\avisynth.dll
2005-07-14 10:31 27648 --sha-r- c:\windows\system32\AVSredirect.dll
2005-06-26 13:32 616448 --sha-r- c:\windows\system32\cygwin1.dll
2005-06-21 20:37 45568 --sha-r- c:\windows\system32\cygz.dll
2005-12-22 18:23 816640 --sha-r- c:\windows\system32\smab.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-05-04_20.50.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-05-06 12:50 . 2011-05-08 15:12 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-05-06 12:50 . 2011-05-02 14:36 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2011-05-08 14:49 . 2011-05-08 15:12 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2011-03-28 21:52 . 2011-05-04 23:45 229829 c:\windows\hpoins47.dat
- 2011-03-28 21:52 . 2011-05-03 15:42 229829 c:\windows\hpoins47.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-04-18 17:25 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sony Ericsson PC Companion"="c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" [2011-02-28 427008]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-04 16120832]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2011-04-17 928496]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-01-07 111208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-01-07 13880424]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-11-04 1753192]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-04-18 3460784]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
"Nokia.PCSync"="d:\programy\Nokia PC Suite\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
.
c:\documents and settings\PATOWIST\Nabˇdka Start\Programy\Po spuçtŘnˇ\
setup_9.0.0.722_03.05.2011_23-34.lnk - d:\programy\Virus Removal Tool\setup_9.0.0.722_03.05.2011_23-34\startup.exe [2011-5-3 72208]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 11 (0xb)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\RAinit]
2008-07-03 13:12 58704 ----a-w- c:\windows\system32\RAinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-12-15 20:07 1242448 ----a-w- d:\programy\Steam\steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mnmsrvc"=3 (0x3)
"Abel"=2 (0x2)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Steam"=d:\programy\Steam\steam.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"ICQ"="c:\program files\ICQ7.4\ICQ.exe" silent loginmode=4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"nwiz"=c:\program files\NVIDIA Corporation\nView\nwiz.exe /install
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"VMonitorVMUVC"="c:\program files\Vimicro Corporation\VMUVC\VMonitor.exe" VMUVC
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"SwitchBoard"=c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"PCSuiteTrayApplication"=d:\programy\Nokia PC Suite\Nokia PC Suite 6\LaunchApplication.exe -startup
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"d:\\Programy\\Steam\\steamapps\\patwist\\condition zero\\hl.exe"=
"d:\\Programy\\Steam\\Steam.exe"=
"d:\\Programy\\Steam\\steamapps\\patwist\\dedicated server\\hlds.exe"=
"d:\\Programy\\Steam\\steamapps\\patwist\\dedicated server\\hltv.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Java\\jre1.6.0_01\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"d:\\Programy\\totalcmd\\TOTALCMD.EXE"=
"d:\\Games\\Counter Strike 1.6 Non Steam\\hl.exe"=
"d:\\Games\\Counter Strike 1.6 Non Steam\\hlds.exe"=
"d:\\Games\\Counter Strike 1.6 Non Steam\\cstrike.exe"=
"d:\\Games\\stahujem\\OTHERS\\HTML\\Prizee\\Prizee Offline\\serwer_prizee.exe"=
"d:\\Games\\stahujem\\OTHERS\\HTML\\Prizee\\Prizee Offline\\http_prizee.exe"=
"d:\\Games\\Counter Strike 1.6 Non Steam\\hltv.exe"=
"d:\\Programy\\uTorrent\\utorrent.exe"=
"d:\\Programy\\Phone Remote Control\\PhoneRemoteControl.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"d:\\Games\\stahujem\\hack\\Ovladanie PC\\Net Control\\Osa9.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\InterVideo\\DVD8\\WinDVD.exe"=
"d:\\Programy\\Unified Remote\\UnifiedRemoteServer.exe"=
"d:\\Games\\stahujem\\hack\\realhack\\aa\\DoS attack by marsmela - posterus.cz DOWN programs\\SuperScan.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\ICQ7.4\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Programy\\MyPhoneExplorer\\MyPhoneExplorer.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"d:\\Programy\\Steam\\steamapps\\patwist\\counter-strike\\hl.exe"=
"d:\\Games\\stahujem\\Software\\Tlaciaren\\setup\\hpznui01.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:Remote Desktop
.
R0 87329312;87329312 Boot Guard Driver;c:\windows\system32\drivers\87329312.sys [3. 5. 2011 22:55 37392]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [16. 9. 2009 16:43 64288]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5. 1. 2009 10:32 717296]
R1 87329311;87329311;c:\windows\system32\drivers\87329311.sys [3. 5. 2011 22:55 128016]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [27. 4. 2011 20:58 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [27. 4. 2011 20:58 307288]
R1 setup_9.0.0.722_03.05.2011_23-34drv;setup_9.0.0.722_03.05.2011_23-34drv;c:\windows\system32\drivers\8732931.sys [3. 5. 2011 22:55 315408]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [27. 4. 2011 20:58 19544]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12. 8. 2010 14:15 1378040]
R2 RARfsDriver;RemotelyAnywhere Remote File System Driver;c:\windows\system32\drivers\RARfsDriver.sys [8. 10. 2008 23:07 46000]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [4. 3. 2011 17:30 1523008]
R3 ramirr;ramirr;c:\windows\system32\drivers\ramirr.sys [17. 4. 2007 14:00 10168]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [17. 2. 2011 19:06 122032]
R3 VMUVC;Vimicro Camera Service VMUVC;c:\windows\system32\drivers\VMUVC.sys [21. 12. 2010 23:58 256512]
R3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\windows\system32\drivers\vvftUVC.sys [21. 12. 2010 23:58 398720]
R3 xcpip;Ovladač protokolu TCP/IP;c:\windows\system32\drivers\xcpip.sys --> c:\windows\system32\drivers\xcpip.sys [?]
R3 xpsec;Ovladač IPSEC;c:\windows\system32\drivers\xpsec.sys --> c:\windows\system32\drivers\xpsec.sys [?]
S0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [27. 10. 2007 12:18 155136]
S0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [27. 10. 2007 12:18 5248]
S2 gupdate1c9feeb4d770e2c;Služba Google Update (gupdate1c9feeb4d770e2c);c:\program files\Google\Update\GoogleUpdate.exe [2. 2. 2011 21:23 136176]
S2 NetControl2.AdminHelper;Net Control 2 Administrator. Helper Service.;d:\programy\Hack\Net Control 2\ahs.exe --> d:\programy\Hack\Net Control 2\ahs.exe [?]
S2 RAInfo;RemotelyAnywhere Kernel Information Provider;\??\d:\programy\RemotelyAnywhere\x86\RaInfo.sys --> d:\programy\RemotelyAnywhere\x86\RaInfo.sys [?]
S3 BTCAMDRV;Mobiola Web Camera driver;c:\windows\system32\drivers\BTCamDrv.sys [26. 1. 2008 0:25 219264]
S3 cpuz;cpuz;\??\c:\docume~1\patwistt\LOCALS~1\Temp\cpuz.sys --> c:\docume~1\patwistt\LOCALS~1\Temp\cpuz.sys [?]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [15. 12. 2010 18:31 13224]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2. 2. 2011 21:23 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;"c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe" --> c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [?]
S3 ncvhook;ncvhook;c:\windows\system32\drivers\ncvhook.sys [1. 9. 2009 21:52 6896]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [15. 12. 2010 18:25 150528]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19. 2. 2010 13:37 517096]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [10. 2. 2011 10:22 10064]
S4 RARfsClientNP;RARfsClientNP; [x]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
.
2011-05-08 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-08-12 23:11]
.
2011-04-18 c:\windows\Tasks\AdobeAAMUpdater-1.0-PATWIST-PATOWIST.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-04-15 15:24]
.
2011-05-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-02 19:23]
.
2011-05-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-02 19:23]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.sk/
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe
FF - ProfilePath - c:\documents and settings\PATOWIST\Data aplikací\Mozilla\Firefox\Profiles\f9ppzm5s.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.sk
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: z: {12d2b889-7ccb-0af6-4126-806f13689ed0} - c:\program files\Mozilla Firefox\extensions\{12d2b889-7ccb-0af6-4126-806f13689ed0}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\DivX\DivX Plus Web Player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files\DivX\DivX Plus Web Player\firefox\wpa
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Easy Youtube Video Downloader: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b} - %profile%\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: TinEye Reverse Image Search: tineye@ideeinc.com - %profile%\extensions\tineye@ideeinc.com
FF - Ext: ReloadEvery: {888d99e7-e8b5-46a3-851e-1ec45da1e644} - %profile%\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-08 17:32
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Lavasoft Kernexplorer]
"ImagePath"="\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-220523388-776561741-839522115-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(964)
c:\windows\system32\RAinit.dll
c:\windows\system32\RARfsClientNP.dll
.
- - - - - - - > 'explorer.exe'(3412)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
d:\programy\Nokia PC Suite\Nokia PC Suite 6\PhoneBrowser.dll
d:\programy\Nokia PC Suite\Nokia PC Suite 6\PCSCM.dll
d:\programy\Nokia PC Suite\Nokia PC Suite 6\Lang\PhoneBrowser_slk.nlr
d:\programy\Nokia PC Suite\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\RARfsClientNP.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanionInfo.exe
d:\programy\Virus Removal Tool\setup_9.0.0.722_03.05.2011_23-34\setup_9.0.0.722_03.05.2011_23-34.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
.
**************************************************************************
.
Celkový čas: 2011-05-08 17:36:57 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-05-08 15:36
ComboFix2.txt 2011-05-04 20:53
ComboFix3.txt 2011-05-03 20:21
ComboFix4.txt 2011-05-03 19:20
.
Před spuštěním: 912 162 816
Po spuštění: 910 462 976
.
- - End Of File - - C08F22B02A1C860FEA5E1F10ECA323D1

EDIT: 19:05, LOG S AVP:

Automatická kontrola: selhání (události: 30, objekty: 512407, čas: Neznámý)
4. 5. 2011 18:38:43 Odstraněno: Trojan-Downloader.Win32.Delf.mwc D:\Games\stahujem\OTHERS\CS\CSS cheats\P7 CSS v1.7\Hack.dll
4. 5. 2011 18:38:41 Zjištěno: Trojan-Downloader.Win32.Delf.mwc D:\Games\stahujem\OTHERS\CS\CSS cheats\P7 CSS v1.7\Hack.dll
4. 5. 2011 18:38:03 Odstraněno: Trojan.Win32.Genome.njkq D:\Games\stahujem\OTHERS\CS\CS cheats\W4R Hook v7\w4r hook v7.dll
4. 5. 2011 18:37:22 Zjištěno: Trojan.Win32.Genome.njkq D:\Games\stahujem\OTHERS\CS\CS cheats\W4R Hook v7\w4r hook v7.dll
4. 5. 2011 18:24:42 Odstraněno: Trojan-GameThief.Win32.Lmir.snu D:\Games\stahujem\OTHERS\CS\CS cheats\FourSeason Hack v0.2 Alpha\FourSeasons.exe
4. 5. 2011 18:24:26 Zjištěno: Trojan-GameThief.Win32.Lmir.snu D:\Games\stahujem\OTHERS\CS\CS cheats\FourSeason Hack v0.2 Alpha\FourSeasons.exe
4. 5. 2011 18:22:11 Odstraněno: Trojan-PSW.Win32.Nilage.dmo D:\Games\stahujem\OTHERS\CS\CS cheats\CShook and loryx\CSHook.dll
4. 5. 2011 18:22:03 Zjištěno: Trojan-PSW.Win32.Nilage.dmo D:\Games\stahujem\OTHERS\CS\CS cheats\CShook and loryx\CSHook.dll
4. 5. 2011 18:18:37 Odstraněno: Trojan.Win32.Cosmu.akfw D:\Games\stahujem\OTHERS\CS\CS cheats\Apocalypse Hook\ApocHook.exe
4. 5. 2011 18:17:42 Zjištěno: Trojan.Win32.Cosmu.akfw D:\Games\stahujem\OTHERS\CS\CS cheats\Apocalypse Hook\ApocHook.exe
4. 5. 2011 15:55:43 Odstraněno: Trojan-GameThief.Win32.Staem.hl D:\Games\Mravenci\ANTS.EXE
4. 5. 2011 15:55:07 Zjištěno: Trojan-GameThief.Win32.Staem.hl D:\Games\Mravenci\ANTS.EXE
4. 5. 2011 14:52:38 Úloha byla spuštěna
4. 5. 2011 0:38:54 Úloha byla zastavena
4. 5. 2011 0:13:43 Odstraněno: Trojan-Clicker.JS.Iframe.bb C:\Documents and Settings\PATOWIST\Dokumenty\P A T R I K\patwist.ic.czz\photoalbum\lib\support\index.php
4. 5. 2011 0:13:42 Zjištěno: Trojan-Clicker.JS.Iframe.bb C:\Documents and Settings\PATOWIST\Dokumenty\P A T R I K\patwist.ic.czz\photoalbum\lib\support\index.php
4. 5. 2011 0:13:29 Odstraněno: Trojan-Clicker.JS.Iframe.bb C:\Documents and Settings\PATOWIST\Dokumenty\P A T R I K\patwist.ic.czz\photoalbum\main.php
4. 5. 2011 0:13:29 Zjištěno: Trojan-Clicker.JS.Iframe.bb C:\Documents and Settings\PATOWIST\Dokumenty\P A T R I K\patwist.ic.czz\photoalbum\main.php
4. 5. 2011 0:13:29 Odstraněno: Trojan-Clicker.JS.Iframe.bb C:\Documents and Settings\PATOWIST\Dokumenty\P A T R I K\patwist.ic.czz\blog\_upgrade\index.php
4. 5. 2011 0:13:28 Zjištěno: Trojan-Clicker.JS.Iframe.bb C:\Documents and Settings\PATOWIST\Dokumenty\P A T R I K\patwist.ic.czz\blog\_upgrade\index.php
4. 5. 2011 0:13:19 Odstraněno: Trojan-Clicker.JS.Iframe.bb C:\Documents and Settings\PATOWIST\Dokumenty\P A T R I K\patwist.ic.czz\blog\admin\index_uvod.php
4. 5. 2011 0:13:18 Odstraněno: Trojan-Clicker.JS.Iframe.bb C:\Documents and Settings\PATOWIST\Dokumenty\P A T R I K\patwist.ic.czz\blog\admin\index_xxx.php
4. 5. 2011 0:13:18 Odstraněno: Trojan-Clicker.JS.Iframe.bb C:\Documents and Settings\PATOWIST\Dokumenty\P A T R I K\patwist.ic.czz\blog\index.php
4. 5. 2011 0:12:57 Zjištěno: Trojan-Clicker.JS.Iframe.bb C:\Documents and Settings\PATOWIST\Dokumenty\P A T R I K\patwist.ic.czz\blog\admin\index_xxx.php
4. 5. 2011 0:12:57 Zjištěno: Trojan-Clicker.JS.Iframe.bb C:\Documents and Settings\PATOWIST\Dokumenty\P A T R I K\patwist.ic.czz\blog\admin\index_uvod.php
4. 5. 2011 0:12:51 Zjištěno: Trojan-Clicker.JS.Iframe.bb C:\Documents and Settings\PATOWIST\Dokumenty\P A T R I K\patwist.ic.czz\blog\index.php
3. 5. 2011 23:26:23 Odstranění při restartování systému se nezdařilo: Backdoor.Win32.Sinowal.knf C:\Documents and Settings\All Users\Data aplikací\AVAST Software\Avast\arpot\847fe-d78-0.dat
3. 5. 2011 23:25:57 Dezinfekce při restartování systému se nezdařila: Backdoor.Win32.Sinowal.knf C:\Documents and Settings\All Users\Data aplikací\AVAST Software\Avast\arpot\847fe-d78-0.dat
3. 5. 2011 23:25:56 Zjištěno: Backdoor.Win32.Sinowal.knf C:\Documents and Settings\All Users\Data aplikací\AVAST Software\Avast\arpot\847fe-d78-0.dat
3. 5. 2011 23:03:05 Úloha byla spuštěna
Automatická kontrola: dokončeno před 3 dní (události: 33, objekty: 332470, čas: 00:02:45)
4. 5. 2011 22:35:38 Úloha byla dokončena
4. 5. 2011 22:35:38 Chyba zpracování J:\Média\Obrázky\Pozadia\Photodisc. Object Series\OS21. Lions, Tigers and Bears (120 images)\OS21103.JPG Chyba čtení
4. 5. 2011 22:35:38 Chyba zpracování J:\Média\Obrázky\Pozadia\Photodisc. Object Series\OS21. Lions, Tigers and Bears (120 images)\OS21102.JPG Chyba čtení
4. 5. 2011 22:35:38 Chyba zpracování J:\Média\Obrázky\Pozadia\Photodisc. Object Series\OS21. Lions, Tigers and Bears (120 images)\OS21100.JPG Chyba čtení
4. 5. 2011 22:35:38 Chyba zpracování J:\Média\Obrázky\Pozadia\Photodisc. Object Series\OS21. Lions, Tigers and Bears (120 images)\OS21101.JPG Chyba čtení
4. 5. 2011 22:35:38 Chyba zpracování J:\Média\Obrázky\Pozadia\Photodisc. Object Series\OS21. Lions, Tigers and Bears (120 images)\OS21099.JPG Chyba čtení
4. 5. 2011 22:35:38 Chyba zpracování J:\Média\Obrázky\Pozadia\Photodisc. Object Series\OS21. Lions, Tigers and Bears (120 images)\OS21098.JPG Chyba čtení
4. 5. 2011 22:35:38 Chyba zpracování J:\Média\Obrázky\Pozadia\Photodisc. Object Series\OS21. Lions, Tigers and Bears (120 images)\OS21097.JPG Chyba čtení
4. 5. 2011 22:35:36 Chyba zpracování J:\Média\Hudba\Dramatikz - Výsledok doby (2009)\c_back.jpg Chyba čtení
4. 5. 2011 22:35:35 Chyba zpracování J:\Média\Hudba\B-Complex\beautifullies.jpg Chyba čtení
4. 5. 2011 22:35:35 Chyba zpracování J:\Média\Hudba\Ma§aker - Oko vraha (2009)\MASAKER.doc Chyba čtení
4. 5. 2011 22:35:35 Chyba zpracování J:\Média\Hudba\B-Complex - Complex Vibez Chorzow 192\beautifullies.jpg Chyba čtení
4. 5. 2011 22:35:34 Chyba zpracování J:\Média\Hudba\Kaidžas - Od začiatku až do konca feat Svetový hlas (2010)\Covers\01.JPG Chyba čtení
4. 5. 2011 22:35:34 Chyba zpracování J:\Média\Hudba\Stress - Renaissance (2007)\1.jpg Chyba čtení
4. 5. 2011 22:32:53 Úloha byla spuštěna
4. 5. 2011 22:23:07 Úloha byla zastavena
4. 5. 2011 22:09:10 Odstraněno: HackTool.Win32.BruteForce.ix D:\System Volume Information\_restore{FEB6D5CB-154E-4CBE-9DE2-838BD3E96843}\RP80\A0017549.exe
4. 5. 2011 22:08:16 Zjištěno: HackTool.Win32.BruteForce.ix D:\System Volume Information\_restore{FEB6D5CB-154E-4CBE-9DE2-838BD3E96843}\RP80\A0017549.exe/data0001
4. 5. 2011 21:59:46 Odstraněno: Trojan-Downloader.Win32.Delf.mwc D:\System Volume Information\_restore{2EFDA1B1-972B-494A-BF2F-BD09E636618E}\RP751\A0448993.dll
4. 5. 2011 21:59:45 Odstraněno: Trojan-GameThief.Win32.Lmir.snu D:\System Volume Information\_restore{2EFDA1B1-972B-494A-BF2F-BD09E636618E}\RP751\A0448990.exe
4. 5. 2011 21:59:44 Zjištěno: Trojan-Downloader.Win32.Delf.mwc D:\System Volume Information\_restore{2EFDA1B1-972B-494A-BF2F-BD09E636618E}\RP751\A0448993.dll
4. 5. 2011 21:59:44 Odstraněno: Trojan.Win32.Genome.njkq D:\System Volume Information\_restore{2EFDA1B1-972B-494A-BF2F-BD09E636618E}\RP751\A0448992.dll
4. 5. 2011 21:59:44 Odstraněno: Trojan.Win32.Cosmu.akfw D:\System Volume Information\_restore{2EFDA1B1-972B-494A-BF2F-BD09E636618E}\RP751\A0448988.exe
4. 5. 2011 21:59:44 Zjištěno: Trojan.Win32.Genome.njkq D:\System Volume Information\_restore{2EFDA1B1-972B-494A-BF2F-BD09E636618E}\RP751\A0448992.dll
4. 5. 2011 21:59:44 Zjištěno: Trojan-GameThief.Win32.Lmir.snu D:\System Volume Information\_restore{2EFDA1B1-972B-494A-BF2F-BD09E636618E}\RP751\A0448990.exe
4. 5. 2011 21:59:44 Odstraněno: Trojan-PSW.Win32.Nilage.dmo D:\System Volume Information\_restore{2EFDA1B1-972B-494A-BF2F-BD09E636618E}\RP751\A0448989.dll
4. 5. 2011 21:59:43 Odstraněno: Trojan-GameThief.Win32.Staem.hl D:\System Volume Information\_restore{2EFDA1B1-972B-494A-BF2F-BD09E636618E}\RP751\A0448976.EXE
4. 5. 2011 21:59:29 Zjištěno: Trojan-PSW.Win32.Nilage.dmo D:\System Volume Information\_restore{2EFDA1B1-972B-494A-BF2F-BD09E636618E}\RP751\A0448989.dll
4. 5. 2011 21:59:22 Zjištěno: Trojan.Win32.Cosmu.akfw D:\System Volume Information\_restore{2EFDA1B1-972B-494A-BF2F-BD09E636618E}\RP751\A0448988.exe
4. 5. 2011 21:59:12 Zjištěno: Trojan-GameThief.Win32.Staem.hl D:\System Volume Information\_restore{2EFDA1B1-972B-494A-BF2F-BD09E636618E}\RP751\A0448976.EXE
4. 5. 2011 21:30:07 Úloha byla spuštěna
4. 5. 2011 21:20:38 Úloha byla zastavena
4. 5. 2011 19:29:48 Úloha byla spuštěna
Automatická kontrola: dokončeno před 2 min. (události: 10, objekty: 190179, čas: 01:23:59)
8. 5. 2011 19:02:18 Úloha byla dokončena
8. 5. 2011 18:53:03 Odstraněno: Trojan-Downloader.Win32.IstBar.gen D:\System Volume Information\_restore{FEB6D5CB-154E-4CBE-9DE2-838BD3E96843}\RP80\A0017661.exe
8. 5. 2011 18:51:48 Zjištěno: Trojan-Downloader.Win32.IstBar.gen D:\System Volume Information\_restore{FEB6D5CB-154E-4CBE-9DE2-838BD3E96843}\RP80\A0017661.exe/data0034/UPX
8. 5. 2011 17:38:19 Úloha byla spuštěna
8. 5. 2011 17:01:33 Úloha byla zastavena
8. 5. 2011 16:56:17 Úloha byla spuštěna
4. 5. 2011 23:13:32 Úloha byla zastavena
4. 5. 2011 22:54:31 Úloha byla spuštěna
4. 5. 2011 22:36:02 Úloha byla zastavena
4. 5. 2011 22:35:45 Úloha byla spuštěna

Re: Motji: Prosím o kontrolu logu

Napsal: 08 kvě 2011 18:50
od motji
Jak je na tom počítač?

:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://tharifas.sweb.cz/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?

Re: Motji: Prosím o kontrolu logu

Napsal: 08 kvě 2011 19:29
od PATWIST
Všetko som urobil podľa napísaného návodu. A CCleaner používám :wink: je to dobrý program :) .
PC sa chová dobre - rýchlo sa zapne atď. až na tie Windows aktualizácie :o .

Ďakujem :wink:

LOG S RSIT #2

Logfile of random's system information tool 1.08 (written by random/random)
Run by PATOWIST at 2011-05-08 20:26:43
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 2 GB (9%) free of 23 GB
Total RAM: 1023 MB (26% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:26:57, on 8. 5. 2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanionInfo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\PATOWIST\Plocha\RSIT.exe
C:\Program Files\trend micro\PATOWIST.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Kwyshell MidpX - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Kwyshell MidpX - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Sony Ericsson PC Companion] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] D:\Programy\Nokia PC Suite\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDow ... eqlab2.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate1c9feeb4d770e2c) (gupdate1c9feeb4d770e2c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (file missing)
O23 - Service: Net Control 2 Administrator. Helper Service. (NetControl2.AdminHelper) - Unknown owner - D:\Programy\Hack\Net Control 2\ahs.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Unknown owner - D:\Programy\Nero\Nero BackItUp 4\IoctlSvc.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

--
End of file - 8134 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-PATWIST-PATOWIST.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll [2011-02-08 3118976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 853672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}]
DivX HiQ - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll [2011-02-08 3118976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-09 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-02-09 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EBE9E2B5-B526-48BC-AD46-687263EDCB0E}]
Kwyshell MidpX - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll [2004-12-03 100864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22 517688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - Kwyshell MidpX - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll [2004-12-03 100864]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-04-04 16120832]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2011-04-18 928496]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2011-01-07 111208]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-01-07 13880424]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-11-04 1753192]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-04-18 3460784]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sony Ericsson PC Companion"=C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [2011-02-28 427008]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
D:\Programy\Steam\Steam.exe [2010-12-15 1242448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mnmsrvc"=3
"Abel"=2

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RAinit]
C:\WINDOWS\system32\RAinit.dll [2008-07-03 58704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2006-11-11 312112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"MaxRecentDocs"=11
"NoBandCustomize"=0
"NoDrives"=0
"NoSharedDocuments"=0x01000000
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoBandCustomize"=0
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"D:\Programy\Steam\steamapps\patwist\condition zero\hl.exe"="D:\Programy\Steam\steamapps\patwist\condition zero\hl.exe:*:Enabled:Half-Life Launcher"
"D:\Programy\Steam\Steam.exe"="D:\Programy\Steam\Steam.exe:*:Enabled:Steam"
"D:\Programy\Steam\steamapps\patwist\dedicated server\hlds.exe"="D:\Programy\Steam\steamapps\patwist\dedicated server\hlds.exe:*:Enabled:HLDS Launcher"
"D:\Programy\Steam\steamapps\patwist\dedicated server\hltv.exe"="D:\Programy\Steam\steamapps\patwist\dedicated server\hltv.exe:*:Enabled:HLTV Launcher"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Program Files\Java\jre1.6.0_01\launch4j-tmp\JDownloader.exe"="C:\Program Files\Java\jre1.6.0_01\launch4j-tmp\JDownloader.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\WINDOWS\system32\java.exe"="C:\WINDOWS\system32\java.exe:*:Enabled:Java(TM) Platform SE binary"
"D:\Programy\totalcmd\TOTALCMD.EXE"="D:\Programy\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"D:\Games\Counter Strike 1.6 Non Steam\hl.exe"="D:\Games\Counter Strike 1.6 Non Steam\hl.exe:*:Enabled:Half-Life Launcher"
"D:\Games\Counter Strike 1.6 Non Steam\hlds.exe"="D:\Games\Counter Strike 1.6 Non Steam\hlds.exe:*:Enabled:HLDS Launcher"
"D:\Games\Counter Strike 1.6 Non Steam\cstrike.exe"="D:\Games\Counter Strike 1.6 Non Steam\cstrike.exe:*:Enabled:Counter-Strike Launcher"
"D:\Games\stahujem\OTHERS\HTML\Prizee\Prizee Offline\serwer_prizee.exe"="D:\Games\stahujem\OTHERS\HTML\Prizee\Prizee Offline\serwer_prizee.exe:*:Enabled:serwer_prizee"
"D:\Games\stahujem\OTHERS\HTML\Prizee\Prizee Offline\http_prizee.exe"="D:\Games\stahujem\OTHERS\HTML\Prizee\Prizee Offline\http_prizee.exe:*:Enabled:http_prizee"
"D:\Games\Counter Strike 1.6 Non Steam\hltv.exe"="D:\Games\Counter Strike 1.6 Non Steam\hltv.exe:*:Enabled:HLTV Launcher"
"D:\Programy\uTorrent\utorrent.exe"="D:\Programy\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"D:\Programy\Phone Remote Control\PhoneRemoteControl.exe"="D:\Programy\Phone Remote Control\PhoneRemoteControl.exe:*:Enabled: "
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Disabled:Java(TM) Platform SE binary"
"D:\Games\stahujem\hack\Ovladanie PC\Net Control\Osa9.exe"="D:\Games\stahujem\hack\Ovladanie PC\Net Control\Osa9.exe:*:Enabled:Osa9"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\InterVideo\DVD8\WinDVD.exe"="C:\Program Files\InterVideo\DVD8\WinDVD.exe:*:Enabled:WinDVD"
"D:\Programy\Unified Remote\UnifiedRemoteServer.exe"="D:\Programy\Unified Remote\UnifiedRemoteServer.exe:*:Enabled:Unified Remote Server"
"D:\Games\stahujem\hack\realhack\aa\DoS attack by marsmela - posterus.cz DOWN programs\SuperScan.exe"="D:\Games\stahujem\hack\realhack\aa\DoS attack by marsmela - posterus.cz DOWN programs\SuperScan.exe:*:Enabled:SuperScan 4 Beta 1"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\ICQ7.4\ICQ.exe"="C:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"D:\Programy\MyPhoneExplorer\MyPhoneExplorer.exe"="D:\Programy\MyPhoneExplorer\MyPhoneExplorer.exe:*:Enabled:MyPhoneExplorer"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"D:\Programy\Steam\steamapps\patwist\counter-strike\hl.exe"="D:\Programy\Steam\steamapps\patwist\counter-strike\hl.exe:*:Enabled:Counter-Strike"
"D:\Games\stahujem\Software\Tlaciaren\setup\hpznui01.exe"="D:\Games\stahujem\Software\Tlaciaren\setup\hpznui01.exe:*:Enabled:hpznui01.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Programy\FlashFXP\FlashFXP.exe"="D:\Programy\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3"
"E:\setup\hpznui01.exe"="E:\setup\hpznui01.exe:*:Enabled:hpznui01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe"
"C:\Program Files\HP\HP Software Update\hpwucli.exe"="C:\Program Files\HP\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe"
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe"="C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe"
"C:\Program Files\HP\Digital Imaging\{59C83C08-63F4-4AEC-81D6-392C5E23B843}\setup\hpznui01.exe"="C:\Program Files\HP\Digital Imaging\{59C83C08-63F4-4AEC-81D6-392C5E23B843}\setup\hpznui01.exe:*:Enabled:hpznui01.exe"
"C:\Program Files\ICQ7.4\ICQ.exe"="C:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"
"C:\Documents and Settings\PATOWIST\Local Settings\Temp\7zS4F9A\setup\hpznui01.exe"="C:\Documents and Settings\PATOWIST\Local Settings\Temp\7zS4F9A\setup\hpznui01.exe:*:Enabled:hpznui01.exe"
"C:\Documents and Settings\PATOWIST\Local Settings\Temp\7zS6285\setup\hpznui01.exe"="C:\Documents and Settings\PATOWIST\Local Settings\Temp\7zS6285\setup\hpznui01.exe:*:Enabled:hpznui01.exe"
"D:\Games\stahujem\Software\Tlaciaren\setup\hpznui01.exe"="D:\Games\stahujem\Software\Tlaciaren\setup\hpznui01.exe:*:Enabled:hpznui01.exe"

======List of files/folders created in the last 1 months======

2011-05-08 20:26:44 ----D---- C:\Program Files\trend micro
2011-05-08 20:26:43 ----D---- C:\rsit
2011-05-08 19:44:57 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2011-05-08 19:29:04 ----A---- C:\WINDOWS\system32\drivers\dtsoftbus01.sys
2011-05-08 19:27:23 ----D---- C:\Documents and Settings\PATOWIST\Data aplikací\DAEMON Tools Lite
2011-05-08 19:27:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
2011-05-08 18:58:25 ----SHD---- C:\RECYCLER
2011-05-03 23:10:50 ----D---- C:\Program Files\Speccy
2011-05-03 21:03:42 ----A---- C:\Boot.bak
2011-05-03 21:03:37 ----RASHD---- C:\cmdcons
2011-05-02 19:47:23 ----D---- C:\Documents and Settings\PATOWIST\Data aplikací\TS3Client
2011-04-27 20:58:06 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2011-04-27 20:58:06 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011-04-27 20:58:03 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2011-04-27 20:58:03 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2011-04-27 20:58:03 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2011-04-27 20:58:02 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2011-04-27 20:58:02 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2011-04-27 20:58:01 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2011-04-27 20:57:00 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-04-27 20:56:34 ----D---- C:\Program Files\AVAST Software
2011-04-27 20:56:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2011-04-18 01:11:42 ----A---- C:\WINDOWS\system32\drivers\SBREDrv.sys
2011-04-17 23:55:35 ----HDC---- C:\Documents and Settings\All Users\Data aplikací\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2011-04-17 19:03:28 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2011-04-17 03:43:25 ----RSHD---- C:\WINDOWS\system32\rpcnetp
2011-04-15 17:41:56 ----D---- C:\Documents and Settings\All Users\Data aplikací\regid.1986-12.com.adobe
2011-04-15 17:33:23 ----D---- C:\Program Files\Adobe Media Player
2011-04-15 16:19:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\HP Product Assistant
2011-04-15 16:16:39 ----D---- C:\Program Files\HP
2011-04-15 01:37:32 ----D---- C:\Documents and Settings\PATOWIST\Data aplikací\MyPhoneExplorer
2011-04-14 17:34:59 ----A---- C:\WINDOWS\system32\XAudio2_6.dll
2011-04-14 17:34:59 ----A---- C:\WINDOWS\system32\XAPOFX1_4.dll
2011-04-14 17:34:56 ----A---- C:\WINDOWS\system32\xactengine3_6.dll
2011-04-14 17:34:53 ----A---- C:\WINDOWS\system32\X3DAudio1_7.dll
2011-04-14 17:30:03 ----D---- C:\Program Files\OpenAL
2011-04-14 17:30:03 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2011-04-14 17:30:03 ----A---- C:\WINDOWS\system32\OpenAL32.dll
2011-04-14 16:10:39 ----A---- C:\WINDOWS\treeskp.sys
2011-04-14 15:10:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avanquest
2011-04-14 15:10:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\BVRP Software
2011-04-14 03:14:01 ----A---- C:\WINDOWS\system32\OpenCL.dll
2011-04-14 03:14:01 ----A---- C:\WINDOWS\system32\nvgenco322040.dll
2011-04-14 03:14:01 ----A---- C:\WINDOWS\system32\nvdispco322090.dll
2011-04-14 03:14:01 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2011-04-14 01:02:40 ----D---- C:\Documents and Settings\PATOWIST\Data aplikací\Chirurgie Simulation
2011-04-12 17:06:42 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype Extras
2011-04-12 16:57:03 ----D---- C:\Program Files\Common Files\Skype
2011-04-12 16:56:56 ----RD---- C:\Program Files\Skype
2011-04-12 16:44:51 ----D---- C:\Documents and Settings\PATOWIST\Data aplikací\ICQ
2011-04-12 16:44:42 ----D---- C:\Program Files\ICQ7.4
2011-04-12 16:22:13 ----D---- C:\Program Files\Opera
2011-04-10 20:58:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2011-04-10 20:57:45 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-04-10 20:57:44 ----A---- C:\WINDOWS\system32\javaws.exe
2011-04-10 20:57:44 ----A---- C:\WINDOWS\system32\javaw.exe
2011-04-10 20:57:44 ----A---- C:\WINDOWS\system32\java.exe
2011-04-09 22:41:01 ----D---- C:\Documents and Settings\PATOWIST\Data aplikací\Mp3tag

======List of files/folders modified in the last 1 months======

2011-05-08 20:26:52 ----D---- C:\WINDOWS\Prefetch
2011-05-08 20:26:44 ----D---- C:\Program Files
2011-05-08 20:25:36 ----D---- C:\WINDOWS\Temp
2011-05-08 20:24:51 ----SD---- C:\WINDOWS\Tasks
2011-05-08 20:23:25 ----D---- C:\WINDOWS\system32\CatRoot2
2011-05-08 20:23:04 ----D---- C:\WINDOWS
2011-05-08 20:20:02 ----D---- C:\WINDOWS\system32\drivers
2011-05-08 20:14:13 ----SHD---- C:\WINDOWS\Installer
2011-05-08 20:14:13 ----D---- C:\Config.Msi
2011-05-08 20:11:04 ----SHD---- C:\System Volume Information
2011-05-08 20:11:04 ----D---- C:\WINDOWS\system32\Restore
2011-05-08 20:11:02 ----D---- C:\WINDOWS\system32
2011-05-08 20:02:50 ----D---- C:\Documents and Settings\PATOWIST\Data aplikací\Uniblue
2011-05-08 19:45:08 ----D---- C:\Program Files\TuneUp Utilities 2011
2011-05-08 19:36:46 ----D---- C:\Documents and Settings\PATOWIST\Data aplikací\uTorrent
2011-05-08 19:29:18 ----HD---- C:\WINDOWS\inf
2011-05-08 18:01:08 ----D---- C:\Program Files\Mozilla Firefox
2011-05-08 17:30:06 ----A---- C:\WINDOWS\system.ini
2011-05-08 17:29:43 ----D---- C:\WINDOWS\system32\drivers\etc
2011-05-08 17:28:36 ----N---- C:\WINDOWS\SchedLgU.Txt
2011-05-08 17:28:24 ----D---- C:\WINDOWS\system32\config
2011-05-08 17:24:12 ----D---- C:\WINDOWS\AppPatch
2011-05-08 17:24:09 ----D---- C:\Program Files\Common Files
2011-05-04 19:23:12 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2011-05-04 19:18:32 ----RSD---- C:\WINDOWS\assembly
2011-05-03 21:28:06 ----D---- C:\WINDOWS\twain_32
2011-05-03 21:11:45 ----RD---- C:\WINDOWS\Web
2011-05-03 21:03:42 ----RASH---- C:\boot.ini
2011-05-03 17:33:51 ----SD---- C:\Documents and Settings\PATOWIST\Data aplikací\Microsoft
2011-05-02 22:16:44 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-05-02 22:16:43 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2011-05-02 21:52:06 ----D---- C:\Documents and Settings\PATOWIST\Data aplikací\Skype
2011-05-02 18:10:19 ----A---- C:\WINDOWS\NeroDigital.ini
2011-05-02 15:43:21 ----D---- C:\WINDOWS\WinSxS
2011-05-01 22:47:10 ----D---- C:\Documents and Settings\PATOWIST\Data aplikací\skypePM
2011-05-01 20:03:10 ----D---- C:\WINDOWS\system32\CatRoot_bak
2011-05-01 20:03:10 ----D---- C:\WINDOWS\system32\CatRoot
2011-04-29 01:33:02 ----D---- C:\Program Files\Common Files\Adobe AIR
2011-04-28 22:25:26 ----D---- C:\Program Files\Sony Ericsson
2011-04-28 22:25:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sony Ericsson
2011-04-28 22:23:52 ----D---- C:\Program Files\Microsoft
2011-04-28 22:19:50 ----A---- C:\WINDOWS\win.ini
2011-04-28 22:11:24 ----D---- C:\WINDOWS\Debug
2011-04-28 20:02:47 ----D---- C:\Program Files\Microsoft Silverlight
2011-04-28 20:02:25 ----D---- C:\WINDOWS\Downloaded Installations
2011-04-18 15:46:44 ----A---- C:\WINDOWS\system32\MRT.exe
2011-04-18 01:11:57 ----DC---- C:\WINDOWS\system32\DRVSTORE
2011-04-18 01:11:31 ----A---- C:\WINDOWS\system32\lsdelete.exe
2011-04-17 19:02:11 ----HD---- C:\WINDOWS\$hf_mig$
2011-04-16 23:57:25 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2011-04-16 23:57:20 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2011-04-16 23:57:20 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2011-04-16 23:57:19 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9L$
2011-04-16 23:57:18 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2011-04-16 23:57:16 ----HDC---- C:\WINDOWS\$NtUninstallwinusb0100$
2011-04-16 23:57:16 ----HDC---- C:\WINDOWS\$NtUninstallWdf01007$
2011-04-16 21:28:59 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-04-16 14:04:23 ----A---- C:\WINDOWS\system32\MRT.INI
2011-04-15 17:42:40 ----D---- C:\Documents and Settings\PATOWIST\Data aplikací\Adobe
2011-04-15 17:36:12 ----D---- C:\Program Files\Common Files\Adobe
2011-04-15 17:35:43 ----RSD---- C:\WINDOWS\Fonts
2011-04-15 17:31:11 ----D---- C:\Program Files\Adobe
2011-04-15 16:25:41 ----D---- C:\Documents and Settings\PATOWIST\Data aplikací\HpUpdate
2011-04-15 16:20:40 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-04-15 16:19:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\HP
2011-04-14 19:20:23 ----HD---- C:\Program Files\InstallShield Installation Information
2011-04-14 17:35:05 ----D---- C:\WINDOWS\system32\DirectX
2011-04-14 03:16:23 ----D---- C:\WINDOWS\Help
2011-04-14 03:15:30 ----D---- C:\Program Files\NVIDIA Corporation
2011-04-14 02:05:53 ----A---- C:\WINDOWS\WINCMD.INI
2011-04-14 02:05:53 ----A---- C:\WINDOWS\wcx_ftp.ini
2011-04-13 12:20:15 ----A---- C:\WINDOWS\wininit.ini
2011-04-12 20:56:57 ----D---- C:\Documents and Settings\PATOWIST\Data aplikací\TuneUp Software
2011-04-12 16:56:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-04-12 15:49:31 ----HD---- C:\Program Files\InstallJammer Registry
2011-04-11 15:00:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\DriverScanner
2011-04-11 14:56:38 ----HDC---- C:\Documents and Settings\All Users\Data aplikací\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2011-04-10 21:02:09 ----D---- C:\Program Files\SystemRequirementsLab
2011-04-10 20:58:18 ----D---- C:\Program Files\Common Files\Java
2011-04-10 20:57:41 ----D---- C:\Program Files\Java
2011-04-10 20:57:01 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 Lbd;Lbd; C:\WINDOWS\system32\DRIVERS\Lbd.sys [2010-08-12 64288]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-07-12 45648]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-01-05 717296]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-15 76544]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-04-18 30680]
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-04-18 25432]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-04-18 441176]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-04-18 307288]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-04-18 49240]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-05-08 218688]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R1 Tosrfcom;Bluetooth RFCOMM from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2005-08-01 64896]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.7.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2010-01-06 21361]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-04-18 19544]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-04-18 102488]
R2 irda;Protokol IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-03 87424]
R2 RARfsDriver;RemotelyAnywhere Remote File System Driver; \??\C:\WINDOWS\system32\drivers\RARfsDriver.sys []
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-09-12 25280]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-04-06 4258816]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2011-01-08 9888672]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-03-22 52736]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-03-22 18944]
R3 ramirr;ramirr; C:\WINDOWS\system32\DRIVERS\ramirr.sys [2007-04-17 10168]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-10-25 5888]
R3 tosporte;Bluetooth Port Driver from Toshiba; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2006-02-10 47488]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2004-08-17 12416]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-04 59264]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
R3 VBoxNetFlt;VBoxNetFlt Service; C:\WINDOWS\system32\DRIVERS\VBoxNetFlt.sys [2011-02-17 122032]
R3 VMUVC;Vimicro Camera Service VMUVC; C:\WINDOWS\System32\Drivers\VMUVC.sys [2008-08-29 256512]
R3 vvftUVC;Vimicro Camera Filter Service VMUVC; C:\WINDOWS\system32\drivers\vvftUVC.sys [2008-07-01 398720]
R3 xcpip;Ovladač protokolu TCP/IP; C:\WINDOWS\system32\drivers\xcpip.sys []
R3 xpsec;Ovladač IPSEC; C:\WINDOWS\system32\drivers\xpsec.sys []
S0 d347bus;d347bus; C:\WINDOWS\system32\DRIVERS\d347bus.sys [2004-08-22 155136]
S0 d347prt;d347prt; C:\WINDOWS\System32\Drivers\d347prt.sys [2004-08-22 5248]
S2 RAInfo;RemotelyAnywhere Kernel Information Provider; \??\D:\Programy\RemotelyAnywhere\x86\RaInfo.sys []
S2 zntport;NTPort Library Driver; \??\C:\WINDOWS\system32\zntport.sys []
S3 actser;actser; C:\WINDOWS\system32\drivers\actser.sys [2004-08-23 29440]
S3 Amsmpu4p;Amsmpu4p; \??\C:\DOCUME~1\PATOWIST\LOCALS~1\Temp\Amsmpu4p.sys []
S3 ao5kcipt;ao5kcipt; C:\WINDOWS\system32\drivers\ao5kcipt.sys []
S3 BTCAMDRV;Mobiola Web Camera driver; C:\WINDOWS\system32\DRIVERS\BTCamDrv.sys [2006-11-01 219264]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 cpuz;cpuz; \??\C:\DOCUME~1\patwistt\LOCALS~1\Temp\cpuz.sys []
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 ggflt;SEMC USB Flash Driver Filter; C:\WINDOWS\system32\DRIVERS\ggflt.sys [2010-12-15 13224]
S3 ggsemc;SEMC USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsemc.sys [2010-12-15 25512]
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MSIRCOMM;Microsoft IR Communications Driver; C:\WINDOWS\system32\DRIVERS\MSIRCOMM.sys [2004-08-04 22016]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 ncvhook;ncvhook; C:\WINDOWS\system32\DRIVERS\ncvhook.sys [2008-11-08 6896]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2004-08-04 40320]
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-09-24 47360]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\rt2870.sys [2008-01-31 560896]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 STIrUsb;SigmaTel USB-IrDA Dongle; C:\WINDOWS\system32\DRIVERS\irstusb.sys [2001-08-17 26624]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 toshidpt;TOSHIBA Bluetooth HID port driver; C:\WINDOWS\system32\drivers\Toshidpt.sys [2005-07-11 3712]
S3 Tosrfbd;Bluetooth RFBUS from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfbd.sys [2006-02-03 108928]
S3 Tosrfbnp;Bluetooth RFBNEP from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2006-03-16 37632]
S3 Tosrfhid;Bluetooth RFHID from TOSHIBA; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2006-02-08 62848]
S3 tosrfnds;Bluetooth Personal Area Network from TOSHIBA; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2005-01-06 18612]
S3 TosRfSnd;Bluetooth Audio Device (WDM) from TOSHIBA; C:\WINDOWS\system32\drivers\TosRfSnd.sys [2006-03-15 52864]
S3 Tosrfusb;Bluetooth USB Controller; C:\WINDOWS\System32\Drivers\tosrfusb.sys [2006-02-24 40192]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys []
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-04 78464]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WinUSB;Sony Ericsson USB Device sa0101 Driver; C:\WINDOWS\system32\DRIVERS\WinUSB.sys [2006-11-02 39368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
S4 RARfsClientNP;RARfsClientNP; C:\WINDOWS\system32\drivers\RARfsClientNP.sys []
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 6to4;Pomocná služba protokolu IPv6; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-04-18 42184]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
R2 HPSLPSVC;HP Network Devices Support; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
R2 Irmon;Sledování infračerveného přenosu; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-02-02 153376]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2011-04-18 1378040]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2004-08-17 14336]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2011-01-07 156776]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2004-08-17 14336]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [2011-03-30 1523008]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2004-08-17 14336]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S2 gupdate1c9feeb4d770e2c;Služba Google Update (gupdate1c9feeb4d770e2c); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-02-02 136176]
S2 NetControl2.AdminHelper;Net Control 2 Administrator. Helper Service.; D:\Programy\Hack\Net Control 2\ahs.exe []
S2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; D:\Programy\Nero\Nero BackItUp 4\IoctlSvc.exe []
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-08-26 72704]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-02-02 136176]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe []
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2007-03-26 292864]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-02-10 150528]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S4 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------


INFO LOG S RSIT #2

info.txt logfile of random's system information tool 1.08 2011-05-08 20:27:08

======Uninstall list======

-->C:\Documents and Settings\All Users\Data aplikací\DivX\DivX7\DivX Converter\DivXConverterUninstall.exe /CONVERTER
-->C:\Documents and Settings\All Users\Data aplikací\DivX\DivX7\DivX Converter\DivXConverterUninstall.exe /CONVERTER
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
32 Bit HP CIO Components Installer-->MsiExec.exe /I{60FFB3E0-6D5B-4D73-AE5B-07E58B83AF0C}
3GP Video Converter 3-->D:\Programy\3GP Video Converter 3\Uninstall.exe
Ad-Aware-->"C:\Documents and Settings\All Users\Data aplikací\{ECC164E0-3133-4C70-A831-F08DB2940F70}\Ad-AwareInstall.exe" REMOVE=TRUE MODIFY=FALSE
Ad-Aware-->C:\Documents and Settings\All Users\Data aplikací\{ECC164E0-3133-4C70-A831-F08DB2940F70}\Ad-AwareInstall.exe
Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}
Adobe Common File Installer-->MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil10p_Plugin.exe -maintain plugin
Adobe Help Center 1.0-->MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
Adobe Media Player-->msiexec /qb /x {DE3A9DC5-9A5D-6485-9662-347162C7E4CA}
Adobe Media Player-->MsiExec.exe /I{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}
Adobe Photoshop CS2-->msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
Adobe Photoshop CS5-->C:\Program Files\Common Files\Adobe\OOBE\PDApp\core\PDApp.exe --appletID="DWA_UI" --appletVersion="1.0" --mode="Uninstall" --mediaSignature="{15FEDA5F-141C-4127-8D7E-B962D1742728}"
Adobe Reader X (10.0.1)-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-AA0000000001}
Adobe Shockwave Player 11.5-->"C:\WINDOWS\system32\Adobe\Shockwave 11\uninstaller.exe"
Adobe Stock Photos 1.0-->MsiExec.exe /I{786C5747-1033-0000-B58E-000000000001}
Advertising Center-->MsiExec.exe /X{b2ec4a38-b545-4a00-8214-13fe0e915e6d}
Aktualizace systému Windows Internet Explorer 8 (KB976662)-->"C:\WINDOWS\ie8updates\KB976662-IE8\spuninst\spuninst.exe"
Aktualizace systému Windows Internet Explorer 8 (KB976749)-->"C:\WINDOWS\ie8updates\KB976749-IE8\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB974455)-->"C:\WINDOWS\ie8updates\KB974455-IE8\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB976325)-->"C:\WINDOWS\ie8updates\KB976325-IE8\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB981332)-->"C:\WINDOWS\ie8updates\KB981332-IE8\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB982381)-->"C:\WINDOWS\ie8updates\KB982381-IE8\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Avanquest update-->"C:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe" -runfromtemp -l0x0009 -removeonly
avast! Free Antivirus-->C:\Program Files\AVAST Software\Avast\aswRunDll.exe "C:\Program Files\AVAST Software\Avast\Setup\setiface.dll" RunSetup
BenVista PhotoZoom Pro 4.0.6-->D:\Programy\PhotoZoom Pro 4\Uninstall.exe
Bluetooth Stack for Windows-->MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
CCleaner (remove only)-->"D:\Programy\CCleaner\uninst.exe"
CircleSurround II Plugin for Windows Media Player-->MsiExec.exe /I{135BFFD7-D9C1-4374-B18C-BEB64FC7851C}
Codec Pack - All In 1 6.0.3.0-->C:\WINDOWS\iun6002.exe "C:\Program Files\Codec Pack - All In 1\irunin.ini"
ConvertXtoDVD 3.3.4.106c-->"D:\Programy\ConvertX\3\unins000.exe"
Counter-Strike 1.6 Final Release-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9ABFB92D-93DA-49EE-8ABF-F8195DE45CA9}\Setup.exe" -l0x19
Counter-Strike-->"D:\Programy\Steam\steam.exe" steam://uninstall/10
DAEMON Tools Lite-->D:\Programy\DAEMON Tools Lite\uninst.exe
DAEMON Tools-->MsiExec.exe /I{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}
Defraggler-->"D:\Programy\Defraggler\uninst.exe"
DivX Setup-->C:\Documents and Settings\All Users\Data aplikací\DivX\Setup\DivXSetup.exe /uninstall /bundleGroupId divx.com
DolbyFiles-->MsiExec.exe /X{b1adf008-e898-4fe2-8a1f-690d9a06acaf}
Edimax Wireless LAN-->C:\Program Files\InstallShield Installation Information\{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}\setup.exe -runfromtemp -l0x0009 -removeonly
Fraps (remove only)-->"D:\Fraps\uninstall.exe"
Futuremark SystemInfo-->"C:\Program Files\InstallShield Installation Information\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}\setup.exe" -runfromtemp -l0x0009 -removeonly
Google Earth Plug-in-->MsiExec.exe /X{FB4F9000-04FC-11E0-85D2-001AA037B01E}
Google Earth-->MsiExec.exe /X{C768790F-04FB-11E0-9B2C-001AA037B01E}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Graffiti Studio 2.0-->"D:\Programy\Graffiti Studio 2.0\unins000.exe"
GTA San Andreas-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\setup.exe" -l0x9 -removeonly
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Customer Participation Program 14.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat -forcereboot
HP Imaging Device Functions 14.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart Wireless B110 All-In-One Driver Software 14.0 Rel. 7-->C:\Program Files\HP\Digital Imaging\{014E482A-0C27-47E3-BA82-307E9DCA2F47}\setup\hpzscr01.exe -datfile hposcr47.dat -onestop -forcereboot
HP Photosmart Wireless B110 All-In-One Driver Software 14.0 Rel. 7-->C:\Program Files\HP\Digital Imaging\{59C83C08-63F4-4AEC-81D6-392C5E23B843}\setup\hpzscr01.exe -datfile hposcr47.dat -onestop -forcereboot
HP Product Detection-->MsiExec.exe /X{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}
HP Smart Web Printing 4.60-->C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpzscr01.exe -datfile hpqbud15.dat
HP Solution Center 14.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat -forcereboot
HP Update-->MsiExec.exe /X{74DC0593-6BC6-4001-AD5F-D810AFB68D86}
ICQ7.4-->"C:\Program Files\InstallShield Installation Information\{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37}\ICQ7.exe" -runfromtemp -l0x0009 -removeonly
InterVideo WinDVD 8-->C:\Program Files\InstallShield Installation Information\{20471B27-D702-4FE8-8DEC-0702CC8C0A85}\setup.exe -runfromtemp -l0x0405
Java(TM) 6 Update 24-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
K-Lite Mega Codec Pack 4.1.7-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Kwyshell MidpX Emulator Package 1.3.1-->C:\Program Files\Kwyshell\MidpX\uninst.exe
Menu Templates - Starter Kit-->MsiExec.exe /X{b78120a0-cf84-4366-a393-4d0a59bc546c}
Microsoft .NET Framework 2.0 Language Pack - CSY-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - CSY\install.exe
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Czech Language Pack-->C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Czech Language Pack\setup.exe
Microsoft .NET Framework 3.0 Czech Language Pack-->MsiExec.exe /X{FB09515C-8E3E-4E0F-A1F2-032F38DEC185}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0044-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-041B-0000-0000000FF1CE} /uninstall {8AF3A9EB-FBB9-449F-AC11-94CE39930037}
Microsoft Office Access MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0015-041B-0000-0000000FF1CE}
Microsoft Office Excel MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0016-041B-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0044-041B-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Slovak) 2007-->MsiExec.exe /X{90120000-001A-041B-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0018-041B-0000-0000000FF1CE}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011041B-6000-11D3-8CFE-0150048383C9}
Microsoft Office Professional Plus 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Hungarian) 2007-->MsiExec.exe /X{90120000-001F-040E-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Slovak) 2007-->MsiExec.exe /X{90120000-002C-041B-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0405-0000-0000000FF1CE} /uninstall {294B4278-CF7B-40B9-86A1-2D3FF0C2C524}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040E-0000-0000000FF1CE} /uninstall {573CA1BB-C8A3-46C4-993E-DB4043D9BFCD}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-041B-0000-0000000FF1CE} /uninstall {10EC59E5-9BCE-4884-BB1A-E28627220232}
Microsoft Office Publisher MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0019-041B-0000-0000000FF1CE}
Microsoft Office Shared MUI (Slovak) 2007-->MsiExec.exe /X{90120000-006E-041B-0000-0000000FF1CE}
Microsoft Office Word MUI (Slovak) 2007-->MsiExec.exe /X{90120000-001B-041B-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft_VC80_ATL_x86-->MsiExec.exe /I{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}
Microsoft_VC80_CRT_x86-->MsiExec.exe /I{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}
Microsoft_VC80_MFC_x86-->MsiExec.exe /I{D1A19B02-817E-4296-A45B-07853FD74D57}
Microsoft_VC80_MFCLOC_x86-->MsiExec.exe /I{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}
Microsoft_VC90_ATL_x86-->MsiExec.exe /I{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}
Microsoft_VC90_CRT_x86-->MsiExec.exe /I{08D2E121-7F6A-43EB-97FD-629B44903403}
Microsoft_VC90_MFC_x86-->MsiExec.exe /I{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}
Movie Templates - Starter Kit-->MsiExec.exe /X{e498385e-1c51-459a-b45f-1721e37aa1a0}
Mozilla Firefox 4.0.1 (x86 sk)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mp3 Knife 3.2-->"D:\Programy\Mp3 Knife\unins000.exe"
Mp3tag v2.48-->D:\Programy\Mp3tag\Mp3tagUninstall.EXE
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
MSXML 6 Service Pack 2 (KB973686)-->MsiExec.exe /I{56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}
MyPhoneExplorer-->D:\Programy\MyPhoneExplorer\uninstall.exe
Native Instruments Traktor DJ Studio 3-->D:\Programy\Native Instruments\Traktor DJ Studio 3\UNWISE.EXE D:\Programy\Native Instruments\Traktor DJ Studio 3\INSTALL.LOG
Need for Speed Most Wanted SK-->D:\Games\Need for Speed Most Wanted\Odinštalovať NFS-MW_SK.exe
Nero 8 Micro-->"D:\Programy\Nero\unins000.exe"
Nero 9 Trial-->C:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="8M01-209M-AH6P-5UW0-WHAW-C53X-473X-79MH"
Nero BurnRights-->MsiExec.exe /X{7829db6f-a066-4e40-8912-cb07887c20bb}
Nero ControlCenter-->MsiExec.exe /X{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}
Nero CoverDesigner-->MsiExec.exe /X{62ac81f6-bdd3-4110-9d36-3e9eaab40999}
Nero DiscSpeed-->MsiExec.exe /X{869200db-287a-4dc0-b02b-2b6787fbcd4c}
Nero DriveSpeed-->MsiExec.exe /X{33cf58f5-48d8-4575-83d6-96f574e4d83a}
Nero InfoTool-->MsiExec.exe /X{fbcdfd61-7dcf-4e71-9226-873ba0053139}
Nero Installer-->MsiExec.exe /X{e8a80433-302b-4ff1-815d-fcc8eac482ff}
Nero Live-->MsiExec.exe /X{df6a95f5-adc1-406a-bdc6-2aa7cc0182aa}
Nero OEM-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
Nero PhotoSnap-->MsiExec.exe /X{9e82b934-9a25-445b-b8df-8012808074ac}
Nero Recode-->MsiExec.exe /X{359cfc0a-beb1-440d-95ba-cf63a86da34f}
Nero Rescue Agent-->MsiExec.exe /X{368ba326-73ad-4351-84ed-3c0a7a52cc53}
Nero ShowTime-->MsiExec.exe /X{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}
Nero StartSmart-->MsiExec.exe /X{7748ac8c-18e3-43bb-959b-088faea16fb2}
Nero Vision-->MsiExec.exe /X{43e39830-1826-415d-8bae-86845787b54b}
Nero WaveEditor-->MsiExec.exe /X{a209525b-3377-43f4-b886-32f6b6e7356f}
NeroBurningROM-->MsiExec.exe /X{d025a639-b9c9-417d-8531-208859000af8}
NeroExpress-->MsiExec.exe /X{595a3116-40bb-4e0f-a2e8-d7951da56270}
NeroLiveGadget-->MsiExec.exe /X{9e9fdde6-2c26-492a-85a0-05646b3f2795}
NeroVision Express-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
Nokia Connectivity Cable Driver-->MsiExec.exe /I{52D02A2B-03D2-4E34-A358-DC5D951FD296}
Nokia PC Suite-->C:\Documents and Settings\All Users\Data aplikací\Installations\{57A48477-92F0-4C1F-ADF9-4806C4EC3CF2}\Nokia_PC_Suite_683_rel_14_1_slk_web.exe /LANG="1051"
Nokia PC Suite-->MsiExec.exe /I{57A48477-92F0-4C1F-ADF9-4806C4EC3CF2}
NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
NVIDIA nView 135.50-->"C:\WINDOWS\system32\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.NView
NVIDIA nView Desktop Manager-->C:\Program Files\NVIDIA Corporation\nView\nViewSetup.exe -uninstall
NVIDIA Ovladače grafiky 266.58-->"C:\WINDOWS\system32\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.Driver
NVIDIA WDM Drivers-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B023185F-F1EF-4F97-B0BD-AE6D802226D1}\setup.exe"
OpenAL-->"C:\Program Files\OpenAL\oalinst.exe" /U
Opera 11.10-->"C:\Program Files\Opera\Opera.exe" /uninstall
Oprava hotfix aplikace Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
PC Connectivity Solution-->MsiExec.exe /I{066D65EA-ED53-44E4-A96A-F81B6E409D2E}
PDF Settings CS5-->MsiExec.exe /I{A78FE97A-C0C8-49CE-89D0-EDD524A17392}
Phone Remote Control-->MsiExec.exe /I{F3B6CF89-B918-4DDE-A7F7-B4D4C3E6D033}
Prestigio 2.0 Megapixels High Performance Webcam-->C:\Program Files\InstallShield Installation Information\{71A51A91-E7D3-11DB-A386-005056C00008}\setup.exe -runfromtemp -l0x0005 -removeonly
QuickTime-->MsiExec.exe /I{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x5 -removeonly
Remote Professional N95 Skin-->"D:\Programy\Remote Professional\Uninstall-N95-Skin.exe"
Remote Professional-->"D:\Programy\Remote Professional\Uninstall.exe"
Security Update for 2007 Microsoft Office System (KB2288621)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5C497F0B-2061-4CC9-A61C-6B45B867354D}
Security Update for 2007 Microsoft Office System (KB2288931)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {CD769337-C8AC-46DB-A7DC-643E50089263}
Security Update for 2007 Microsoft Office System (KB2345043)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {536FB502-775F-4494-BACE-C02CC90B7A5B}
Security Update for 2007 Microsoft Office System (KB2466156)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {CEF209AB-F96D-404F-B5CC-44057C057CA3}
Security Update for 2007 Microsoft Office System (KB2509488)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {AD0DE453-0804-4495-9C91-33D0F9AA5463}
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB976321)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {7F207DCA-3399-40CB-A968-6E5991B1421A}
Security Update for Microsoft Office Access 2007 (KB979440)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {1142CCEC-ACA9-484B-BA90-C3A5CA1988C5}
Security Update for Microsoft Office Access 2007 (KB979440)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5A4E43D5-858F-49BD-BA72-8F30E1793060}
Security Update for Microsoft Office Excel 2007 (KB2464583)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {151E2FEA-C3A6-4CB6-BE6B-16651FDF04BE}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {1109D0B3-EFA3-4553-AAED-4C3E9AD130E8}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
Security Update for Microsoft Office PowerPoint 2007 (KB2464594)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {E6B7C11E-21E9-4BA0-9677-29AD603B953C}
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {D75E6D0C-BADF-4F41-98B2-0C0F02C15062}
Security Update for Microsoft Office Publisher 2007 (KB2284697)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {3A4CDE54-2403-483D-8D9A-15E3264410DF}
Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
Security Update for Microsoft Office Word 2007 (KB2344993)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}
Shop for HP Supplies-->C:\Program Files\HP\Digital Imaging\HPSSupply\hpzscr01.exe -datfile hpqbud16.dat
Skype™ 5.3-->MsiExec.exe /X{5335DADB-34BA-4AE8-A519-648D78498846}
SmartMovie Converter-->"D:\Programy\SmartMovie Converter\IIUninst.exe" D:\Programy\SmartMovie Converter\install.log
Sony Ericsson PC Companion 2.01.149-->"C:\Program Files\InstallShield Installation Information\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}\setup.exe" -runfromtemp -l0x0009 -removeonly
SoundTrax-->MsiExec.exe /X{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}
Speccy-->"C:\Program Files\Speccy\uninst.exe"
Spybot - Search & Destroy 1.4-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
System Requirements Lab CYRI-->MsiExec.exe /I{679F739E-5C76-4A41-B562-F9392156B6DD}
System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
TeamSpeak 3 Client-->"D:\Programy\TeamSpeak 3 Client\uninstall.exe"
Total Commander (Remove or Repair)-->D:\Programy\totalcmd\tcuninst.exe
Trojan Remover 6.8.2-->"D:\Programy\Trojan Remover\unins000.exe"
Tunatic-->"C:\WINDOWS\lsb_un20.exe" /C=UC /N=Tunatic
TuneUp Utilities 2011-->C:\Program Files\TuneUp Utilities 2011\TUInstallHelper.exe --Trigger-Uninstall
Uniblue DriverScanner 2009-->"C:\Documents and Settings\All Users\Data aplikací\{D5ABFFAD-D592-4F98-B02B-587125B4801F}\DriverScanner_Setup.exe" REMOVE=TRUE MODIFY=FALSE
Uniblue DriverScanner 2009-->C:\Documents and Settings\All Users\Data aplikací\{D5ABFFAD-D592-4F98-B02B-587125B4801F}\DriverScanner_Setup.exe
Uniblue RegistryBooster 2-->"D:\Programy\Registry Booster 2\unins000.exe"
Uniblue SpeedUpMyPC 2009-->"C:\Documents and Settings\All Users\Data aplikací\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}\SpeedUpMyPC.exe" REMOVE=TRUE MODIFY=FALSE
Uniblue SpeedUpMyPC 2009-->C:\Documents and Settings\All Users\Data aplikací\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}\SpeedUpMyPC.exe
Unified Remote-->MsiExec.exe /I{BC73BB64-DC02-4ECA-9616-7133BAA4D104}
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Microsoft Office Outlook 2007 (KB2412171)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {752A0B7C-BD24-4362-AC86-AB63FEE6F46F}
Update for Outlook 2007 Junk Email Filter (KB2522999)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {CC8A81F7-5A36-4DE9-ABB3-5499132062C5}
VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
Ventrilo-->MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
VentriloMIX-->D:\PROGRAMY\Ventrilo MIX v0.5\Uninstal.exe
Video Converter-->"C:\WINDOWS\Video Converter\uninstall.exe" "/U:D:\Programy\VideoConverter\Uninstall\uninstall.xml"
Virtual DJ - Atomix Productions-->D:\Programy\VirtualDJ6\UNWISE.EXE D:\Programy\VirtualDJ6\INSTALL.LOG
Virtual DJ Home - Atomix Productions-->D:\Programy\VirtualDJ6\UNWISE.EXE D:\Programy\VirtualDJ6\INSTALL.LOG
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
Web Page Maker V3.21-->"D:\Programy\Web Page Maker\unins000.exe"
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows Live ID Sign-in Assistant-->MsiExec.exe /X{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Presentation Foundation Language Pack (CSY)-->MsiExec.exe /X{AAB6D0F8-02B3-4E89-B24C-0BB153C21445}
Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows Workflow Foundation CS Language Pack-->MsiExec.exe /I{6EF72FC6-842E-4FE6-BF88-BFBF03C9DA74}
WinRAR archivátor-->D:\Programy\Winrar\uninstall.exe

======Security center information======

AV: Lavasoft Ad-Watch Live! Anti-Virus
AV: avast! Antivirus

======System event log======

Computer Name: PATWIST
Event Code: 20
Message: Instalace se nezdařila: Instalace následující aktualizace se nezdařila z důvodu chyby (0x80070652): Aktualizace zabezpečení sady Microsoft Office 2003 (KB2288613).

Record Number: 15845
Source Name: Windows Update Agent
Time Written: 20110428221222.000000+120
Event Type: Chyba
User:

Computer Name: PATWIST
Event Code: 20
Message: Instalace se nezdařila: Instalace následující aktualizace se nezdařila z důvodu chyby (0x80070652): Aktualizace zabezpečení aplikace Microsoft Office Publisher 2003 (KB2284695).

Record Number: 15844
Source Name: Windows Update Agent
Time Written: 20110428221214.000000+120
Event Type: Chyba
User:

Computer Name: PATWIST
Event Code: 20
Message: Instalace se nezdařila: Instalace následující aktualizace se nezdařila z důvodu chyby (0x80070652): Aktualizace zabezpečení pro produkt Microsoft Office InfoPath 2003 (KB980923).

Record Number: 15843
Source Name: Windows Update Agent
Time Written: 20110428221214.000000+120
Event Type: Chyba
User:

Computer Name: PATWIST
Event Code: 7036
Message: Stav služby Windows Installer byl změněn na: Spuštěno

Record Number: 15842
Source Name: Service Control Manager
Time Written: 20110428221109.000000+120
Event Type: Informace
User:

Computer Name: PATWIST
Event Code: 7035
Message: Řídící příkaz Spuštěno byl službě Windows Installer úspěšně odeslán.

Record Number: 15841
Source Name: Service Control Manager
Time Written: 20110428221109.000000+120
Event Type: Informace
User: NT AUTHORITY\SYSTEM

=====Application event log=====

Computer Name: PATWIST
Event Code: 11708
Message: Produkt: Microsoft Office Professional Edition 2003 -- Inštalácia zlyhala.

Record Number: 19616
Source Name: MsiInstaller
Time Written: 20110329184549.000000+120
Event Type: Informace
User: PATWIST\PATOWIST

Computer Name: PATWIST
Event Code: 1024
Message: Aktualizaci {9F2DFB2F-DDA1-4034-84FA-D008BDD93972} produktu Microsoft Office Professional Edition 2003 nebylo možné nainstalovat. Kód chyby: 1648. Instalační služba systému Windows může vytvořit soubor protokolu s informacemi, které usnadní řešení potíží při instalaci softwaru. Další informace naleznete na webu na adrese http://go.microsoft.com/fwlink/?LinkId=23127

Record Number: 19615
Source Name: MsiInstaller
Time Written: 20110329184549.000000+120
Event Type: Chyba
User: PATWIST\PATOWIST

Computer Name: PATWIST
Event Code: 11708
Message: Produkt: Microsoft Office Professional Edition 2003 -- Inštalácia zlyhala.

Record Number: 19614
Source Name: MsiInstaller
Time Written: 20110329184548.000000+120
Event Type: Informace
User: PATWIST\PATOWIST

Computer Name: PATWIST
Event Code: 1024
Message: Aktualizaci {C628731E-0A27-446E-81B7-8A2D2843FC23} produktu Microsoft Office Professional Edition 2003 nebylo možné nainstalovat. Kód chyby: 1648. Instalační služba systému Windows může vytvořit soubor protokolu s informacemi, které usnadní řešení potíží při instalaci softwaru. Další informace naleznete na webu na adrese http://go.microsoft.com/fwlink/?LinkId=23127

Record Number: 19613
Source Name: MsiInstaller
Time Written: 20110329184548.000000+120
Event Type: Chyba
User: PATWIST\PATOWIST

Computer Name: PATWIST
Event Code: 11708
Message: Produkt: Microsoft Office Professional Edition 2003 -- Inštalácia zlyhala.

Record Number: 19612
Source Name: MsiInstaller
Time Written: 20110329184547.000000+120
Event Type: Informace
User: PATWIST\PATOWIST

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;%CommonProgramFiles%\Microsoft Shared\Windows Live;C:\Program Files\PC Connectivity Solution;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Common Files\Adobe\AGL
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 79 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=4f02
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip

-----------------EOF-----------------

Re: Motji: Prosím o kontrolu logu

Napsal: 08 kvě 2011 20:53
od motji
Co je s aktualizacemi?

Re: Motji: Prosím o kontrolu logu

Napsal: 08 kvě 2011 21:21
od PATWIST
Akurát som dal avast sken ešte pred spustením aplikácii teda hneď po štarte ale niečo na externom to seklo :roll: . Nedá sa aktualizovať. Stale napise ze niektoré aktualizácie sa nepodarilo nainštalovať. Teraz po prvý krát mi vyskočila ponuka SP3 a hneď potom napísalo

Některé aktualizace nelze nainstalovat.
Následující aktualizace nebyli nainstalovány:
Aktualizace Windows XP Service Pack 3 (KB936929)

Re: Motji: Prosím o kontrolu logu

Napsal: 09 kvě 2011 10:27
od motji
Zkuste v nouzovém režimu

Re: Motji: Prosím o kontrolu logu

Napsal: 09 kvě 2011 15:47
od PATWIST
Zapol som PC a pritom držal F8 (teda spustil som ten núdzový režim) a pekne sa mi nainštaloval SP Pack 3, potom som reštartoval PC a už mi nabehli 63 aktualizácií s ktorých sa niektoré stiahli ale 18 sa nedá stiahnuť (všetky sú s Microsoft Office 2003 a ja mám nainštalovanú aj 2007) :?: Systém sa vypína dlho. Vadí keď mám nainštalovaný Avast a Ad-Aware? Ešte skúsim nainštalovať tlačiareň.

Některé aktualizace nelze nainstalovat
Aktualizace se projeví ž po restartovaní počítače.
Nasledujíci aktualizace nebyli nainstalovány:

Aktualizace zabezpečení pro produkt Microsoft Office InfoPath 2003 (KB980923)
Aktualizace zabezpečení aplikace Microsoft Office Publisher 2003 (KB2284695)
Aktualizace zabezpečení sady Microsoft Office 2003 (KB2288613)
Aktualizace zabezpečení sady Microsoft Office 2003 (KB972580)
Aktualizace zabezpečení aplikace Microsoft Office PowerPoint 2003 (KB2464588)
Aktualizace zabezpečení sady Microsoft Office 2003 (KB951535)
Aktualizace sady Microsoft Office 2003 (KB978551)
Aktualizace zabezpečení sady Microsoft Works Suite 2005 (KB943973)
Aktualizace zabezpečení aplikace Microsoft Office Word 2003 (KB2344911)
Aktualizace zabezpečení sady Microsoft Office 2003 (KB2509503)
Aktualizace zabezpečení součástí Microsoft Office Web Components (KB947319)
Aktualizace zabezpečení aplikace Microsoft Office Access 2003 (KB981716)
Aktualizace zabezpečení sady Microsoft Office 2003 (KB974554)
Aktualizace zabezpečení aplikace Microsoft Office Excel 2003 (KB2502786)
Aktualizace aplikace Microsoft Office Outlook 2003 (KB2449798)
Aktualizace zabezpečení aplikace Microsoft Office Outlook 2003 (KB980373)
Aktualizace zabezpečení sady Microsoft Office 2003 (KB976382)

A Avast mi stále hlási (aj po odstránení daného objektu):

V systéme sa našiel podozrivý objekt (rookit). Môže to byť príznak nákazy škodlivým kódom. Odporúčame tento objekt okamžite odstrániť.

INFORMÁCIE O ROOTKITE
Názov súboru: MBR: \\.\PHYSICALDRIVE0

Re: Motji: Prosím o kontrolu logu

Napsal: 09 kvě 2011 16:00
od motji
A jé, kde jste zas k tomu přišel :o , Mbr jsem prověřovala a byl v pořádku :o .

:arrow: Stahněte ASWMBR http://public.avast.com/~gmerek/aswMBR.exe na plochu
- otevřte program dvojklikem na ikonu
-klikněte na volbu scan
-program provede krátký sken Mbr, pak klikněte na volbu save log
-program zavřete a log mi zkopírujete zde :)

Re: Motji: Prosím o kontrolu logu

Napsal: 09 kvě 2011 16:11
od PATWIST
LOG S aswMBR:

aswMBR version 0.9.5.256 Copyright(c) 2011 AVAST Software
Run date: 2011-05-09 17:10:03
-----------------------------
17:10:03.062 OS Version: Windows 5.1.2600 Service Pack 3
17:10:03.062 Number of processors: 1 586 0x4F02
17:10:03.062 ComputerName: PATWIST UserName:
17:10:03.296 Initialize success
17:10:05.296 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e
17:10:05.296 Disk 0 Vendor: SAMSUNG_HD160JJ ZM100-41 Size: 152627MB BusType: 3
17:10:05.296 Disk 0 MBR read error 0
17:10:05.296 Disk 0 MBR scan
17:10:05.296 Disk 0 unknown MBR code
17:10:05.296 MBR BIOS signature not found 0
17:10:05.312 Disk 0 scanning sectors +312576705
17:10:05.312 Disk 0 scanning C:\WINDOWS\system32\drivers
17:10:10.015 Service scanning
17:10:11.000 Disk 0 trace - called modules:
17:10:11.000 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x85eccaee]<<
17:10:11.000 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x870c8ab8]
17:10:11.000 3 CLASSPNP.SYS[f769cfd7] -> nt!IofCallDriver -> \Device\0000008e[0x871cdf18]
17:10:11.000 5 ACPI.sys[f73f5620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-e[0x871cbd98]
17:10:11.078 Scan finished successfully
17:10:24.234 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\PATOWIST\Plocha\MBR.dat"
17:10:24.250 The log file has been saved successfully to "C:\Documents and Settings\PATOWIST\Plocha\aswMBR.txt"

Re: Motji: Prosím o kontrolu logu

Napsal: 09 kvě 2011 16:16
od motji
Já tam nic nevidím :o

:arrow: Stáhněte TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
- a uložte ho na plochu.
- 2x klikněte na ikonu programu a spusťte
- dejte volbu Spustit kontrolu - pak potvrdte start sken
- pokud program najde infikovaný soubor, ukáže se Vám předvolená akce Cure, v tom případě potvrdte tlačítko Continue
- pokud bude chtít program restartovat počítač, klikněte na tlačítko Reboot Now
- pokud si restart nevyžádá, klikněte na tlačítko Report. Měl vy na Vás vyskočit log, obsah logu zkopírujte do svého topicu.
- pokud se log nezobrazí, je uložený ve Vašem kořenovém adresáři.

Re: Motji: Prosím o kontrolu logu

Napsal: 09 kvě 2011 16:32
od PATWIST
Log s TDSSKiller:

Zatiaľ, po reštartovaní PC upravím príspevok

\HardDisk1 (Backdoor.Win32.Sinowal.knf) - will be cured after reboot
\HardDisk1 - ok

Log s TDSSKiller: Aj avast mi zobrazoval Sinowal

2011/05/09 17:29:31.0828 2600 TDSS rootkit removing tool 2.5.0.0 May 1 2011 14:20:16
2011/05/09 17:29:32.0015 2600 ================================================================================
2011/05/09 17:29:32.0015 2600 SystemInfo:
2011/05/09 17:29:32.0015 2600
2011/05/09 17:29:32.0015 2600 OS Version: 5.1.2600 ServicePack: 3.0
2011/05/09 17:29:32.0015 2600 Product type: Workstation
2011/05/09 17:29:32.0015 2600 ComputerName: PATWIST
2011/05/09 17:29:32.0015 2600 UserName: PATOWIST
2011/05/09 17:29:32.0015 2600 Windows directory: C:\WINDOWS
2011/05/09 17:29:32.0015 2600 System windows directory: C:\WINDOWS
2011/05/09 17:29:32.0015 2600 Processor architecture: Intel x86
2011/05/09 17:29:32.0015 2600 Number of processors: 1
2011/05/09 17:29:32.0015 2600 Page size: 0x1000
2011/05/09 17:29:32.0015 2600 Boot type: Normal boot
2011/05/09 17:29:32.0015 2600 ================================================================================
2011/05/09 17:29:36.0640 2600 Initialize success
2011/05/09 17:29:46.0671 3988 ================================================================================
2011/05/09 17:29:46.0671 3988 Scan started
2011/05/09 17:29:46.0671 3988 Mode: Manual;
2011/05/09 17:29:46.0671 3988 ================================================================================
2011/05/09 17:29:46.0921 3988 Aavmker4 (78a4db23bb4e8d4349e164d1d90af73f) C:\WINDOWS\system32\drivers\Aavmker4.sys
2011/05/09 17:29:47.0015 3988 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/05/09 17:29:47.0046 3988 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/05/09 17:29:47.0093 3988 actser (6463d1db354b13e6ced4d67f6e4910f4) C:\WINDOWS\system32\drivers\actser.sys
2011/05/09 17:29:47.0140 3988 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/05/09 17:29:47.0187 3988 AegisP (023867b6606fbabcdd52e089c4a507da) C:\WINDOWS\system32\DRIVERS\AegisP.sys
2011/05/09 17:29:47.0234 3988 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2011/05/09 17:29:47.0359 3988 AmdK8 (59301936898ae62245a6f09c0aba9475) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
2011/05/09 17:29:47.0593 3988 aswFsBlk (9bdb29e81abceb883556df44649696c4) C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011/05/09 17:29:47.0609 3988 aswMon2 (2ce6da466687cbb3b97e59f8831a27cb) C:\WINDOWS\system32\drivers\aswMon2.sys
2011/05/09 17:29:47.0640 3988 aswRdr (a90cf680ca7a323913ca3a0810c8e02d) C:\WINDOWS\system32\drivers\aswRdr.sys
2011/05/09 17:29:47.0687 3988 aswSnx (f7969934cca2e566e95df17380a3cb11) C:\WINDOWS\system32\drivers\aswSnx.sys
2011/05/09 17:29:47.0734 3988 aswSP (478d6a0e0630c31bf4a7f5eb0a05b92c) C:\WINDOWS\system32\drivers\aswSP.sys
2011/05/09 17:29:47.0765 3988 aswTdi (e52e45743e27fd6184c55618a10b81ab) C:\WINDOWS\system32\drivers\aswTdi.sys
2011/05/09 17:29:47.0796 3988 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/05/09 17:29:47.0828 3988 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/05/09 17:29:47.0859 3988 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/05/09 17:29:47.0906 3988 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/05/09 17:29:47.0937 3988 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/05/09 17:29:47.0984 3988 BTCAMDRV (62506a32d1f1878655dc3de3dfd1cff2) C:\WINDOWS\system32\DRIVERS\BTCamDrv.sys
2011/05/09 17:29:48.0031 3988 BTHPORT (f338662a6c1fc11dd9508f6dff2c06a2) C:\WINDOWS\system32\Drivers\BTHport.sys
2011/05/09 17:29:48.0062 3988 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys
2011/05/09 17:29:48.0109 3988 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/05/09 17:29:48.0125 3988 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/05/09 17:29:48.0171 3988 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/05/09 17:29:48.0203 3988 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/05/09 17:29:48.0234 3988 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/05/09 17:29:48.0375 3988 d347bus (5776322f93cdb91086111f5ffbfda2a0) C:\WINDOWS\system32\DRIVERS\d347bus.sys
2011/05/09 17:29:48.0406 3988 d347prt (b49f79ace459763f4e0380071be9cb45) C:\WINDOWS\system32\Drivers\d347prt.sys
2011/05/09 17:29:48.0468 3988 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/05/09 17:29:48.0515 3988 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
2011/05/09 17:29:48.0546 3988 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
2011/05/09 17:29:48.0578 3988 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/05/09 17:29:48.0609 3988 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/05/09 17:29:48.0656 3988 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/05/09 17:29:48.0703 3988 dtsoftbus01 (555e54ac2f601a8821cef58961653991) C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys
2011/05/09 17:29:48.0750 3988 ENTECH (16ebd8bf1d5090923694cc972c7ce1b4) C:\WINDOWS\system32\DRIVERS\ENTECH.sys
2011/05/09 17:29:48.0796 3988 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/05/09 17:29:48.0828 3988 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/05/09 17:29:48.0843 3988 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
2011/05/09 17:29:48.0875 3988 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2011/05/09 17:29:48.0890 3988 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/05/09 17:29:48.0937 3988 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/05/09 17:29:48.0953 3988 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/05/09 17:29:48.0984 3988 ggflt (007aea2e06e7cef7372e40c277163959) C:\WINDOWS\system32\DRIVERS\ggflt.sys
2011/05/09 17:29:49.0031 3988 ggsemc (c73de35960ca75c5ab4ae636b127c64e) C:\WINDOWS\system32\DRIVERS\ggsemc.sys
2011/05/09 17:29:49.0062 3988 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/05/09 17:29:49.0093 3988 hamachi (7929a161f9951d173ca9900fe7067391) C:\WINDOWS\system32\DRIVERS\hamachi.sys
2011/05/09 17:29:49.0140 3988 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/05/09 17:29:49.0171 3988 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/05/09 17:29:49.0250 3988 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/05/09 17:29:49.0312 3988 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/05/09 17:29:49.0343 3988 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/05/09 17:29:49.0515 3988 IntcAzAudAddService (2389f12f0ed506176b7c29c8144cea09) C:\WINDOWS\system32\drivers\RtkHDAud.sys
2011/05/09 17:29:49.0609 3988 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/05/09 17:29:49.0640 3988 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/05/09 17:29:49.0687 3988 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/05/09 17:29:49.0718 3988 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/05/09 17:29:49.0750 3988 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/05/09 17:29:49.0765 3988 irda (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys
2011/05/09 17:29:49.0796 3988 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/05/09 17:29:49.0828 3988 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/05/09 17:29:49.0859 3988 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/05/09 17:29:49.0890 3988 kbdhid (86c8f23616c6c6e5b2776901c17b945b) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2011/05/09 17:29:49.0921 3988 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/05/09 17:29:49.0953 3988 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/05/09 17:29:50.0031 3988 Lavasoft Kernexplorer (0bd6d3f477df86420de942a741dabe37) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
2011/05/09 17:29:50.0062 3988 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\WINDOWS\system32\DRIVERS\Lbd.sys
2011/05/09 17:29:50.0156 3988 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/05/09 17:29:50.0187 3988 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
2011/05/09 17:29:50.0218 3988 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/05/09 17:29:50.0250 3988 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/05/09 17:29:50.0281 3988 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/05/09 17:29:50.0312 3988 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/05/09 17:29:50.0375 3988 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/05/09 17:29:50.0406 3988 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/05/09 17:29:50.0437 3988 MSIRCOMM (95c6432151ccff8617352f8e616a1aa4) C:\WINDOWS\system32\DRIVERS\MSIRCOMM.sys
2011/05/09 17:29:50.0468 3988 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/05/09 17:29:50.0500 3988 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/05/09 17:29:50.0515 3988 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/05/09 17:29:50.0546 3988 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/05/09 17:29:50.0578 3988 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/05/09 17:29:50.0593 3988 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/05/09 17:29:50.0625 3988 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/05/09 17:29:50.0671 3988 ncvhook (843c8b0dec260ef371c2f8f949f6ec8b) C:\WINDOWS\system32\DRIVERS\ncvhook.sys
2011/05/09 17:29:50.0703 3988 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/05/09 17:29:50.0718 3988 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/05/09 17:29:50.0750 3988 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/05/09 17:29:50.0781 3988 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/05/09 17:29:50.0812 3988 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/05/09 17:29:50.0828 3988 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/05/09 17:29:50.0859 3988 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/05/09 17:29:50.0890 3988 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/05/09 17:29:50.0953 3988 nm (1e421a6bcf2203cc61b821ada9de878b) C:\WINDOWS\system32\DRIVERS\NMnt.sys
2011/05/09 17:29:50.0968 3988 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/05/09 17:29:51.0031 3988 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/05/09 17:29:51.0062 3988 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/05/09 17:29:51.0359 3988 nv (18c9b152da7bea76b2f9e4b6412e0aaf) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/05/09 17:29:51.0640 3988 NVENETFD (cc34564bca235ebad8b308d871efa2df) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
2011/05/09 17:29:51.0656 3988 nvnetbus (46fdb8d07dd4fc81093b0acb243a525d) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
2011/05/09 17:29:51.0703 3988 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/05/09 17:29:51.0734 3988 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/05/09 17:29:51.0796 3988 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\drivers\Parport.sys
2011/05/09 17:29:51.0828 3988 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/05/09 17:29:51.0859 3988 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/05/09 17:29:51.0890 3988 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/05/09 17:29:51.0937 3988 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/05/09 17:29:51.0968 3988 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/05/09 17:29:52.0000 3988 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys
2011/05/09 17:29:52.0156 3988 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/05/09 17:29:52.0187 3988 Processor (7eb15dce4ec3a0220bd796a15c18186e) C:\WINDOWS\system32\DRIVERS\processr.sys
2011/05/09 17:29:52.0234 3988 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/05/09 17:29:52.0250 3988 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/05/09 17:29:52.0296 3988 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/05/09 17:29:52.0453 3988 ramirr (4f3dca35e6cf4afab34363fbe29daaf8) C:\WINDOWS\system32\DRIVERS\ramirr.sys
2011/05/09 17:29:52.0484 3988 RARfsDriver (67fbc3ff98032dfc214aea1879272716) C:\WINDOWS\system32\drivers\RARfsDriver.sys
2011/05/09 17:29:52.0515 3988 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/05/09 17:29:52.0546 3988 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys
2011/05/09 17:29:52.0562 3988 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/05/09 17:29:52.0593 3988 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/05/09 17:29:52.0609 3988 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/05/09 17:29:52.0640 3988 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/05/09 17:29:52.0671 3988 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/05/09 17:29:52.0703 3988 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/05/09 17:29:52.0734 3988 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/05/09 17:29:52.0765 3988 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/05/09 17:29:52.0796 3988 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
2011/05/09 17:29:52.0859 3988 rt2870 (4311d22a38f7e403475aa2c338768c11) C:\WINDOWS\system32\DRIVERS\rt2870.sys
2011/05/09 17:29:52.0921 3988 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/05/09 17:29:52.0968 3988 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2011/05/09 17:29:52.0984 3988 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\DRIVERS\serial.sys
2011/05/09 17:29:53.0015 3988 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/05/09 17:29:53.0078 3988 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/05/09 17:29:53.0125 3988 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/05/09 17:29:53.0171 3988 sptd (71e276f6d189413266ea22171806597b) C:\WINDOWS\system32\Drivers\sptd.sys
2011/05/09 17:29:53.0187 3988 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 71e276f6d189413266ea22171806597b
2011/05/09 17:29:53.0187 3988 sptd - detected LockedFile.Multi.Generic (1)
2011/05/09 17:29:53.0203 3988 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/05/09 17:29:53.0250 3988 Srv (89220b427890aa1dffd1a02648ae51c3) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/05/09 17:29:53.0281 3988 STIrUsb (a1a16662c6b1a665d965d61b9eecc5a7) C:\WINDOWS\system32\DRIVERS\irstusb.sys
2011/05/09 17:29:53.0312 3988 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/05/09 17:29:53.0343 3988 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/05/09 17:29:53.0375 3988 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/05/09 17:29:53.0578 3988 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/05/09 17:29:53.0640 3988 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/05/09 17:29:53.0687 3988 Tcpip6 (4e53bbcc4be37d7a4bd6ef1098c89ff7) C:\WINDOWS\system32\DRIVERS\tcpip6.sys
2011/05/09 17:29:53.0718 3988 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/05/09 17:29:53.0765 3988 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/05/09 17:29:53.0843 3988 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/05/09 17:29:53.0968 3988 toshidpt (e362d54fd394999c4178936396664e57) C:\WINDOWS\system32\drivers\Toshidpt.sys
2011/05/09 17:29:54.0140 3988 tosporte (b2842672056ca33f0a4aab3e5cbbf181) C:\WINDOWS\system32\DRIVERS\tosporte.sys
2011/05/09 17:29:54.0187 3988 Tosrfbd (0ec5206059d97a8dc785be73fb457ec7) C:\WINDOWS\system32\Drivers\tosrfbd.sys
2011/05/09 17:29:54.0234 3988 Tosrfbnp (1ae2ba74b2a4f5a358b13fcd35258c30) C:\WINDOWS\system32\Drivers\tosrfbnp.sys
2011/05/09 17:29:54.0265 3988 Tosrfcom (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\WINDOWS\system32\Drivers\tosrfcom.sys
2011/05/09 17:29:54.0296 3988 Tosrfhid (5dbf390aab62dd0d4d43a9278614e001) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
2011/05/09 17:29:54.0328 3988 tosrfnds (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\WINDOWS\system32\DRIVERS\tosrfnds.sys
2011/05/09 17:29:54.0359 3988 TosRfSnd (ab6fd13d7efa2634fa6bdf84c7ef0696) C:\WINDOWS\system32\drivers\TosRfSnd.sys
2011/05/09 17:29:54.0390 3988 Tosrfusb (d870fd6ce9060b73289f47e88630ee0e) C:\WINDOWS\system32\Drivers\tosrfusb.sys
2011/05/09 17:29:54.0500 3988 TuneUpUtilitiesDrv (f2107c9d85ec0df116939ccce06ae697) C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys
2011/05/09 17:29:54.0578 3988 tunmp (8f861eda21c05857eb8197300a92501c) C:\WINDOWS\system32\DRIVERS\tunmp.sys
2011/05/09 17:29:54.0625 3988 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/05/09 17:29:54.0687 3988 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/05/09 17:29:54.0734 3988 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
2011/05/09 17:29:54.0765 3988 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/05/09 17:29:54.0796 3988 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/05/09 17:29:54.0828 3988 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/05/09 17:29:54.0859 3988 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
2011/05/09 17:29:54.0890 3988 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/05/09 17:29:54.0921 3988 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/05/09 17:29:55.0046 3988 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/05/09 17:29:55.0078 3988 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
2011/05/09 17:29:55.0125 3988 VBoxNetFlt (cbb6f6d2f9a90853f830876967e514c6) C:\WINDOWS\system32\DRIVERS\VBoxNetFlt.sys
2011/05/09 17:29:55.0156 3988 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/05/09 17:29:55.0234 3988 VMUVC (9b4c3481cd420bb22ec0ede7d96226c1) C:\WINDOWS\system32\Drivers\VMUVC.sys
2011/05/09 17:29:55.0265 3988 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/05/09 17:29:55.0312 3988 vvftUVC (d3ee7cc6b0c29083a874db9d890bceb5) C:\WINDOWS\system32\drivers\vvftUVC.sys
2011/05/09 17:29:55.0453 3988 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/05/09 17:29:55.0515 3988 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys
2011/05/09 17:29:55.0578 3988 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/05/09 17:29:55.0640 3988 WinUSB (fd600b032e741eb6aab509fc630f7c42) C:\WINDOWS\system32\DRIVERS\WinUSB.sys
2011/05/09 17:29:55.0718 3988 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\Drivers\wpdusb.sys
2011/05/09 17:29:55.0765 3988 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2011/05/09 17:29:55.0796 3988 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/05/09 17:29:55.0828 3988 WudfPf (50eb9e21963b4f06fd010d007d54351b) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/05/09 17:29:55.0859 3988 WudfRd (6e209664bdea8a15b5e8e480d6c607c2) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/05/09 17:29:55.0968 3988 \HardDisk1 - detected Backdoor.Win32.Sinowal.knf (0)
2011/05/09 17:29:55.0984 3988 ================================================================================
2011/05/09 17:29:55.0984 3988 Scan finished
2011/05/09 17:29:55.0984 3988 ================================================================================
2011/05/09 17:29:56.0000 5520 Detected object count: 2
2011/05/09 17:30:22.0984 5520 LockedFile.Multi.Generic(sptd) - User select action: Skip
2011/05/09 17:30:23.0015 5520 \HardDisk1 (Backdoor.Win32.Sinowal.knf) - will be cured after reboot
2011/05/09 17:30:23.0015 5520 \HardDisk1 - ok
2011/05/09 17:30:23.0015 5520 Backdoor.Win32.Sinowal.knf(\HardDisk1) - User select action: Cure
2011/05/09 17:32:07.0203 1876 Deinitialize success