Stránka 1 z 1

kontrola logu

Napsal: 29 pro 2010 23:05
od Mili
Při startu a kontrole programem RSIT.exe mi to nahlásilo erorr a AVG nahlásilo malver přesto se log vypsal přikládám :o

Logfile of random's system information tool 1.08 (written by random/random)
Run by Hulín at 2010-12-29 23:01:37
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 40 GB (61%) free of 65 GB
Total RAM: 2047 MB (65% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:02:43, on 29.12.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17093)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\DOCUME~1\HULN~1\LOCALS~1\Temp\TeamViewer\Version6\TeamViewer.exe
c:\docume~1\huln~1\locals~1\temp\teamviewer\version6\TeamViewer_Desktop.exe
C:\DOCUME~1\HULN~1\LOCALS~1\Temp\TeamViewer\Version6\tv_w32.exe
C:\Documents and Settings\Hulín\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Hulín\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Hulín\Plocha\RSIT.exe
C:\Program Files\trend micro\Hulín.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: (no name) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: PHPNukeEN Toolbar - {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - C:\Program Files\PHPNukeEN\tbPHP2.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: PHPNukeEN Toolbar - {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - C:\Program Files\PHPNukeEN\tbPHP2.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UpdateService\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [RemoteControl] "D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "D:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKCU\..\Run: [Skype] "C:\Documents and Settings\Hulín\Plocha\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: Kniha klipů HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Chytrý výběr - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{60BC5F53-94F2-40F0-BB93-1737C50CC50D}: NameServer = 10.0.0.138
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Stronghold Crusader Extreme Drivers Auto Removal (pr2aszab) (pr2aszab) - Cenega Czech - C:\WINDOWS\system32\pr2aszab.exe
O23 - Service: Prime95 Service - Unknown owner - D:\Program Files\Prime95\prime95.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 10346 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll [2007-03-02 1298024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-10-18 3908192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG10\avgssie.dll [2010-11-22 2732896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7c5c0f58-e061-457d-9033-77307f5ed00c}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2008-11-30 2403392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [2008-12-21 737776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-12-28 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}]
PHPNukeEN Toolbar - C:\Program Files\PHPNukeEN\tbPHP2.dll [2010-10-18 3908192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-12-28 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2008-11-30 2403392]
{dd02a4eb-4afd-4d60-99d8-e67f964ca813} - PHPNukeEN Toolbar - C:\Program Files\PHPNukeEN\tbPHP2.dll [2010-10-18 3908192]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"=D:\Program Files\QuickTime\qttask.exe [2009-01-05 413696]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UpdateService\ISUSPM.exe [2004-06-16 221184]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-04-28 61440]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2008-11-10 4366848]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2008-11-10 962112]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2008-11-10 165144]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"AVG_TRAY"=C:\Program Files\AVG\AVG10\avgtray.exe [2010-10-22 2745696]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"RemoteControl"=D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2006-11-23 56928]
"LanguageShortcut"=D:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2006-12-05 54832]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Documents and Settings\Hulín\Plocha\Phone\Skype.exe [2009-01-29 23975720]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2010-11-16 172856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-04-29 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableStatusMessages"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveSearch"=1
"NoDrives"=0
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program files\EA GAMES\Medal of Honor Pacific Assault(tm)\mohpa.exe"="D:\Program files\EA GAMES\Medal of Honor Pacific Assault(tm)\mohpa.exe:*:Enabled:Medal of Honor Pacific Assault(tm)"
"D:\Program files\MC2\Sniper Elite\SniperElite.exe"="D:\Program files\MC2\Sniper Elite\SniperElite.exe:*:Enabled:SniperElite"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"D:\Program files\Call of Duty\CoDUOMP.exe"="D:\Program files\Call of Duty\CoDUOMP.exe:*:Enabled:CoDUOMP"
"D:\Program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe"="D:\Program files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:*:Enabled:Medal of Honor Airborne™"
"D:\Program files\Microsoft Games\Age of Empires II - The Age of Kings\empires2.exe"="D:\Program files\Microsoft Games\Age of Empires II - The Age of Kings\empires2.exe:*:Enabled:Age of Empires II"
"D:\Program files\Electronic Arts\Crytek\Crysis SP Demo\Bin32\Crysis.exe"="D:\Program files\Electronic Arts\Crytek\Crysis SP Demo\Bin32\Crysis.exe:*:Enabled:Crysis_32_sp_demo"
"D:\Program files\id Software\Enemy Territory - QUAKE Wars Demo\etqw.exe"="D:\Program files\id Software\Enemy Territory - QUAKE Wars Demo\etqw.exe:*:Enabled:Enemy Territory - QUAKE Wars(TM) Demo"
"D:\Program files\id Software\Enemy Territory - QUAKE Wars Demo\etqwded.exe"="D:\Program files\id Software\Enemy Territory - QUAKE Wars Demo\etqwded.exe:*:Enabled:etqwded.exe"
"D:\Program files\Unreal Tournament 3 Demo\Binaries\UT3Demo.exe"="D:\Program files\Unreal Tournament 3 Demo\Binaries\UT3Demo.exe:*:Enabled:Unreal Tournament 3 Demo"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"D:\Program files\id Software\Enemy Territory - QUAKE Wars Demo 2\etqw.exe"="D:\Program files\id Software\Enemy Territory - QUAKE Wars Demo 2\etqw.exe:*:Enabled:Enemy Territory - QUAKE Wars(TM) Demo 2"
"D:\Program files\id Software\Enemy Territory - QUAKE Wars Demo 2\etqwded.exe"="D:\Program files\id Software\Enemy Territory - QUAKE Wars Demo 2\etqwded.exe:*:Enabled:etqwded.exe"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"D:\Program files\Firefly Studios\Stronghold Crusader\Stronghold Crusader.exe"="D:\Program files\Firefly Studios\Stronghold Crusader\Stronghold Crusader.exe:*:Enabled:Stronghold Crusader"
"D:\Program files\Call of Duty\CoDMP.exe"="D:\Program files\Call of Duty\CoDMP.exe:*:Enabled:CoDMP"
"D:\Program files\Cenega Czech\SCE\Stronghold Crusader.exe"="D:\Program files\Cenega Czech\SCE\Stronghold Crusader.exe:*:Enabled:Stronghold Crusader"
"C:\Program Files\Microsoft Games\Halo Trial\halo.exe"="C:\Program Files\Microsoft Games\Halo Trial\halo.exe:*:Enabled:Halo"
"C:\Program Files\Sony\Station\LaunchPad\LaunchPad.exe"="C:\Program Files\Sony\Station\LaunchPad\LaunchPad.exe:*:Enabled:LaunchPad"
"D:\Program files\LucasArts\Star Wars JK II Jedi Outcast\GameData\jk2mp.exe"="D:\Program files\LucasArts\Star Wars JK II Jedi Outcast\GameData\jk2mp.exe:*:Enabled:Star Wars Jedi Knight(TM): Jedi Outcast(TM)"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"D:\Program files\Microsoft Games\Zoo Tycoon 2\zt.exe"="D:\Program files\Microsoft Games\Zoo Tycoon 2\zt.exe:*:Enabled:Zoo Tycoon 2 Executable"
"C:\Program Files\Hamachi\hamachi.exe"="C:\Program Files\Hamachi\hamachi.exe:*:Enabled:Hamachi"
"D:\Stary HDD\C\Program Files\ICQ6\ICQ.exe"="D:\Stary HDD\C\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ Library"
"D:\Program files\Team17\Worms 3D\bin\Worms3D.exe"="D:\Program files\Team17\Worms 3D\bin\Worms3D.exe:*:Enabled:Worms3D"
"D:\Program files\Firefly Studios\Stronghold 2\Stronghold2.exe"="D:\Program files\Firefly Studios\Stronghold 2\Stronghold2.exe:*:Enabled:Stronghold 2"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Sony\Station\LaunchPad\_aunchPad.exe"="C:\Program Files\Sony\Station\LaunchPad\_aunchPad.exe:*:Enabled:_aunchPad"
"C:\Documents and Settings\Hulín\Plocha\Phone\Skype.exe"="C:\Documents and Settings\Hulín\Plocha\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Java\jre6\launch4j-tmp\frd.exe"="C:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\AVG\AVG10\avgnsx.exe"="C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Webový štít"
"C:\Program Files\AVG\AVG10\avgmfapx.exe"="C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:Instalátor AVG"
"C:\Program Files\AVG\AVG10\avgemcx.exe"="C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Obecná kontrola pošty"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-12-29 23:01:39 ----D---- C:\Program Files\trend micro
2010-12-29 11:37:58 ----D---- C:\Documents and Settings\Hulín\Data aplikací\BSplayer Pro
2010-12-29 11:37:58 ----D---- C:\Documents and Settings\Hulín\Data aplikací\BSplayer
2010-12-29 09:50:50 ----D---- C:\Program Files\Common Files\Adobe
2010-12-29 04:47:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2296199$
2010-12-29 03:09:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2010-12-29 03:09:25 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-12-29 03:09:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2010-12-29 03:09:07 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-12-29 03:08:58 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-12-29 03:08:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2010-12-29 03:08:41 ----HDC---- C:\WINDOWS\$NtUninstallKB981349$
2010-12-29 03:08:30 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-12-29 03:08:23 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-12-29 03:08:16 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2010-12-29 03:06:31 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-12-29 03:06:22 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-12-29 03:06:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2010-12-29 03:05:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2010-12-29 03:05:13 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2010-12-29 03:05:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2010-12-29 03:04:58 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-12-29 03:04:49 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-12-29 03:04:33 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-12-29 03:04:24 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2010-12-29 03:04:16 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2010-12-29 03:03:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2436673$
2010-12-29 03:03:40 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-12-29 03:03:18 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-12-29 03:03:09 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-12-29 03:03:00 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-12-29 03:02:43 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-12-29 03:02:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2286198$
2010-12-29 03:01:48 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-12-29 03:01:43 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-12-29 03:01:23 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-12-28 23:33:46 ----HD---- C:\$AVG
2010-12-28 22:42:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2010-12-28 22:42:20 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2010-12-28 22:42:14 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-12-28 22:42:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2259922$
2010-12-28 22:42:02 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-12-28 22:41:49 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2010-12-28 22:41:42 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-12-28 22:41:35 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2010-12-28 22:41:26 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-12-28 22:41:14 ----A---- C:\WINDOWS\system32\wmpns.dll
2010-12-28 22:40:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2010-12-28 22:39:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2010-12-28 22:39:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2010-12-28 22:38:05 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-12-28 22:37:57 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-12-28 22:37:27 ----HDC---- C:\WINDOWS\$NtUninstallKB981852$
2010-12-28 22:37:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2443685$
2010-12-28 22:28:53 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-12-28 22:22:40 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-12-28 22:22:22 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-12-28 22:18:26 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-12-28 22:18:08 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2010-12-28 22:10:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2467659$
2010-12-28 22:03:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2141007$
2010-12-28 21:54:45 ----D---- C:\Program Files\ConduitEngine
2010-12-28 21:54:45 ----A---- C:\WINDOWS\system32\ConduitEngine.tmp
2010-12-28 21:49:40 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2010-12-28 21:49:34 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-12-28 21:48:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2010-12-28 21:48:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2010-12-28 21:36:17 ----D---- C:\Documents and Settings\Hulín\Data aplikací\TeamViewer
2010-12-28 21:22:00 ----D---- C:\Documents and Settings\Hulín\Data aplikací\AVG10
2010-12-28 21:20:13 ----HD---- C:\Documents and Settings\All Users\Data aplikací\Common Files
2010-12-28 21:17:42 ----D---- C:\WINDOWS\system32\drivers\AVG
2010-12-28 21:17:42 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVG10
2010-12-28 21:14:47 ----D---- C:\Documents and Settings\Hulín\Data aplikací\VitySoft
2010-12-28 21:14:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2010-12-28 21:14:41 ----D---- C:\Program Files\Common Files\Java
2010-12-28 21:14:17 ----A---- C:\WINDOWS\system32\javaws.exe
2010-12-28 21:14:17 ----A---- C:\WINDOWS\system32\javaw.exe
2010-12-28 21:14:17 ----A---- C:\WINDOWS\system32\java.exe
2010-12-28 21:14:17 ----A---- C:\WINDOWS\system32\deployJava1.dll
2010-12-28 21:13:27 ----D---- C:\Program Files\Java
2010-12-28 21:13:00 ----D---- C:\Documents and Settings\Hulín\Data aplikací\Sun
2010-12-28 21:10:40 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-12-28 21:10:18 ----D---- C:\Documents and Settings\All Users\Data aplikací\MFAData
2010-12-28 20:48:10 ----ASH---- C:\pagefile.sys
2010-12-08 04:12:38 ----A---- C:\WINDOWS\system32\drivers\avgldx86.sys

======List of files/folders modified in the last 1 months======

2010-12-29 23:01:58 ----D---- C:\WINDOWS\Prefetch
2010-12-29 23:01:39 ----D---- C:\Program Files
2010-12-29 22:26:33 ----D---- C:\Documents and Settings\Hulín\Data aplikací\Skype
2010-12-29 22:25:20 ----D---- C:\WINDOWS\system32
2010-12-29 22:25:14 ----D---- C:\WINDOWS\system32\CatRoot2
2010-12-29 22:24:52 ----D---- C:\WINDOWS\temp
2010-12-29 22:22:25 ----D---- C:\WINDOWS
2010-12-29 22:21:08 ----D---- C:\Config.Msi
2010-12-29 19:08:56 ----SHD---- C:\WINDOWS\Installer
2010-12-29 19:08:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-12-29 15:53:05 ----D---- C:\Program Files\Google
2010-12-29 12:04:21 ----D---- C:\Program Files\CyberLink
2010-12-29 12:03:14 ----HD---- C:\Program Files\InstallShield Installation Information
2010-12-29 10:35:51 ----A---- C:\WINDOWS\NeroDigital.ini
2010-12-29 10:24:34 ----D---- C:\WINDOWS\Debug
2010-12-29 09:51:24 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-12-29 09:50:50 ----D---- C:\Program Files\Common Files
2010-12-29 04:49:59 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-12-29 04:48:03 ----HD---- C:\WINDOWS\inf
2010-12-29 04:47:59 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-12-29 04:45:11 ----RSD---- C:\WINDOWS\assembly
2010-12-29 04:41:47 ----RSD---- C:\WINDOWS\Fonts
2010-12-29 04:41:31 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-12-29 04:40:55 ----D---- C:\Program Files\Microsoft Works
2010-12-29 03:31:48 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-12-29 03:28:14 ----D---- C:\Program Files\Microsoft Silverlight
2010-12-29 03:09:41 ----D---- C:\WINDOWS\system32\drivers
2010-12-29 03:06:04 ----D---- C:\WINDOWS\system32\CatRoot
2010-12-29 03:02:52 ----D---- C:\Program Files\Outlook Express
2010-12-28 23:39:56 ----D---- C:\WINDOWS\Microsoft.NET
2010-12-28 22:45:45 ----D---- C:\WINDOWS\AppPatch
2010-12-28 22:42:33 ----HD---- C:\WINDOWS\$hf_mig$
2010-12-28 22:42:15 ----D---- C:\WINDOWS\WinSxS
2010-12-28 22:31:00 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-12-28 22:18:11 ----D---- C:\Program Files\Movie Maker
2010-12-28 22:09:37 ----D---- C:\WINDOWS\system32\cs-cz
2010-12-28 22:09:32 ----D---- C:\Program Files\Internet Explorer
2010-12-28 22:08:39 ----D---- C:\WINDOWS\ie7updates
2010-12-28 21:54:41 ----D---- C:\Program Files\PHPNukeEN
2010-12-28 21:47:08 ----A---- C:\WINDOWS\wincmd.ini
2010-12-28 21:31:50 ----D---- C:\Program Files\DAEMON Tools Toolbar
2010-12-28 21:16:23 ----D---- C:\Program Files\AVG
2010-12-28 21:06:08 ----D---- C:\Program Files\ICQ6.5
2010-12-28 20:59:19 ----SD---- C:\Documents and Settings\Hulín\Data aplikací\Microsoft
2010-12-28 20:52:51 ----RD---- C:\WINDOWS\Web
2010-12-08 21:34:08 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSEH;AVGIDSEH; C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\WINDOWS\system32\DRIVERS\avgrkx86.sys [2010-09-07 26064]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 pe3aszab;Stronghold Crusader Extreme Environment Driver (pe3aszab); C:\WINDOWS\system32\drivers\pe3aszab.sys [2008-09-08 69272]
R0 pf2aszab;Stronghold Crusader Extreme File System Driver (pf2aszab); C:\WINDOWS\system32\drivers\pf2aszab.sys [2008-09-08 83608]
R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2004-08-09 114016]
R0 prosync1;StarForce Protection Synchronization Driver v1; C:\WINDOWS\System32\drivers\prosync1.sys [2004-07-19 7040]
R0 ps7aszab;Stronghold Crusader Extreme Synchronization Driver (ps7aszab); C:\WINDOWS\system32\drivers\ps7aszab.sys [2008-09-08 68256]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2008-08-20 44944]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2004-11-25 46080]
R0 sfhlp01;StarForce Protection Helper Driver; C:\WINDOWS\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2004-10-28 6656]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\WINDOWS\System32\drivers\sfsync02.sys [2004-11-29 19648]
R0 snapman380;Acronis Snapshots Manager (Build 380); C:\WINDOWS\system32\DRIVERS\snman380.sys [2009-10-07 134272]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-06-06 721904]
R0 tdrpman147;Acronis Try&Decide and Restore Points filter (build 147); C:\WINDOWS\system32\DRIVERS\tdrpm147.sys [2009-10-07 971232]
R0 timounter;Acronis True Image Backup Archive Explorer; C:\WINDOWS\system32\DRIVERS\timntr.sys [2009-10-07 540000]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-15 76544]
R1 Avgldx86;AVG AVI Loader Driver; C:\WINDOWS\system32\DRIVERS\avgldx86.sys [2010-12-08 251728]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS\system32\DRIVERS\avgmfx86.sys [2010-09-07 34384]
R1 Avgtdix;AVG TDI Driver; C:\WINDOWS\system32\DRIVERS\avgtdix.sys [2010-11-12 299984]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-08-09 53920]
R2 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2004-07-28 9856]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2009-10-07 44704]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-04-29 3643904]
R3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys [2009-04-01 93184]
R3 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys [2010-08-19 123472]
R3 AVGIDSFilter;AVGIDSFilter; C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys [2010-08-19 30288]
R3 AVGIDSShim;AVGIDSShim; C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys [2010-08-19 26192]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-04-20 25280]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-01-30 4725760]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-03-02 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-01-03 105856]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 InCDPass;InCDPass; C:\WINDOWS\system32\drivers\InCDPass.sys []
S1 InCDRm;InCD Reader; C:\WINDOWS\system32\drivers\InCDRm.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys []
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 epmntdrv;epmntdrv; \??\C:\WINDOWS\system32\epmntdrv.sys []
S3 EuGdiDrv;EuGdiDrv; \??\C:\WINDOWS\system32\EuGdiDrv.sys []
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 HdAudAddService;ATI Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\AtiHdAud.sys [2006-12-28 84992]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-03-08 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-03-08 21568]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2008-09-15 17664]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2008-09-15 22016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2008-09-15 8064]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2008-09-15 8064]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2008-03-27 503008]
S4 InCDFs;InCD File System; C:\WINDOWS\system32\drivers\InCDFs.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2008-11-10 554264]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-04-29 602112]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-11-23 6128208]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG10\avgwdsvc.exe [2010-10-22 265400]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-12-28 153376]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-01-22 66872]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2005-08-08 167936]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-04-28 593920]
S2 pr2aszab;Stronghold Crusader Extreme Drivers Auto Removal (pr2aszab); C:\WINDOWS\system32\pr2aszab.exe [2008-09-08 415128]
S2 Prime95 Service;Prime95 Service; D:\Program Files\Prime95\prime95.exe []
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-30 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-11-11 620544]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: kontrola logu

Napsal: 29 pro 2010 23:16
od Rudy
V logu nic nebezpečného nevidím. Kde a jaký malware AVG nalezl?

Re: kontrola logu

Napsal: 29 pro 2010 23:27
od Mili
Tak nakonec to označilo za malver samotný RSIT program :)

Jinak před tím po nainstalování AVG odstranilo:

Nalezeno Tracking cookie.Tradedoubler;"c:\Documents and Settings\Hulín\Cookies\hulín@tradedoubler[2].txt";"";"29.12.2010, 19:13:14";"Soubor";"C:\Program Files\Internet Explorer\iexplore.exe"
Nalezeno Tracking cookie.Tradedoubler;"c:\Documents and Settings\Hulín\Cookies\hulín@tradedoubler[2].txt";"";"29.12.2010, 18:12:34";"Soubor";"C:\Program Files\Internet Explorer\iexplore.exe"
Trojský kůň PSW.Generic8.AGZD;"c:\System Volume Information\_restore{FA64E4C5-3A8B-492A-8A13-F774A77711E3}\RP178\A0173560.exe";"Přesunuto do trezoru";"29.12.2010, 13:57:42";"Soubor";"C:\WINDOWS\system32\svchost.exe"
Trojský kůň Generic2_c.CBQY;"c:\System Volume Information\_restore{FA64E4C5-3A8B-492A-8A13-F774A77711E3}\RP178\A0173556.exe";"Přesunuto do trezoru";"29.12.2010, 8:20:07";"Soubor";"C:\WINDOWS\system32\svchost.exe"
Trojský kůň Generic2_c.CBQY;"c:\System Volume Information\_restore{FA64E4C5-3A8B-492A-8A13-F774A77711E3}\RP178\A0173556.exe";"Infikováno";"29.12.2010, 4:18:47";"Soubor";"C:\WINDOWS\system32\svchost.exe"

Re: kontrola logu

Napsal: 30 pro 2010 17:24
od Rudy
Je celkem běžné, že se antiviry navzájem označují jako malware. AVP smazal, co měl.

Re: kontrola logu

Napsal: 30 pro 2010 20:10
od Mili
Všehno až na poslední řádek :

Trojský kůň Generic2_c.CBQY;"c:\System Volume Information\_restore{FA64E4C5-3A8B-492A-8A13-F774A77711E3}\RP17\A0173556.exe";"Infikováno";"29.12.2010, 4:18:47";"Soubor";"C:\WINDOWS\system32\svchost.exe"

tam je červenej křížek a uvedeno "infikováno" :wink:

Re: kontrola logu

Napsal: 30 pro 2010 20:46
od Rudy
OK. Vypněte obnovu systému, restartujte PCX a obnov u opět zapněte. Vir je v záloze systému a uvedeným úkonem zálohu smažete. Po zapnutí obnovy se vytvoří nová.

Re: kontrola logu

Napsal: 30 pro 2010 20:57
od Mili
Ok děkuju za rady :worship:

přeju pěkný večer a PF 2011 :guitar:

Re: kontrola logu

Napsal: 30 pro 2010 21:46
od Rudy
Totéž přeji i já vám a nemáte zač!