Stránka 1 z 1

Může to být nějaký vir?

Napsal: 07 úno 2011 20:52
od geobir
Ahojte,

ségra stahovala nějaký videa, zaseknul se komp a nešlo nic dělat. Natvrdo ho vypnula a nešel spusit. V nouzovém režimu jde, ale v normálním ne. Funkce obnovení systému vypisuje toto:
Podpis problému:
Název události problému: StartupRepairOffline
Podpis problému 01 0.0.0.0
Podpis problému 02 0.0.0.0
Podpis problému 03 unknown
Podpis problému 04 0
Podpis problému 05 unknown
Podpis problému 06 1
Podpis problému 07 unknown
Verze operačního systému: 6.1.7600.2.0.0.256.1
ID národního prostředí: 1029

Mohl by to být vir? Jinak nevím co jiného by to bylo.

Re: Může to být nějaký vir?

Napsal: 07 úno 2011 20:57
od Rudy
Pokud stahovala pouze videa, vir by to být neměl (videosoubory nejsou samy o sobě zavirovatelné). Dejte log z RSIT: http://www.viry.cz/forum/viewtopic.php?f=13&t=105895 .

Re: Může to být nějaký vir?

Napsal: 07 úno 2011 21:08
od geobir
Logfile of random's system information tool 1.08 (written by random/random)
Run by smraďoch at 2011-02-07 21:02:29
Microsoft Windows 7 Professional
System drive C: has 61 GB (26%) free of 238 GB
Total RAM: 2046 MB (73% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:02:47, on 7.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Windows\helppane.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\smraďoch\Downloads\RSIT.exe
C:\Program Files\trend micro\smraďoch.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Centrum.cz Toolbar - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O3 - Toolbar: PandoraTV Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.2\ICQ.exe" silent loginmode=4
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

--
End of file - 5842 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A}]
CentrumczToolbar BHO - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-02-12 1274160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
PandoraTV Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D5D47440-0750-463D-BAEF-A47D02414806} - Centrum.cz Toolbar - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-02-12 1274160]
{D4027C7F-154A-4066-A1AD-4243D8127440} - PandoraTV Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-03-28 1017592]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-07-28 9398888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-05-16 153136]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-05 1305408]
"ICQ"=C:\Program Files\ICQ7.2\ICQ.exe [2011-01-05 133432]

C:\Users\smraďoch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2011-02-07 21:02:30 ----D---- C:\Program Files\trend micro
2011-02-07 21:02:29 ----D---- C:\rsit
2011-02-07 20:06:08 ----A---- C:\Windows\ntbtlog.txt
2011-02-03 03:27:56 ----D---- C:\Windows\system32\Wat
2011-02-03 03:11:22 ----A---- C:\Windows\system32\msv1_0.dll
2011-02-03 03:09:43 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2011-02-03 03:09:43 ----A---- C:\Windows\system32\PresentationHost.exe
2011-02-03 03:09:43 ----A---- C:\Windows\system32\netfxperf.dll
2011-02-03 03:09:43 ----A---- C:\Windows\system32\mscoree.dll
2011-02-03 03:09:43 ----A---- C:\Windows\system32\dfshim.dll
2011-02-03 03:03:19 ----A---- C:\Windows\system32\browserchoice.exe
2011-02-03 03:02:12 ----A---- C:\Windows\system32\drivers\ks.sys
2011-02-03 03:01:46 ----D---- C:\Program Files\MSXML 4.0
2011-02-02 16:17:46 ----A---- C:\Windows\system32\mshtml.dll
2011-02-02 16:17:45 ----A---- C:\Windows\system32\iertutil.dll
2011-02-02 16:17:45 ----A---- C:\Windows\system32\ieframe.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\wininet.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\urlmon.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\mstime.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\mshtmled.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\msfeedssync.exe
2011-02-02 16:17:44 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\msfeeds.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\licmgr10.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\jsproxy.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\ieui.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\iepeers.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\iedkcs32.dll
2011-02-02 16:17:43 ----A---- C:\Windows\system32\ole32.dll
2011-02-02 16:17:39 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-02-02 16:17:32 ----A---- C:\Windows\system32\drivers\fvevol.sys
2011-02-02 16:17:31 ----A---- C:\Windows\system32\spoolsv.exe
2011-02-02 16:16:24 ----A---- C:\Windows\system32\t2embed.dll
2011-02-02 16:16:24 ----A---- C:\Windows\system32\ir32_32.dll
2011-02-02 16:16:24 ----A---- C:\Windows\system32\iccvid.dll
2011-02-02 16:16:23 ----A---- C:\Windows\system32\winlogon.exe
2011-02-02 16:16:23 ----A---- C:\Windows\explorer.exe
2011-02-02 16:16:22 ----A---- C:\Windows\system32\tzres.dll
2011-02-02 16:16:17 ----A---- C:\Windows\system32\msdri.dll
2011-02-02 16:16:17 ----A---- C:\Windows\system32\CPFilters.dll
2011-02-02 16:16:16 ----A---- C:\Windows\system32\psisdecd.dll
2011-02-02 16:15:57 ----A---- C:\Windows\system32\schannel.dll
2011-02-02 16:15:49 ----A---- C:\Windows\system32\wmicmiplugin.dll
2011-02-02 16:15:49 ----A---- C:\Windows\system32\taskschd.dll
2011-02-02 16:15:49 ----A---- C:\Windows\system32\taskeng.exe
2011-02-02 16:15:49 ----A---- C:\Windows\system32\taskcomp.dll
2011-02-02 16:15:49 ----A---- C:\Windows\system32\schtasks.exe
2011-02-02 16:15:49 ----A---- C:\Windows\system32\schedsvc.dll
2011-02-02 16:15:45 ----A---- C:\Windows\system32\msasn1.dll
2011-02-02 16:15:44 ----A---- C:\Windows\system32\lsasrv.dll
2011-02-02 16:15:44 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2011-02-02 16:15:30 ----A---- C:\Windows\system32\rtutils.dll
2011-02-02 16:15:29 ----A---- C:\Windows\system32\inetcomm.dll
2011-02-02 16:15:28 ----A---- C:\Windows\system32\odbc32.dll
2011-02-02 16:15:28 ----A---- C:\Windows\system32\msxml3.dll
2011-02-02 16:15:25 ----A---- C:\Windows\system32\ntdll.dll
2011-02-02 16:15:23 ----A---- C:\Windows\system32\winresume.exe
2011-02-02 16:15:23 ----A---- C:\Windows\system32\winload.exe
2011-02-02 16:15:23 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-02-02 16:15:23 ----A---- C:\Windows\system32\CertEnroll.dll
2011-02-02 16:14:51 ----A---- C:\Windows\system32\asycfilt.dll
2011-02-02 16:14:50 ----A---- C:\Windows\system32\comctl32.dll
2011-02-02 16:14:49 ----A---- C:\Windows\system32\mfc40u.dll
2011-02-02 16:14:49 ----A---- C:\Windows\system32\mfc40.dll
2011-02-02 16:14:02 ----A---- C:\Windows\system32\wmploc.DLL
2011-02-02 16:14:02 ----A---- C:\Windows\system32\wmp.dll
2011-02-02 16:13:56 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2011-02-02 16:13:54 ----A---- C:\Windows\system32\jscript.dll
2011-02-02 16:13:53 ----A---- C:\Windows\system32\kernel32.dll
2011-02-02 16:13:53 ----A---- C:\Windows\system32\apphelp.dll
2011-02-02 16:13:48 ----A---- C:\Windows\system32\quartz.dll
2011-02-02 16:13:48 ----A---- C:\Windows\system32\msyuv.dll
2011-02-02 16:13:48 ----A---- C:\Windows\system32\msvidc32.dll
2011-02-02 16:13:48 ----A---- C:\Windows\system32\mciavi32.dll
2011-02-02 16:13:48 ----A---- C:\Windows\system32\iyuv_32.dll
2011-02-02 16:13:48 ----A---- C:\Windows\system32\avifil32.dll
2011-02-02 16:13:47 ----A---- C:\Windows\system32\tsbyuv.dll
2011-02-02 16:13:47 ----A---- C:\Windows\system32\msrle32.dll
2011-02-02 16:13:46 ----A---- C:\Windows\system32\fontsub.dll
2011-02-02 16:13:46 ----A---- C:\Windows\system32\atmlib.dll
2011-02-02 16:13:46 ----A---- C:\Windows\system32\atmfd.dll
2011-02-02 16:13:44 ----A---- C:\Windows\system32\webio.dll
2011-02-02 16:13:44 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-02-02 16:13:43 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-02-02 16:13:40 ----A---- C:\Windows\system32\shell32.dll
2011-02-02 16:13:21 ----A---- C:\Windows\system32\srvsvc.dll
2011-02-02 16:13:21 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-02-02 16:13:21 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-02-02 16:13:21 ----A---- C:\Windows\system32\drivers\srv.sys
2011-02-02 16:13:19 ----A---- C:\Windows\system32\wmpmde.dll
2011-02-02 16:13:18 ----A---- C:\Windows\system32\consent.exe
2011-02-02 16:13:17 ----A---- C:\Windows\system32\vbscript.dll
2011-02-02 16:13:16 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2011-02-02 16:13:16 ----A---- C:\Windows\system32\secproc_isv.dll
2011-02-02 16:13:16 ----A---- C:\Windows\system32\secproc.dll
2011-02-02 16:13:16 ----A---- C:\Windows\system32\RMActivate_isv.exe
2011-02-02 16:13:16 ----A---- C:\Windows\system32\RMActivate.exe
2011-02-02 16:13:16 ----A---- C:\Windows\system32\oleaut32.dll
2011-02-02 16:13:15 ----A---- C:\Windows\system32\secproc_ssp.dll
2011-02-02 16:13:15 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2011-02-02 16:13:15 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2011-02-02 16:13:12 ----A---- C:\Windows\system32\win32k.sys
2011-02-02 16:13:12 ----A---- C:\Windows\system32\StructuredQuery.dll
2011-02-02 16:13:11 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-02-02 16:13:11 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-02-02 16:13:11 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-02-02 15:58:18 ----A---- C:\Windows\system32\wintrust.dll
2011-02-02 15:58:14 ----A---- C:\Windows\system32\cabview.dll
2011-02-02 15:48:00 ----D---- C:\Windows\cs
2011-02-02 15:41:52 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2011-02-02 15:37:46 ----D---- C:\Program Files\Windows Live
2011-02-02 15:37:21 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-02-02 15:37:21 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-02-02 15:37:21 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-02-02 15:36:38 ----A---- C:\Windows\system32\UIRibbonRes.dll
2011-02-02 15:36:38 ----A---- C:\Windows\system32\UIRibbon.dll
2011-02-02 15:36:08 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-02-02 15:36:08 ----A---- C:\Windows\system32\mf.dll
2011-02-02 15:36:07 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-02-02 15:34:59 ----D---- C:\Program Files\Common Files\Windows Live
2011-02-02 15:23:58 ----D---- C:\Program Files\Movie Maker
2011-02-02 08:26:08 ----A---- C:\Windows\Čestina do SimCity 4 Rush Hour a Delux BETA Uninstaller.exe
2011-02-02 08:22:09 ----D---- C:\Program Files\Maxis
2011-01-31 22:44:15 ----D---- C:\Users\smraďoch\AppData\Roaming\teamspeak2
2011-01-31 22:29:07 ----D---- C:\Program Files\Teamspeak2_RC2
2011-01-29 19:07:55 ----D---- C:\Program Files\GameSpy Arcade
2011-01-29 19:06:04 ----D---- C:\Program Files\FireFly Studios
2011-01-29 13:29:40 ----D---- C:\ProgramData\PopCap Games
2011-01-29 13:29:10 ----D---- C:\Program Files\Plants vs. Zombies
2011-01-28 22:00:19 ----D---- C:\ProgramData\Firefly Studios
2011-01-20 16:30:49 ----D---- C:\Program Files\Mp3 Knife
2011-01-20 13:11:52 ----D---- C:\Program Files\aTube Catcher
2011-01-18 16:01:20 ----D---- C:\ProgramData\Farm Fishes
2011-01-18 03:37:18 ----A---- C:\Windows\IsUninst.exe
2011-01-18 03:37:16 ----RASH---- C:\MSDOS.SYS
2011-01-18 03:37:16 ----RASH---- C:\IO.SYS
2011-01-18 03:21:49 ----D---- C:\ProgramData\FarmFrenzy3_Madagascar
2011-01-18 03:15:15 ----D---- C:\ProgramData\FarmFrenzy-PizzaParty
2011-01-17 16:34:35 ----D---- C:\ProgramData\FarmFrenzy3_America
2011-01-17 16:33:31 ----D---- C:\ProgramData\AlawarWrapper
2011-01-17 16:27:38 ----D---- C:\ProgramData\FarmFrenzy3_Arctica
2011-01-17 16:25:37 ----D---- C:\Program Files\Alawar
2011-01-17 13:11:58 ----D---- C:\ProgramData\FarmFrenzy3
2011-01-16 23:34:54 ----D---- C:\Program Files\Farm Frenzy
2011-01-16 00:47:44 ----D---- C:\Users\smraďoch\AppData\Roaming\Rovio
2011-01-15 20:54:51 ----SD---- C:\Program Files\HLSW
2011-01-15 20:54:51 ----D---- C:\Users\smraďoch\AppData\Roaming\HLSW
2011-01-15 20:50:56 ----D---- C:\Users\smraďoch\AppData\Roaming\WinRAR
2011-01-15 11:40:48 ----D---- C:\Windows\system32\RTCOM
2011-01-15 11:40:22 ----D---- C:\Program Files\GamePark
2011-01-15 11:40:00 ----A---- C:\Windows\system32\WavesLib.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\WavesGUILib.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\SRSWOW.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\SRSTSXT.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\SRSTSHD.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\SRSHP360.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\SFNHK.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\SFCOM.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\SFAPO.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\RtkPgExt.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\RtkCoInst.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\RtkApoApi.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\drivers\RTKVHDA.sys
2011-01-15 11:39:58 ----A---- C:\Windows\system32\RtkAPO.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\RTEEP32A.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\RTEEL32A.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\RTEEG32A.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\RTEED32A.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\RP3DHT32.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\RP3DAA32.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\MaxxAudioAPO.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\FMAPO.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSVoiceClarityDLL.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSSymmetryDLL.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSS2SpeakerDLL.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSNeoPCDLL.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSLimiterDLL.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSLFXAPO.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSGFXAPONS.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSGFXAPO.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSGainCompensatorDLL.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSBoostDLL.dll
2011-01-15 11:39:56 ----D---- C:\Program Files\Realtek
2011-01-15 11:39:56 ----A---- C:\Windows\system32\DTSBassEnhancementDLL.dll
2011-01-15 11:39:56 ----A---- C:\Windows\system32\AERTARen.dll
2011-01-15 11:39:56 ----A---- C:\Windows\system32\AERTACap.dll
2011-01-15 11:39:54 ----HD---- C:\Program Files\Temp
2011-01-15 11:39:54 ----A---- C:\Windows\RtlExUpd.dll
2011-01-15 11:39:40 ----D---- C:\Program Files\Common Files\InstallShield
2011-01-15 11:18:31 ----D---- C:\ProgramData\UAB
2011-01-15 11:17:47 ----D---- C:\ProgramData\PC Drivers HeadQuarters
2011-01-15 11:16:56 ----D---- C:\Program Files\PC Drivers HeadQuarters
2011-01-15 04:05:44 ----D---- C:\Program Files\Activision
2011-01-15 03:59:14 ----D---- C:\HRY
2011-01-15 03:43:44 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-01-15 03:43:44 ----A---- C:\Windows\system32\x3daudio1_2.dll
2011-01-15 03:43:44 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-01-15 03:43:44 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-01-15 03:43:44 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-01-15 03:43:43 ----A---- C:\Windows\system32\xinput1_3.dll
2011-01-15 03:43:43 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-01-15 03:43:43 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-01-15 03:43:43 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-01-15 03:43:43 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-01-15 03:43:42 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-01-15 03:43:42 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-01-15 03:43:42 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-01-15 03:43:42 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-01-15 03:43:42 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-01-15 03:43:42 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-01-15 03:43:42 ----A---- C:\Windows\system32\d3dx10.dll
2011-01-15 03:43:41 ----A---- C:\Windows\system32\xinput1_2.dll
2011-01-15 03:43:41 ----A---- C:\Windows\system32\xinput1_1.dll
2011-01-15 03:43:41 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-01-15 03:43:41 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-01-15 03:43:41 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-01-15 03:43:36 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-01-15 03:43:36 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-01-15 03:43:35 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-01-15 03:43:34 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-01-15 03:43:34 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-01-15 03:43:34 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-01-15 03:43:33 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-01-15 03:42:58 ----A---- C:\Windows\system32\drivers\PnkBstrK.sys
2011-01-15 03:42:48 ----A---- C:\Users\smraďoch\AppData\Roaming\PnkBstrK.sys
2011-01-15 03:42:12 ----A---- C:\Windows\system32\PnkBstrB.exe
2011-01-15 03:42:01 ----A---- C:\Windows\system32\PnkBstrA.exe
2011-01-15 03:41:59 ----A---- C:\Windows\game.ini
2011-01-15 02:25:35 ----HD---- C:\Program Files\InstallShield Installation Information
2011-01-15 02:25:34 ----D---- C:\Program Files\ICQ6Toolbar
2011-01-15 02:25:29 ----D---- C:\ProgramData\ICQ
2011-01-15 02:23:09 ----D---- C:\Users\smraďoch\AppData\Roaming\ICQ
2011-01-15 02:23:03 ----D---- C:\Program Files\ICQ7.2
2011-01-15 01:09:29 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-01-15 01:09:23 ----D---- C:\Program Files\DAEMON Tools Lite
2011-01-15 01:09:11 ----D---- C:\Users\smraďoch\AppData\Roaming\DAEMON Tools Lite
2011-01-15 01:09:11 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-01-15 01:04:04 ----D---- C:\Program Files\Ask.com
2011-01-15 01:03:50 ----D---- C:\Program Files\The KMPlayer
2011-01-15 00:53:43 ----D---- C:\Users\smraďoch\AppData\Roaming\Ahead
2011-01-15 00:53:36 ----D---- C:\ProgramData\Ahead
2011-01-15 00:53:05 ----D---- C:\ProgramData\Nero
2011-01-15 00:53:05 ----D---- C:\Program Files\Nero
2011-01-15 00:53:05 ----D---- C:\Program Files\Common Files\Ahead
2011-01-15 00:52:30 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-01-15 00:52:30 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-01-15 00:47:56 ----A---- C:\Windows\system32\msonpmon.dll
2011-01-15 00:47:10 ----D---- C:\Program Files\Microsoft Works
2011-01-15 00:46:56 ----D---- C:\Program Files\Microsoft Visual Studio
2011-01-15 00:46:56 ----D---- C:\Program Files\Common Files\DESIGNER
2011-01-15 00:46:45 ----D---- C:\Windows\PCHEALTH
2011-01-15 00:46:45 ----D---- C:\Program Files\Microsoft.NET
2011-01-15 00:45:41 ----D---- C:\Program Files\Microsoft Visual Studio 8
2011-01-15 00:45:06 ----D---- C:\ProgramData\Microsoft Help
2011-01-15 00:45:06 ----D---- C:\Program Files\Microsoft Office
2011-01-15 00:44:52 ----RHD---- C:\MSOCache
2011-01-15 00:43:12 ----D---- C:\Program Files\WinRAR
2011-01-15 00:42:57 ----A---- C:\Windows\iun6002.exe
2011-01-15 00:42:56 ----D---- C:\Program Files\Codec Pack - All In 1
2011-01-15 00:42:47 ----A---- C:\Windows\Codec Pack - All In 1 Setup Log.txt
2011-01-15 00:31:24 ----A---- C:\Windows\system32\MpSigStub.exe
2011-01-15 00:27:33 ----D---- C:\Users\smraďoch\AppData\Roaming\Macromedia
2011-01-15 00:27:33 ----D---- C:\Users\smraďoch\AppData\Roaming\Adobe
2011-01-15 00:26:10 ----D---- C:\Windows\system32\Macromed
2011-01-15 00:18:20 ----D---- C:\Users\smraďoch\AppData\Roaming\Mozilla
2011-01-15 00:17:51 ----D---- C:\Program Files\Mozilla Firefox
2011-01-15 00:16:11 ----D---- C:\ProgramData\CentrumczToolbar
2011-01-15 00:16:11 ----D---- C:\Program Files\CentrumczToolbar
2011-01-15 00:10:46 ----D---- C:\ProgramData\NVIDIA
2011-01-15 00:10:17 ----SHD---- C:\Windows\Installer
2011-01-15 00:10:09 ----D---- C:\ProgramData\NVIDIA Corporation
2011-01-15 00:09:41 ----A---- C:\Windows\system32\OpenCL.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvwgf2um.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvoglv32.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvgenco322030.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvdispco322050.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvdecodemft.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvd3dum.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvcuvid.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvcuda.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvcompiler.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvapi.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-01-15 00:08:58 ----D---- C:\Program Files\NVIDIA Corporation
2011-01-15 00:08:39 ----D---- C:\NVIDIA
2011-01-14 21:22:21 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-01-14 21:18:50 ----D---- C:\Users\smraďoch\AppData\Roaming\Identities
2011-01-14 21:18:40 ----SD---- C:\Users\smraďoch\AppData\Roaming\Microsoft
2011-01-14 21:18:40 ----D---- C:\Users\smraďoch\AppData\Roaming\Media Center Programs
2011-01-14 21:18:26 ----SHD---- C:\Recovery
2011-01-14 21:18:26 ----SHD---- C:\ProgramData\Šablony
2011-01-14 21:18:26 ----SHD---- C:\ProgramData\Plocha
2011-01-14 21:18:26 ----SHD---- C:\ProgramData\Oblíbené položky
2011-01-14 21:18:26 ----SHD---- C:\ProgramData\Nabídka Start
2011-01-14 21:18:26 ----SHD---- C:\ProgramData\Dokumenty
2011-01-14 21:18:26 ----SHD---- C:\ProgramData\Data aplikací
2011-01-14 21:15:00 ----D---- C:\Windows\SoftwareDistribution
2011-01-14 21:12:25 ----D---- C:\Windows\Prefetch
2011-01-14 21:12:12 ----ASH---- C:\pagefile.sys
2011-01-14 21:12:08 ----SHD---- C:\System Volume Information
2011-01-14 21:12:08 ----ASH---- C:\hiberfil.sys
2011-01-14 21:10:53 ----D---- C:\Windows\Panther
2011-01-14 20:58:37 ----A---- C:\Windows\system32\drivers\jraid.sys

======List of files/folders modified in the last 1 months======

2011-02-07 21:02:33 ----D---- C:\Windows\Temp
2011-02-07 21:02:30 ----RD---- C:\Program Files
2011-02-07 20:06:08 ----D---- C:\Windows
2011-02-07 20:04:44 ----D---- C:\Windows\system32\wfp
2011-02-07 20:04:42 ----D---- C:\Windows\system32\wbem
2011-02-07 20:04:03 ----D---- C:\Windows\system32\config
2011-02-07 20:03:56 ----D---- C:\Windows\winsxs
2011-02-07 20:03:56 ----D---- C:\Windows\Tasks
2011-02-07 20:03:56 ----D---- C:\Windows\system32\DriverStore
2011-02-07 20:03:56 ----D---- C:\Windows\system32\drivers
2011-02-07 20:03:56 ----D---- C:\Windows\system32\catroot2
2011-02-07 20:03:56 ----D---- C:\Windows\System32
2011-02-07 20:03:54 ----RSD---- C:\Windows\Fonts
2011-02-07 20:03:54 ----RSD---- C:\Windows\assembly
2011-02-07 20:03:54 ----D---- C:\Windows\system32\drivers\UMDF
2011-02-07 20:03:54 ----D---- C:\Windows\system32\CodeIntegrity
2011-02-07 20:03:54 ----D---- C:\Windows\inf
2011-02-07 20:03:54 ----D---- C:\Windows\AppCompat
2011-02-07 20:03:52 ----D---- C:\Program Files\Common Files\System
2011-02-07 20:03:52 ----D---- C:\Program Files\Common Files\microsoft shared
2011-02-07 20:03:46 ----D---- C:\Windows\registration
2011-02-07 20:03:32 ----D---- C:\Windows\Microsoft.NET
2011-02-03 04:08:18 ----D---- C:\Windows\rescache
2011-02-03 03:28:02 ----D---- C:\Windows\system32\cs-CZ
2011-02-03 03:28:02 ----D---- C:\Windows\ehome
2011-02-03 03:28:02 ----D---- C:\Program Files\Windows Mail
2011-02-03 03:28:01 ----D---- C:\Windows\system32\migration
2011-02-03 03:28:01 ----D---- C:\Program Files\Internet Explorer
2011-02-03 03:28:00 ----D---- C:\Windows\system32\Boot
2011-02-03 03:27:59 ----D---- C:\Windows\AppPatch
2011-02-03 03:27:59 ----D---- C:\Program Files\Windows Media Player
2011-02-03 03:11:28 ----D---- C:\Windows\system32\catroot
2011-02-02 15:39:26 ----SD---- C:\ProgramData\Microsoft
2011-02-02 15:36:47 ----D---- C:\Windows\Logs
2011-02-02 15:34:59 ----D---- C:\Program Files\Common Files
2011-01-29 19:27:52 ----D---- C:\Windows\Downloaded Program Files
2011-01-29 19:12:33 ----SHD---- C:\$Recycle.Bin
2011-01-29 13:29:40 ----HD---- C:\ProgramData
2011-01-25 21:06:30 ----D---- C:\Windows\system32\NDF
2011-01-21 17:47:09 ----D---- C:\Windows\LiveKernelReports
2011-01-20 22:08:16 ----D---- C:\Windows\system32\wdi
2011-01-15 10:46:10 ----D---- C:\Windows\debug
2011-01-15 03:42:00 ----D---- C:\Windows\system32\LogFiles
2011-01-15 01:04:05 ----D---- C:\Windows\system32\Tasks
2011-01-15 00:47:06 ----D---- C:\Program Files\MSBuild
2011-01-15 00:46:55 ----D---- C:\Windows\ShellNew
2011-01-15 00:45:33 ----A---- C:\Windows\win.ini
2011-01-15 00:31:11 ----D---- C:\Windows\system32\restore
2011-01-15 00:10:23 ----D---- C:\Windows\Help
2011-01-14 21:18:38 ----RD---- C:\Users
2011-01-14 21:18:26 ----D---- C:\Program Files\Windows NT
2011-01-14 21:14:29 ----D---- C:\Windows\system32\sysprep
2011-01-14 21:12:42 ----D---- C:\Windows\CSC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2009-08-13 96368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-15 218176]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 32bitový systém Windows Vista; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2010-07-28 3154920]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-07-13 1068032]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

S2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-03-28 246520]
S2 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [2010-10-16 600680]
S2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2011-01-15 75136]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
S2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-16 271920]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-02-03 1343400]

-----------------EOF-----------------

Re: Může to být nějaký vir?

Napsal: 07 úno 2011 21:34
od Rudy
Ještě poprosím o log z ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware

Re: Může to být nějaký vir?

Napsal: 07 úno 2011 21:54
od geobir
ComboFix 11-02-06.02 - smraďoch 07.02.2011 21:45:30.1.2 - x86 NETWORK
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2046.1593 [GMT 1:00]
Spuštěný z: c:\users\smraďoch\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.

((((((((((((((((((((((((( Soubory vytvořené od 2011-01-07 do 2011-02-07 )))))))))))))))))))))))))))))))
.

2011-02-07 20:49 . 2011-02-07 20:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-02-07 20:02 . 2011-02-07 20:02 -------- d-----w- c:\program files\trend micro
2011-02-07 20:02 . 2011-02-07 20:02 -------- d-----w- C:\rsit
2011-02-07 19:08 . 2010-11-16 11:01 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0E718D67-6637-40E6-9909-3ECA8A3F51CC}\mpengine.dll
2011-02-03 02:27 . 2011-02-03 02:27 -------- d-----w- c:\windows\system32\Wat
2011-02-03 02:11 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2011-02-03 02:09 . 2009-11-25 11:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-02-03 02:09 . 2009-11-25 11:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-02-03 02:09 . 2009-11-25 11:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-02-03 02:09 . 2009-11-25 11:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-02-03 02:09 . 2009-11-25 11:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-02-03 02:03 . 2011-02-03 02:03 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2011-02-03 02:03 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe
2011-02-03 02:02 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2011-02-03 02:01 . 2011-02-03 02:01 -------- d-----w- c:\program files\MSXML 4.0
2011-02-02 15:16 . 2010-10-12 04:25 516096 ----a-w- c:\program files\Windows Mail\wab.exe
2011-02-02 15:16 . 2010-08-26 04:39 109056 ----a-w- c:\windows\system32\t2embed.dll
2011-02-02 15:16 . 2010-07-29 06:30 197632 ----a-w- c:\windows\system32\ir32_32.dll
2011-02-02 15:16 . 2010-07-29 06:30 82944 ----a-w- c:\windows\system32\iccvid.dll
2011-02-02 15:16 . 2009-10-31 05:45 2614272 ----a-w- c:\windows\explorer.exe
2011-02-02 15:16 . 2009-10-28 06:17 285696 ----a-w- c:\windows\system32\winlogon.exe
2011-02-02 15:16 . 2010-10-27 04:32 2048 ----a-w- c:\windows\system32\tzres.dll
2011-02-02 15:16 . 2010-08-04 06:18 641536 ----a-w- c:\windows\system32\CPFilters.dll
2011-02-02 15:16 . 2010-08-04 06:17 417792 ----a-w- c:\windows\system32\msdri.dll
2011-02-02 15:16 . 2010-08-04 06:15 204288 ----a-w- c:\windows\system32\MSNP.ax
2011-02-02 15:16 . 2010-08-04 06:15 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2011-02-02 15:16 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2011-02-02 15:14 . 2010-03-05 07:42 67584 ----a-w- c:\windows\system32\asycfilt.dll
2011-02-02 15:14 . 2010-08-21 05:33 530432 ----a-w- c:\windows\system32\comctl32.dll
2011-02-02 15:14 . 2010-08-31 04:32 954752 ----a-w- c:\windows\system32\mfc40.dll
2011-02-02 15:14 . 2010-08-31 04:32 954288 ----a-w- c:\windows\system32\mfc40u.dll
2011-02-02 15:14 . 2010-09-01 04:26 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2011-02-02 15:14 . 2010-09-01 04:23 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2011-02-02 14:58 . 2009-12-29 06:55 172032 ----a-w- c:\windows\system32\wintrust.dll
2011-02-02 14:58 . 2010-01-09 06:52 132608 ----a-w- c:\windows\system32\cabview.dll
2011-02-02 14:48 . 2011-02-02 14:48 -------- d-----w- c:\windows\cs
2011-02-02 14:41 . 2011-02-02 14:41 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-02-02 14:37 . 2011-02-02 14:40 -------- d-----w- c:\program files\Windows Live
2011-02-02 14:37 . 2009-09-04 16:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2011-02-02 14:37 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2011-02-02 14:37 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2011-02-02 14:36 . 2010-08-11 04:44 2983424 ----a-w- c:\windows\system32\UIRibbon.dll
2011-02-02 14:36 . 2010-08-11 04:35 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-02-02 14:36 . 2010-05-23 10:11 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-02-02 14:36 . 2010-05-23 10:11 3181568 ----a-w- c:\windows\system32\mf.dll
2011-02-02 14:36 . 2010-05-23 10:15 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2011-02-02 14:34 . 2011-02-02 14:34 -------- d-----w- c:\program files\Common Files\Windows Live
2011-02-02 07:26 . 2011-02-02 07:26 151515 ----a-w- c:\windows\Čestina do SimCity 4 Rush Hour a Delux BETA Uninstaller.exe
2011-02-02 07:22 . 2011-02-02 07:22 -------- d-----w- c:\program files\Maxis
2011-01-31 21:44 . 2011-01-31 21:44 34064 ----a-w- c:\windows\system32\lhacm.acm
2011-01-31 21:29 . 2011-01-31 21:44 -------- d-----w- c:\program files\Teamspeak2_RC2
2011-01-29 18:07 . 2011-01-29 18:08 -------- d-----w- c:\program files\GameSpy Arcade
2011-01-29 18:06 . 2011-01-29 18:06 -------- d-----w- c:\program files\FireFly Studios
2011-01-29 12:29 . 2011-01-29 12:29 -------- d-----w- c:\programdata\PopCap Games
2011-01-29 12:29 . 2011-01-29 12:29 -------- d-----w- c:\program files\Plants vs. Zombies
2011-01-28 21:00 . 2011-01-28 21:00 -------- d-----w- c:\programdata\Firefly Studios
2011-01-27 17:33 . 2009-07-14 01:15 90624 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\HPZPPWN7.DLL
2011-01-20 15:30 . 2011-01-20 15:30 -------- d-----w- c:\program files\Mp3 Knife
2011-01-20 15:30 . 2004-04-13 05:57 152848 ----a-w- c:\windows\system32\comdlg32.ocx
2011-01-20 15:30 . 2004-04-13 05:57 609584 ----a-w- c:\windows\system32\comctl32.ocx
2011-01-20 12:11 . 2011-01-20 12:12 -------- d-----w- c:\program files\aTube Catcher
2011-01-18 15:01 . 2011-01-18 15:01 -------- d-----w- c:\programdata\Farm Fishes
2011-01-18 02:37 . 1997-08-26 11:06 315904 ----a-w- c:\windows\IsUninst.exe
2011-01-18 02:15 . 2011-01-18 02:16 -------- d-----w- c:\programdata\FarmFrenzy-PizzaParty
2011-01-17 15:33 . 2011-01-18 02:21 -------- d-----w- c:\programdata\AlawarWrapper
2011-01-17 15:25 . 2011-01-18 23:21 -------- d-----w- c:\program files\Alawar
2011-01-17 12:11 . 2011-01-17 12:12 -------- d-----w- c:\programdata\FarmFrenzy3
2011-01-16 22:34 . 2011-01-16 22:34 -------- d-----w- c:\program files\Farm Frenzy
2011-01-15 20:56 . 2011-02-03 21:03 271200 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-01-15 19:54 . 2011-01-15 19:54 -------- d-s---w- c:\program files\HLSW
2011-01-15 10:40 . 2011-01-15 10:40 -------- d-----w- c:\windows\system32\RTCOM
2011-01-15 10:40 . 2011-01-15 10:40 -------- d-----w- c:\program files\GamePark
2011-01-15 10:40 . 2009-11-18 17:42 1783056 ----a-w- c:\windows\system32\WavesLib.dll
2011-01-15 10:18 . 2011-01-15 10:18 -------- d-----w- c:\programdata\UAB
2011-01-15 10:17 . 2011-01-15 10:17 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2011-01-15 10:16 . 2011-01-15 10:16 -------- d-----w- c:\program files\PC Drivers HeadQuarters
2011-01-15 03:05 . 2011-02-02 00:13 -------- d-----w- c:\program files\Activision
2011-01-15 02:59 . 2011-02-02 14:03 -------- d-----w- C:\HRY
2011-01-15 02:42 . 2011-02-03 21:03 138160 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-01-15 02:42 . 2011-02-03 21:03 271200 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-01-15 02:42 . 2011-02-03 21:03 103736 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-01-15 02:42 . 2011-01-15 11:57 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-01-15 01:25 . 2011-01-29 18:06 -------- d--h--w- c:\program files\InstallShield Installation Information
2011-01-15 01:25 . 2011-01-15 01:25 -------- d-----w- c:\program files\ICQ6Toolbar
2011-01-15 01:25 . 2011-01-15 01:25 -------- d-----w- c:\programdata\ICQ
2011-01-15 01:23 . 2011-01-29 18:27 -------- d-----w- c:\program files\ICQ7.2
2011-01-15 00:09 . 2011-01-15 00:09 218176 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-01-15 00:09 . 2011-01-15 00:09 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-01-15 00:09 . 2011-01-15 00:09 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-01-15 00:04 . 2011-01-15 00:04 -------- d-----w- c:\program files\Ask.com
2011-01-15 00:03 . 2011-01-15 00:04 -------- d-----w- c:\program files\The KMPlayer
2011-01-14 23:53 . 2011-01-14 23:53 -------- d-----w- c:\programdata\Ahead
2011-01-14 23:53 . 2011-01-14 23:53 -------- d-----w- c:\program files\Common Files\Ahead
2011-01-14 23:53 . 2011-01-14 23:53 -------- d-----w- c:\programdata\Nero
2011-01-14 23:53 . 2011-01-14 23:53 -------- d-----w- c:\program files\Nero
2011-01-14 23:47 . 2006-10-26 18:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2011-01-14 23:47 . 2006-10-26 18:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2011-01-14 23:47 . 2011-02-07 19:03 -------- d-----w- c:\program files\Microsoft Works
2011-01-14 23:46 . 2011-01-14 23:46 -------- d-----w- c:\windows\PCHEALTH
2011-01-14 23:46 . 2011-01-14 23:46 -------- d-----w- c:\program files\Microsoft.NET
2011-01-14 23:45 . 2011-01-14 23:45 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2011-01-14 23:45 . 2011-02-07 19:03 -------- d-----w- c:\programdata\Microsoft Help
2011-01-14 23:44 . 2011-01-14 23:44 -------- d-----r- C:\MSOCache
2011-01-14 23:42 . 2011-01-14 23:42 737280 ----a-w- c:\windows\iun6002.exe
2011-01-14 23:42 . 2011-01-14 23:42 -------- d-----w- c:\program files\Codec Pack - All In 1
2011-01-14 23:31 . 2010-10-19 09:41 222080 ----a-w- c:\windows\system32\MpSigStub.exe
2011-01-14 23:26 . 2011-01-14 23:26 -------- d-----w- c:\windows\system32\Macromed
2011-01-14 23:16 . 2011-01-14 23:18 -------- d-----w- c:\programdata\CentrumczToolbar
2011-01-14 23:16 . 2011-01-14 23:16 -------- d-----w- c:\program files\CentrumczToolbar
2011-01-14 23:10 . 2011-02-07 19:29 -------- d-----w- c:\programdata\NVIDIA
2011-01-14 23:10 . 2011-02-07 19:03 -------- d-sh--w- c:\windows\Installer
2011-01-14 23:10 . 2011-01-14 23:10 -------- d-----w- c:\programdata\NVIDIA Corporation
2011-01-14 23:08 . 2011-01-14 23:10 -------- d-----w- c:\program files\NVIDIA Corporation
2011-01-14 23:08 . 2011-01-14 23:08 -------- d-----w- C:\NVIDIA
2011-01-14 20:21 . 2011-02-07 19:03 -------- d-----w- c:\windows\system32\wbem\Performance
2011-01-14 20:10 . 2011-01-14 20:18 -------- d-----w- c:\windows\Panther
2011-01-14 19:58 . 2009-08-13 15:10 96368 ----a-w- c:\windows\system32\drivers\jraid.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-15 03:10 . 2011-01-15 02:42 22328 ----a-w- c:\users\smraďoch\AppData\Roaming\PnkBstrK.sys
2011-01-15 03:10 . 2011-01-15 02:42 22328 ----a-w- c:\users\smraďoch\AppData\Roaming\PnkBstrK.sys
2010-11-10 01:28 . 2010-11-10 01:28 301936 ----a-w- c:\windows\WLXPGSS.SCR
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 21:44 1400712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-05 1305408]
"ICQ"="c:\program files\ICQ7.2\ICQ.exe" [2011-01-05 133432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-07-28 9398888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]

c:\users\smraÔoch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-03-28 246520]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-02-03 1343400]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-15 218176]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 32bitový systém Windows Vista;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]

.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\users\smraďoch\AppData\Roaming\Mozilla\Firefox\Profiles\5d6ubqux.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.4&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: PandoraTV Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKLM-RunOnce-<NO NAME> - (no file)
AddRemove-Farm Frenzy 3 - c:\program files\Alawar\FarmFrenzy3\Uninstall.exe
AddRemove-Worms Armageddon - c:\team17\Worms Armageddon\Uninst.isu


.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-02-07 21:51:24
ComboFix-quarantined-files.txt 2011-02-07 20:51

Před spuštěním: Volných bajtů: 63 524 188 160
Po spuštění: Volných bajtů: 63 875 244 032

- - End Of File - - 9B6C52E3D771109F6C827742901FFC4C

Re: Může to být nějaký vir?

Napsal: 07 úno 2011 22:00
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Folder::
c:\program files\Ask.com

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek

Re: Může to být nějaký vir?

Napsal: 07 úno 2011 22:13
od geobir
ComboFix 11-02-06.02 - smraďoch 07.02.2011 22:07:46.2.2 - x86 NETWORK
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2046.1565 [GMT 1:00]
Spuštěný z: c:\users\smraďoch\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\smraďoch\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_f95b.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe

.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-07 do 2011-02-07 )))))))))))))))))))))))))))))))
.

2011-02-07 21:10 . 2011-02-07 21:10 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-02-07 20:02 . 2011-02-07 20:02 -------- d-----w- c:\program files\trend micro
2011-02-07 20:02 . 2011-02-07 20:02 -------- d-----w- C:\rsit
2011-02-07 19:08 . 2010-11-16 11:01 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0E718D67-6637-40E6-9909-3ECA8A3F51CC}\mpengine.dll
2011-02-03 02:27 . 2011-02-03 02:27 -------- d-----w- c:\windows\system32\Wat
2011-02-03 02:11 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2011-02-03 02:09 . 2009-11-25 11:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-02-03 02:09 . 2009-11-25 11:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-02-03 02:09 . 2009-11-25 11:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-02-03 02:09 . 2009-11-25 11:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-02-03 02:09 . 2009-11-25 11:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-02-03 02:03 . 2011-02-03 02:03 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2011-02-03 02:03 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe
2011-02-03 02:02 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2011-02-03 02:01 . 2011-02-03 02:01 -------- d-----w- c:\program files\MSXML 4.0
2011-02-02 15:16 . 2010-10-12 04:25 516096 ----a-w- c:\program files\Windows Mail\wab.exe
2011-02-02 15:16 . 2010-08-26 04:39 109056 ----a-w- c:\windows\system32\t2embed.dll
2011-02-02 15:16 . 2010-07-29 06:30 197632 ----a-w- c:\windows\system32\ir32_32.dll
2011-02-02 15:16 . 2010-07-29 06:30 82944 ----a-w- c:\windows\system32\iccvid.dll
2011-02-02 15:16 . 2009-10-31 05:45 2614272 ----a-w- c:\windows\explorer.exe
2011-02-02 15:16 . 2009-10-28 06:17 285696 ----a-w- c:\windows\system32\winlogon.exe
2011-02-02 15:16 . 2010-10-27 04:32 2048 ----a-w- c:\windows\system32\tzres.dll
2011-02-02 15:16 . 2010-08-04 06:18 641536 ----a-w- c:\windows\system32\CPFilters.dll
2011-02-02 15:16 . 2010-08-04 06:17 417792 ----a-w- c:\windows\system32\msdri.dll
2011-02-02 15:16 . 2010-08-04 06:15 204288 ----a-w- c:\windows\system32\MSNP.ax
2011-02-02 15:16 . 2010-08-04 06:15 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2011-02-02 15:16 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2011-02-02 15:14 . 2010-03-05 07:42 67584 ----a-w- c:\windows\system32\asycfilt.dll
2011-02-02 15:14 . 2010-08-21 05:33 530432 ----a-w- c:\windows\system32\comctl32.dll
2011-02-02 15:14 . 2010-08-31 04:32 954752 ----a-w- c:\windows\system32\mfc40.dll
2011-02-02 15:14 . 2010-08-31 04:32 954288 ----a-w- c:\windows\system32\mfc40u.dll
2011-02-02 15:14 . 2010-09-01 04:26 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2011-02-02 15:14 . 2010-09-01 04:23 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2011-02-02 14:58 . 2009-12-29 06:55 172032 ----a-w- c:\windows\system32\wintrust.dll
2011-02-02 14:58 . 2010-01-09 06:52 132608 ----a-w- c:\windows\system32\cabview.dll
2011-02-02 14:48 . 2011-02-02 14:48 -------- d-----w- c:\windows\cs
2011-02-02 14:41 . 2011-02-02 14:41 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-02-02 14:37 . 2011-02-02 14:40 -------- d-----w- c:\program files\Windows Live
2011-02-02 14:37 . 2009-09-04 16:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2011-02-02 14:37 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2011-02-02 14:37 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2011-02-02 14:36 . 2010-08-11 04:44 2983424 ----a-w- c:\windows\system32\UIRibbon.dll
2011-02-02 14:36 . 2010-08-11 04:35 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-02-02 14:36 . 2010-05-23 10:11 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-02-02 14:36 . 2010-05-23 10:11 3181568 ----a-w- c:\windows\system32\mf.dll
2011-02-02 14:36 . 2010-05-23 10:15 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2011-02-02 14:34 . 2011-02-02 14:34 -------- d-----w- c:\program files\Common Files\Windows Live
2011-02-02 07:26 . 2011-02-02 07:26 151515 ----a-w- c:\windows\Čestina do SimCity 4 Rush Hour a Delux BETA Uninstaller.exe
2011-02-02 07:22 . 2011-02-02 07:22 -------- d-----w- c:\program files\Maxis
2011-01-31 21:44 . 2011-01-31 21:44 34064 ----a-w- c:\windows\system32\lhacm.acm
2011-01-31 21:29 . 2011-01-31 21:44 -------- d-----w- c:\program files\Teamspeak2_RC2
2011-01-29 18:07 . 2011-01-29 18:08 -------- d-----w- c:\program files\GameSpy Arcade
2011-01-29 18:06 . 2011-01-29 18:06 -------- d-----w- c:\program files\FireFly Studios
2011-01-29 12:29 . 2011-01-29 12:29 -------- d-----w- c:\programdata\PopCap Games
2011-01-29 12:29 . 2011-01-29 12:29 -------- d-----w- c:\program files\Plants vs. Zombies
2011-01-28 21:00 . 2011-01-28 21:00 -------- d-----w- c:\programdata\Firefly Studios
2011-01-27 17:33 . 2009-07-14 01:15 90624 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\HPZPPWN7.DLL
2011-01-20 15:30 . 2011-01-20 15:30 -------- d-----w- c:\program files\Mp3 Knife
2011-01-20 15:30 . 2004-04-13 05:57 152848 ----a-w- c:\windows\system32\comdlg32.ocx
2011-01-20 15:30 . 2004-04-13 05:57 609584 ----a-w- c:\windows\system32\comctl32.ocx
2011-01-20 12:11 . 2011-01-20 12:12 -------- d-----w- c:\program files\aTube Catcher
2011-01-18 15:01 . 2011-01-18 15:01 -------- d-----w- c:\programdata\Farm Fishes
2011-01-18 02:37 . 1997-08-26 11:06 315904 ----a-w- c:\windows\IsUninst.exe
2011-01-18 02:15 . 2011-01-18 02:16 -------- d-----w- c:\programdata\FarmFrenzy-PizzaParty
2011-01-17 15:33 . 2011-01-18 02:21 -------- d-----w- c:\programdata\AlawarWrapper
2011-01-17 15:25 . 2011-01-18 23:21 -------- d-----w- c:\program files\Alawar
2011-01-17 12:11 . 2011-01-17 12:12 -------- d-----w- c:\programdata\FarmFrenzy3
2011-01-16 22:34 . 2011-01-16 22:34 -------- d-----w- c:\program files\Farm Frenzy
2011-01-15 20:56 . 2011-02-03 21:03 271200 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-01-15 19:54 . 2011-01-15 19:54 -------- d-s---w- c:\program files\HLSW
2011-01-15 10:40 . 2011-01-15 10:40 -------- d-----w- c:\windows\system32\RTCOM
2011-01-15 10:40 . 2011-01-15 10:40 -------- d-----w- c:\program files\GamePark
2011-01-15 10:40 . 2009-11-18 17:42 1783056 ----a-w- c:\windows\system32\WavesLib.dll
2011-01-15 10:18 . 2011-01-15 10:18 -------- d-----w- c:\programdata\UAB
2011-01-15 10:17 . 2011-01-15 10:17 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2011-01-15 10:16 . 2011-01-15 10:16 -------- d-----w- c:\program files\PC Drivers HeadQuarters
2011-01-15 03:05 . 2011-02-02 00:13 -------- d-----w- c:\program files\Activision
2011-01-15 02:59 . 2011-02-02 14:03 -------- d-----w- C:\HRY
2011-01-15 02:42 . 2011-02-03 21:03 138160 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-01-15 02:42 . 2011-02-03 21:03 271200 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-01-15 02:42 . 2011-02-03 21:03 103736 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-01-15 02:42 . 2011-01-15 11:57 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-01-15 01:25 . 2011-01-29 18:06 -------- d--h--w- c:\program files\InstallShield Installation Information
2011-01-15 01:25 . 2011-01-15 01:25 -------- d-----w- c:\program files\ICQ6Toolbar
2011-01-15 01:25 . 2011-01-15 01:25 -------- d-----w- c:\programdata\ICQ
2011-01-15 01:23 . 2011-01-29 18:27 -------- d-----w- c:\program files\ICQ7.2
2011-01-15 00:09 . 2011-01-15 00:09 218176 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-01-15 00:09 . 2011-01-15 00:09 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-01-15 00:09 . 2011-01-15 00:09 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-01-15 00:03 . 2011-01-15 00:04 -------- d-----w- c:\program files\The KMPlayer
2011-01-14 23:53 . 2011-01-14 23:53 -------- d-----w- c:\programdata\Ahead
2011-01-14 23:53 . 2011-01-14 23:53 -------- d-----w- c:\program files\Common Files\Ahead
2011-01-14 23:53 . 2011-01-14 23:53 -------- d-----w- c:\programdata\Nero
2011-01-14 23:53 . 2011-01-14 23:53 -------- d-----w- c:\program files\Nero
2011-01-14 23:47 . 2006-10-26 18:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2011-01-14 23:47 . 2006-10-26 18:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2011-01-14 23:47 . 2011-02-07 19:03 -------- d-----w- c:\program files\Microsoft Works
2011-01-14 23:46 . 2011-01-14 23:46 -------- d-----w- c:\windows\PCHEALTH
2011-01-14 23:46 . 2011-01-14 23:46 -------- d-----w- c:\program files\Microsoft.NET
2011-01-14 23:45 . 2011-01-14 23:45 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2011-01-14 23:45 . 2011-02-07 19:03 -------- d-----w- c:\programdata\Microsoft Help
2011-01-14 23:44 . 2011-01-14 23:44 -------- d-----r- C:\MSOCache
2011-01-14 23:42 . 2011-01-14 23:42 737280 ----a-w- c:\windows\iun6002.exe
2011-01-14 23:42 . 2011-01-14 23:42 -------- d-----w- c:\program files\Codec Pack - All In 1
2011-01-14 23:31 . 2010-10-19 09:41 222080 ----a-w- c:\windows\system32\MpSigStub.exe
2011-01-14 23:26 . 2011-01-14 23:26 -------- d-----w- c:\windows\system32\Macromed
2011-01-14 23:16 . 2011-01-14 23:18 -------- d-----w- c:\programdata\CentrumczToolbar
2011-01-14 23:16 . 2011-01-14 23:16 -------- d-----w- c:\program files\CentrumczToolbar
2011-01-14 23:10 . 2011-02-07 19:29 -------- d-----w- c:\programdata\NVIDIA
2011-01-14 23:10 . 2011-02-07 19:03 -------- d-sh--w- c:\windows\Installer
2011-01-14 23:10 . 2011-01-14 23:10 -------- d-----w- c:\programdata\NVIDIA Corporation
2011-01-14 23:08 . 2011-01-14 23:10 -------- d-----w- c:\program files\NVIDIA Corporation
2011-01-14 23:08 . 2011-01-14 23:08 -------- d-----w- C:\NVIDIA
2011-01-14 20:21 . 2011-02-07 19:03 -------- d-----w- c:\windows\system32\wbem\Performance
2011-01-14 20:10 . 2011-01-14 20:18 -------- d-----w- c:\windows\Panther
2011-01-14 19:58 . 2009-08-13 15:10 96368 ----a-w- c:\windows\system32\drivers\jraid.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-15 03:10 . 2011-01-15 02:42 22328 ----a-w- c:\users\smraďoch\AppData\Roaming\PnkBstrK.sys
2011-01-15 03:10 . 2011-01-15 02:42 22328 ----a-w- c:\users\smraďoch\AppData\Roaming\PnkBstrK.sys
2010-11-10 01:28 . 2010-11-10 01:28 301936 ----a-w- c:\windows\WLXPGSS.SCR
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-05 1305408]
"ICQ"="c:\program files\ICQ7.2\ICQ.exe" [2011-01-05 133432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-07-28 9398888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]

c:\users\smraÔoch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-03-28 246520]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-02-03 1343400]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-15 218176]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 32bitový systém Windows Vista;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]

.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\users\smraďoch\AppData\Roaming\Mozilla\Firefox\Profiles\5d6ubqux.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.4&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: PandoraTV Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKLM-RunOnce-<NO NAME> - (no file)


.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-02-07 22:12:11
ComboFix-quarantined-files.txt 2011-02-07 21:12
ComboFix2.txt 2011-02-07 20:51

Před spuštěním: Volných bajtů: 63 937 437 696
Po spuštění: Volných bajtů: 63 866 396 672

- - End Of File - - 13F51BDC38D2B324B3D685887AC08034

Re: Může to být nějaký vir?

Napsal: 07 úno 2011 22:27
od geobir
po tomto logu jsem pc restartoval a vypadá to, že vše běží bez problémů.... takže mnohokrát děkuji... :-)

Re: Může to být nějaký vir?

Napsal: 07 úno 2011 22:56
od Rudy
Nemáte zač!

Re: Může to být nějaký vir?

Napsal: 08 úno 2011 06:30
od geobir
PC jsem poté zapnul již normálně, ale asi 2x během 3 hodin mi vyskčilo okno s upozorněním, že přestal pracovat ovladač grafiky, ale že vše bylo opět obnoveno. Ráno po zapnutí pc je vše jako včera. Při zapnutí v normálním režimu se na monitoru oběví pouze pruhy a nic víc a v Nouzovém režimu vše běží, včetně internetových stránek. Mohli by jste mi prosím ještě poradit???

sputstil jsem jako včera ten program a vygeneroval ten log, tak ho sem vkládám

Re: Může to být nějaký vir?

Napsal: 08 úno 2011 06:31
od geobir
Logfile of random's system information tool 1.08 (written by random/random)
Run by smraďoch at 2011-02-08 06:24:11
Microsoft Windows 7 Professional
System drive C: has 62 GB (26%) free of 238 GB
Total RAM: 2046 MB (69% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:24:16, on 8.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Windows\helppane.exe
C:\Users\smraďoch\Downloads\RSIT.exe
C:\Program Files\trend micro\smraďoch.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Centrum.cz Toolbar - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.2\ICQ.exe" silent loginmode=4
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PEVSystemStart - Unknown owner - C:\ComboFix\PEV.cfxxe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

--
End of file - 4934 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A}]
CentrumczToolbar BHO - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-02-12 1274160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D5D47440-0750-463D-BAEF-A47D02414806} - Centrum.cz Toolbar - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-02-12 1274160]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-03-28 1017592]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-07-28 9398888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-05-16 153136]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-05 1305408]
"ICQ"=C:\Program Files\ICQ7.2\ICQ.exe [2011-01-05 133432]

C:\Users\smraďoch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2009-07-14 229376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2011-02-08 03:03:32 ----SHD---- C:\Config.Msi
2011-02-08 01:05:06 ----SD---- C:\ComboFix
2011-02-08 01:04:49 ----A---- C:\Windows\SWXCACLS.exe
2011-02-07 22:46:27 ----A---- C:\Windows\system32\MRT.exe
2011-02-07 22:41:33 ----D---- C:\Windows\Minidump
2011-02-07 22:12:14 ----SHD---- C:\$RECYCLE.BIN
2011-02-07 22:12:13 ----D---- C:\Windows\temp
2011-02-07 21:42:47 ----A---- C:\Windows\zip.exe
2011-02-07 21:42:47 ----A---- C:\Windows\SWSC.exe
2011-02-07 21:42:47 ----A---- C:\Windows\SWREG.exe
2011-02-07 21:42:47 ----A---- C:\Windows\sed.exe
2011-02-07 21:42:47 ----A---- C:\Windows\PEV.exe
2011-02-07 21:42:47 ----A---- C:\Windows\NIRCMD.exe
2011-02-07 21:42:47 ----A---- C:\Windows\MBR.exe
2011-02-07 21:42:47 ----A---- C:\Windows\grep.exe
2011-02-07 21:42:42 ----D---- C:\Windows\ERDNT
2011-02-07 21:42:36 ----D---- C:\Qoobox
2011-02-07 21:02:30 ----D---- C:\Program Files\trend micro
2011-02-07 21:02:29 ----D---- C:\rsit
2011-02-07 20:06:08 ----A---- C:\Windows\ntbtlog.txt
2011-02-03 03:27:56 ----D---- C:\Windows\system32\Wat
2011-02-03 03:11:22 ----A---- C:\Windows\system32\msv1_0.dll
2011-02-03 03:09:43 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2011-02-03 03:09:43 ----A---- C:\Windows\system32\PresentationHost.exe
2011-02-03 03:09:43 ----A---- C:\Windows\system32\netfxperf.dll
2011-02-03 03:09:43 ----A---- C:\Windows\system32\mscoree.dll
2011-02-03 03:09:43 ----A---- C:\Windows\system32\dfshim.dll
2011-02-03 03:03:19 ----A---- C:\Windows\system32\browserchoice.exe
2011-02-03 03:02:12 ----A---- C:\Windows\system32\drivers\ks.sys
2011-02-03 03:01:46 ----D---- C:\Program Files\MSXML 4.0
2011-02-02 16:17:46 ----A---- C:\Windows\system32\mshtml.dll
2011-02-02 16:17:45 ----A---- C:\Windows\system32\iertutil.dll
2011-02-02 16:17:45 ----A---- C:\Windows\system32\ieframe.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\wininet.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\urlmon.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\mstime.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\mshtmled.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\msfeedssync.exe
2011-02-02 16:17:44 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\msfeeds.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\licmgr10.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\jsproxy.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\ieui.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\iepeers.dll
2011-02-02 16:17:44 ----A---- C:\Windows\system32\iedkcs32.dll
2011-02-02 16:17:43 ----A---- C:\Windows\system32\ole32.dll
2011-02-02 16:17:39 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-02-02 16:17:32 ----A---- C:\Windows\system32\drivers\fvevol.sys
2011-02-02 16:17:31 ----A---- C:\Windows\system32\spoolsv.exe
2011-02-02 16:16:24 ----A---- C:\Windows\system32\t2embed.dll
2011-02-02 16:16:24 ----A---- C:\Windows\system32\ir32_32.dll
2011-02-02 16:16:24 ----A---- C:\Windows\system32\iccvid.dll
2011-02-02 16:16:23 ----A---- C:\Windows\system32\winlogon.exe
2011-02-02 16:16:23 ----A---- C:\Windows\explorer.exe
2011-02-02 16:16:22 ----A---- C:\Windows\system32\tzres.dll
2011-02-02 16:16:17 ----A---- C:\Windows\system32\msdri.dll
2011-02-02 16:16:17 ----A---- C:\Windows\system32\CPFilters.dll
2011-02-02 16:16:16 ----A---- C:\Windows\system32\psisdecd.dll
2011-02-02 16:15:57 ----A---- C:\Windows\system32\schannel.dll
2011-02-02 16:15:49 ----A---- C:\Windows\system32\wmicmiplugin.dll
2011-02-02 16:15:49 ----A---- C:\Windows\system32\taskschd.dll
2011-02-02 16:15:49 ----A---- C:\Windows\system32\taskeng.exe
2011-02-02 16:15:49 ----A---- C:\Windows\system32\taskcomp.dll
2011-02-02 16:15:49 ----A---- C:\Windows\system32\schtasks.exe
2011-02-02 16:15:49 ----A---- C:\Windows\system32\schedsvc.dll
2011-02-02 16:15:45 ----A---- C:\Windows\system32\msasn1.dll
2011-02-02 16:15:44 ----A---- C:\Windows\system32\lsasrv.dll
2011-02-02 16:15:44 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2011-02-02 16:15:30 ----A---- C:\Windows\system32\rtutils.dll
2011-02-02 16:15:29 ----A---- C:\Windows\system32\inetcomm.dll
2011-02-02 16:15:28 ----A---- C:\Windows\system32\odbc32.dll
2011-02-02 16:15:28 ----A---- C:\Windows\system32\msxml3.dll
2011-02-02 16:15:25 ----A---- C:\Windows\system32\ntdll.dll
2011-02-02 16:15:23 ----A---- C:\Windows\system32\winresume.exe
2011-02-02 16:15:23 ----A---- C:\Windows\system32\winload.exe
2011-02-02 16:15:23 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-02-02 16:15:23 ----A---- C:\Windows\system32\CertEnroll.dll
2011-02-02 16:14:51 ----A---- C:\Windows\system32\asycfilt.dll
2011-02-02 16:14:50 ----A---- C:\Windows\system32\comctl32.dll
2011-02-02 16:14:49 ----A---- C:\Windows\system32\mfc40u.dll
2011-02-02 16:14:49 ----A---- C:\Windows\system32\mfc40.dll
2011-02-02 16:14:02 ----A---- C:\Windows\system32\wmploc.DLL
2011-02-02 16:14:02 ----A---- C:\Windows\system32\wmp.dll
2011-02-02 16:13:56 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2011-02-02 16:13:54 ----A---- C:\Windows\system32\jscript.dll
2011-02-02 16:13:53 ----A---- C:\Windows\system32\kernel32.dll
2011-02-02 16:13:53 ----A---- C:\Windows\system32\apphelp.dll
2011-02-02 16:13:48 ----A---- C:\Windows\system32\quartz.dll
2011-02-02 16:13:48 ----A---- C:\Windows\system32\msyuv.dll
2011-02-02 16:13:48 ----A---- C:\Windows\system32\msvidc32.dll
2011-02-02 16:13:48 ----A---- C:\Windows\system32\mciavi32.dll
2011-02-02 16:13:48 ----A---- C:\Windows\system32\iyuv_32.dll
2011-02-02 16:13:48 ----A---- C:\Windows\system32\avifil32.dll
2011-02-02 16:13:47 ----A---- C:\Windows\system32\tsbyuv.dll
2011-02-02 16:13:47 ----A---- C:\Windows\system32\msrle32.dll
2011-02-02 16:13:46 ----A---- C:\Windows\system32\fontsub.dll
2011-02-02 16:13:46 ----A---- C:\Windows\system32\atmlib.dll
2011-02-02 16:13:46 ----A---- C:\Windows\system32\atmfd.dll
2011-02-02 16:13:44 ----A---- C:\Windows\system32\webio.dll
2011-02-02 16:13:44 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-02-02 16:13:43 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-02-02 16:13:40 ----A---- C:\Windows\system32\shell32.dll
2011-02-02 16:13:21 ----A---- C:\Windows\system32\srvsvc.dll
2011-02-02 16:13:21 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-02-02 16:13:21 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-02-02 16:13:21 ----A---- C:\Windows\system32\drivers\srv.sys
2011-02-02 16:13:19 ----A---- C:\Windows\system32\wmpmde.dll
2011-02-02 16:13:18 ----A---- C:\Windows\system32\consent.exe
2011-02-02 16:13:17 ----A---- C:\Windows\system32\vbscript.dll
2011-02-02 16:13:16 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2011-02-02 16:13:16 ----A---- C:\Windows\system32\secproc_isv.dll
2011-02-02 16:13:16 ----A---- C:\Windows\system32\secproc.dll
2011-02-02 16:13:16 ----A---- C:\Windows\system32\RMActivate_isv.exe
2011-02-02 16:13:16 ----A---- C:\Windows\system32\RMActivate.exe
2011-02-02 16:13:16 ----A---- C:\Windows\system32\oleaut32.dll
2011-02-02 16:13:15 ----A---- C:\Windows\system32\secproc_ssp.dll
2011-02-02 16:13:15 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2011-02-02 16:13:15 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2011-02-02 16:13:12 ----A---- C:\Windows\system32\win32k.sys
2011-02-02 16:13:12 ----A---- C:\Windows\system32\StructuredQuery.dll
2011-02-02 16:13:11 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-02-02 16:13:11 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-02-02 16:13:11 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-02-02 15:58:18 ----A---- C:\Windows\system32\wintrust.dll
2011-02-02 15:58:14 ----A---- C:\Windows\system32\cabview.dll
2011-02-02 15:48:00 ----D---- C:\Windows\cs
2011-02-02 15:41:52 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2011-02-02 15:37:46 ----D---- C:\Program Files\Windows Live
2011-02-02 15:37:21 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-02-02 15:37:21 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-02-02 15:37:21 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-02-02 15:36:38 ----A---- C:\Windows\system32\UIRibbonRes.dll
2011-02-02 15:36:38 ----A---- C:\Windows\system32\UIRibbon.dll
2011-02-02 15:36:08 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-02-02 15:36:08 ----A---- C:\Windows\system32\mf.dll
2011-02-02 15:36:07 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-02-02 15:34:59 ----D---- C:\Program Files\Common Files\Windows Live
2011-02-02 15:23:58 ----D---- C:\Program Files\Movie Maker
2011-02-02 08:26:08 ----A---- C:\Windows\Čestina do SimCity 4 Rush Hour a Delux BETA Uninstaller.exe
2011-02-02 08:22:09 ----D---- C:\Program Files\Maxis
2011-01-31 22:44:15 ----D---- C:\Users\smraďoch\AppData\Roaming\teamspeak2
2011-01-31 22:29:07 ----D---- C:\Program Files\Teamspeak2_RC2
2011-01-29 19:07:55 ----D---- C:\Program Files\GameSpy Arcade
2011-01-29 19:06:04 ----D---- C:\Program Files\FireFly Studios
2011-01-29 13:29:40 ----D---- C:\ProgramData\PopCap Games
2011-01-29 13:29:10 ----D---- C:\Program Files\Plants vs. Zombies
2011-01-28 22:00:19 ----D---- C:\ProgramData\Firefly Studios
2011-01-20 16:30:49 ----D---- C:\Program Files\Mp3 Knife
2011-01-20 13:11:52 ----D---- C:\Program Files\aTube Catcher
2011-01-18 16:01:20 ----D---- C:\ProgramData\Farm Fishes
2011-01-18 03:37:18 ----A---- C:\Windows\IsUninst.exe
2011-01-18 03:37:16 ----RASH---- C:\MSDOS.SYS
2011-01-18 03:37:16 ----RASH---- C:\IO.SYS
2011-01-18 03:21:49 ----D---- C:\ProgramData\FarmFrenzy3_Madagascar
2011-01-18 03:15:15 ----D---- C:\ProgramData\FarmFrenzy-PizzaParty
2011-01-17 16:34:35 ----D---- C:\ProgramData\FarmFrenzy3_America
2011-01-17 16:33:31 ----D---- C:\ProgramData\AlawarWrapper
2011-01-17 16:27:38 ----D---- C:\ProgramData\FarmFrenzy3_Arctica
2011-01-17 16:25:37 ----D---- C:\Program Files\Alawar
2011-01-17 13:11:58 ----D---- C:\ProgramData\FarmFrenzy3
2011-01-16 23:34:54 ----D---- C:\Program Files\Farm Frenzy
2011-01-16 00:47:44 ----D---- C:\Users\smraďoch\AppData\Roaming\Rovio
2011-01-15 20:54:51 ----SD---- C:\Program Files\HLSW
2011-01-15 20:54:51 ----D---- C:\Users\smraďoch\AppData\Roaming\HLSW
2011-01-15 20:50:56 ----D---- C:\Users\smraďoch\AppData\Roaming\WinRAR
2011-01-15 11:40:48 ----D---- C:\Windows\system32\RTCOM
2011-01-15 11:40:22 ----D---- C:\Program Files\GamePark
2011-01-15 11:40:00 ----A---- C:\Windows\system32\WavesLib.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\WavesGUILib.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\SRSWOW.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\SRSTSXT.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\SRSTSHD.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\SRSHP360.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\SFNHK.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\SFCOM.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\SFAPO.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\RtkPgExt.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\RtkCoInst.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\RtkApoApi.dll
2011-01-15 11:39:59 ----A---- C:\Windows\system32\drivers\RTKVHDA.sys
2011-01-15 11:39:58 ----A---- C:\Windows\system32\RtkAPO.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\RTEEP32A.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\RTEEL32A.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\RTEEG32A.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\RTEED32A.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\RP3DHT32.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\RP3DAA32.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2011-01-15 11:39:58 ----A---- C:\Windows\system32\MaxxAudioAPO.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\FMAPO.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSVoiceClarityDLL.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSSymmetryDLL.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSS2SpeakerDLL.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSNeoPCDLL.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSLimiterDLL.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSLFXAPO.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSGFXAPONS.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSGFXAPO.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSGainCompensatorDLL.dll
2011-01-15 11:39:57 ----A---- C:\Windows\system32\DTSBoostDLL.dll
2011-01-15 11:39:56 ----D---- C:\Program Files\Realtek
2011-01-15 11:39:56 ----A---- C:\Windows\system32\DTSBassEnhancementDLL.dll
2011-01-15 11:39:56 ----A---- C:\Windows\system32\AERTARen.dll
2011-01-15 11:39:56 ----A---- C:\Windows\system32\AERTACap.dll
2011-01-15 11:39:54 ----HD---- C:\Program Files\Temp
2011-01-15 11:39:54 ----A---- C:\Windows\RtlExUpd.dll
2011-01-15 11:39:40 ----D---- C:\Program Files\Common Files\InstallShield
2011-01-15 11:18:31 ----D---- C:\ProgramData\UAB
2011-01-15 11:17:47 ----D---- C:\ProgramData\PC Drivers HeadQuarters
2011-01-15 11:16:56 ----D---- C:\Program Files\PC Drivers HeadQuarters
2011-01-15 04:05:44 ----D---- C:\Program Files\Activision
2011-01-15 03:59:14 ----D---- C:\HRY
2011-01-15 03:43:44 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-01-15 03:43:44 ----A---- C:\Windows\system32\x3daudio1_2.dll
2011-01-15 03:43:44 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-01-15 03:43:44 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-01-15 03:43:44 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-01-15 03:43:43 ----A---- C:\Windows\system32\xinput1_3.dll
2011-01-15 03:43:43 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-01-15 03:43:43 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-01-15 03:43:43 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-01-15 03:43:43 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-01-15 03:43:42 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-01-15 03:43:42 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-01-15 03:43:42 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-01-15 03:43:42 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-01-15 03:43:42 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-01-15 03:43:42 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-01-15 03:43:42 ----A---- C:\Windows\system32\d3dx10.dll
2011-01-15 03:43:41 ----A---- C:\Windows\system32\xinput1_2.dll
2011-01-15 03:43:41 ----A---- C:\Windows\system32\xinput1_1.dll
2011-01-15 03:43:41 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-01-15 03:43:41 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-01-15 03:43:41 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-01-15 03:43:36 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-01-15 03:43:36 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-01-15 03:43:35 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-01-15 03:43:34 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-01-15 03:43:34 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-01-15 03:43:34 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-01-15 03:43:33 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-01-15 03:42:58 ----A---- C:\Windows\system32\drivers\PnkBstrK.sys
2011-01-15 03:42:48 ----A---- C:\Users\smraďoch\AppData\Roaming\PnkBstrK.sys
2011-01-15 03:42:12 ----A---- C:\Windows\system32\PnkBstrB.exe
2011-01-15 03:42:01 ----A---- C:\Windows\system32\PnkBstrA.exe
2011-01-15 03:41:59 ----A---- C:\Windows\game.ini
2011-01-15 02:25:35 ----HD---- C:\Program Files\InstallShield Installation Information
2011-01-15 02:25:34 ----D---- C:\Program Files\ICQ6Toolbar
2011-01-15 02:25:29 ----D---- C:\ProgramData\ICQ
2011-01-15 02:23:09 ----D---- C:\Users\smraďoch\AppData\Roaming\ICQ
2011-01-15 02:23:03 ----D---- C:\Program Files\ICQ7.2
2011-01-15 01:09:29 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-01-15 01:09:23 ----D---- C:\Program Files\DAEMON Tools Lite
2011-01-15 01:09:11 ----D---- C:\Users\smraďoch\AppData\Roaming\DAEMON Tools Lite
2011-01-15 01:09:11 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-01-15 01:03:50 ----D---- C:\Program Files\The KMPlayer
2011-01-15 00:53:43 ----D---- C:\Users\smraďoch\AppData\Roaming\Ahead
2011-01-15 00:53:36 ----D---- C:\ProgramData\Ahead
2011-01-15 00:53:05 ----D---- C:\ProgramData\Nero
2011-01-15 00:53:05 ----D---- C:\Program Files\Nero
2011-01-15 00:53:05 ----D---- C:\Program Files\Common Files\Ahead
2011-01-15 00:52:30 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-01-15 00:52:30 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-01-15 00:47:56 ----A---- C:\Windows\system32\msonpmon.dll
2011-01-15 00:47:10 ----D---- C:\Program Files\Microsoft Works
2011-01-15 00:46:56 ----D---- C:\Program Files\Microsoft Visual Studio
2011-01-15 00:46:56 ----D---- C:\Program Files\Common Files\DESIGNER
2011-01-15 00:46:45 ----D---- C:\Windows\PCHEALTH
2011-01-15 00:46:45 ----D---- C:\Program Files\Microsoft.NET
2011-01-15 00:45:41 ----D---- C:\Program Files\Microsoft Visual Studio 8
2011-01-15 00:45:06 ----D---- C:\ProgramData\Microsoft Help
2011-01-15 00:45:06 ----D---- C:\Program Files\Microsoft Office
2011-01-15 00:44:52 ----RD---- C:\MSOCache
2011-01-15 00:43:12 ----D---- C:\Program Files\WinRAR
2011-01-15 00:42:57 ----A---- C:\Windows\iun6002.exe
2011-01-15 00:42:56 ----D---- C:\Program Files\Codec Pack - All In 1
2011-01-15 00:42:47 ----A---- C:\Windows\Codec Pack - All In 1 Setup Log.txt
2011-01-15 00:31:24 ----N---- C:\Windows\system32\MpSigStub.exe
2011-01-15 00:27:33 ----D---- C:\Users\smraďoch\AppData\Roaming\Macromedia
2011-01-15 00:27:33 ----D---- C:\Users\smraďoch\AppData\Roaming\Adobe
2011-01-15 00:26:10 ----D---- C:\Windows\system32\Macromed
2011-01-15 00:18:20 ----D---- C:\Users\smraďoch\AppData\Roaming\Mozilla
2011-01-15 00:17:51 ----D---- C:\Program Files\Mozilla Firefox
2011-01-15 00:16:11 ----D---- C:\ProgramData\CentrumczToolbar
2011-01-15 00:16:11 ----D---- C:\Program Files\CentrumczToolbar
2011-01-15 00:10:46 ----D---- C:\ProgramData\NVIDIA
2011-01-15 00:10:17 ----SHD---- C:\Windows\Installer
2011-01-15 00:10:09 ----D---- C:\ProgramData\NVIDIA Corporation
2011-01-15 00:09:41 ----A---- C:\Windows\system32\OpenCL.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvwgf2um.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvoglv32.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvgenco322030.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvdispco322050.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvdecodemft.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvd3dum.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvcuvid.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvcuda.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvcompiler.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\nvapi.dll
2011-01-15 00:09:41 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-01-15 00:08:58 ----D---- C:\Program Files\NVIDIA Corporation
2011-01-15 00:08:39 ----D---- C:\NVIDIA
2011-01-14 21:22:21 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-01-14 21:18:50 ----D---- C:\Users\smraďoch\AppData\Roaming\Identities
2011-01-14 21:18:40 ----SD---- C:\Users\smraďoch\AppData\Roaming\Microsoft
2011-01-14 21:18:40 ----D---- C:\Users\smraďoch\AppData\Roaming\Media Center Programs
2011-01-14 21:18:26 ----SHD---- C:\ProgramData\Šablony
2011-01-14 21:18:26 ----SHD---- C:\ProgramData\Plocha
2011-01-14 21:18:26 ----SHD---- C:\ProgramData\Oblíbené položky
2011-01-14 21:18:26 ----SHD---- C:\ProgramData\Nabídka Start
2011-01-14 21:18:26 ----SHD---- C:\ProgramData\Dokumenty
2011-01-14 21:18:26 ----SHD---- C:\ProgramData\Data aplikací
2011-01-14 21:18:26 ----D---- C:\Recovery
2011-01-14 21:15:00 ----D---- C:\Windows\SoftwareDistribution
2011-01-14 21:12:25 ----D---- C:\Windows\Prefetch
2011-01-14 21:12:12 ----ASH---- C:\pagefile.sys
2011-01-14 21:12:08 ----SHD---- C:\System Volume Information
2011-01-14 21:12:08 ----ASH---- C:\hiberfil.sys
2011-01-14 21:10:53 ----D---- C:\Windows\Panther
2011-01-14 20:58:37 ----A---- C:\Windows\system32\drivers\jraid.sys

======List of files/folders modified in the last 1 months======

2011-02-08 03:40:16 ----D---- C:\Windows\system32\config
2011-02-08 03:23:03 ----D---- C:\Windows\winsxs
2011-02-08 03:05:50 ----RSD---- C:\Windows\assembly
2011-02-08 03:04:10 ----RSD---- C:\Windows\Fonts
2011-02-08 03:04:00 ----D---- C:\Program Files\Common Files\microsoft shared
2011-02-08 03:03:52 ----D---- C:\Windows\System32
2011-02-08 03:02:05 ----D---- C:\Program Files\Common Files\System
2011-02-08 03:02:05 ----A---- C:\Windows\win.ini
2011-02-08 01:55:48 ----D---- C:\Windows
2011-02-08 01:05:46 ----D---- C:\Windows\system32\drivers
2011-02-07 22:47:10 ----D---- C:\Windows\inf
2011-02-07 22:46:31 ----D---- C:\Windows\debug
2011-02-07 22:18:07 ----D---- C:\Windows\system32\catroot2
2011-02-07 22:10:45 ----A---- C:\Windows\system.ini
2011-02-07 22:10:41 ----D---- C:\Windows\system32\drivers\etc
2011-02-07 22:10:31 ----RD---- C:\Program Files
2011-02-07 22:09:09 ----D---- C:\Windows\AppPatch
2011-02-07 22:09:08 ----D---- C:\Program Files\Common Files
2011-02-07 20:04:44 ----D---- C:\Windows\system32\wfp
2011-02-07 20:04:42 ----D---- C:\Windows\system32\wbem
2011-02-07 20:03:56 ----D---- C:\Windows\Tasks
2011-02-07 20:03:56 ----D---- C:\Windows\system32\DriverStore
2011-02-07 20:03:54 ----D---- C:\Windows\system32\drivers\UMDF
2011-02-07 20:03:54 ----D---- C:\Windows\system32\CodeIntegrity
2011-02-07 20:03:54 ----D---- C:\Windows\AppCompat
2011-02-07 20:03:46 ----D---- C:\Windows\registration
2011-02-07 20:03:32 ----D---- C:\Windows\Microsoft.NET
2011-02-03 04:08:18 ----D---- C:\Windows\rescache
2011-02-03 03:28:02 ----D---- C:\Windows\system32\cs-CZ
2011-02-03 03:28:02 ----D---- C:\Windows\ehome
2011-02-03 03:28:02 ----D---- C:\Program Files\Windows Mail
2011-02-03 03:28:01 ----D---- C:\Windows\system32\migration
2011-02-03 03:28:01 ----D---- C:\Program Files\Internet Explorer
2011-02-03 03:28:00 ----D---- C:\Windows\system32\Boot
2011-02-03 03:27:59 ----D---- C:\Program Files\Windows Media Player
2011-02-03 03:11:28 ----D---- C:\Windows\system32\catroot
2011-02-02 15:39:26 ----SD---- C:\ProgramData\Microsoft
2011-02-02 15:36:47 ----D---- C:\Windows\Logs
2011-01-29 19:27:52 ----D---- C:\Windows\Downloaded Program Files
2011-01-29 13:29:40 ----D---- C:\ProgramData
2011-01-25 21:06:30 ----D---- C:\Windows\system32\NDF
2011-01-21 17:47:09 ----D---- C:\Windows\LiveKernelReports
2011-01-20 22:08:16 ----D---- C:\Windows\system32\wdi
2011-01-15 03:42:00 ----D---- C:\Windows\system32\LogFiles
2011-01-15 01:04:05 ----D---- C:\Windows\system32\Tasks
2011-01-15 00:47:06 ----D---- C:\Program Files\MSBuild
2011-01-15 00:46:55 ----D---- C:\Windows\ShellNew
2011-01-15 00:31:11 ----D---- C:\Windows\system32\restore
2011-01-15 00:10:23 ----D---- C:\Windows\Help
2011-01-14 21:18:38 ----RD---- C:\Users
2011-01-14 21:18:26 ----D---- C:\Program Files\Windows NT
2011-01-14 21:14:29 ----D---- C:\Windows\system32\sysprep
2011-01-14 21:12:42 ----D---- C:\Windows\CSC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2009-08-13 96368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-15 218176]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 32bitový systém Windows Vista; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
S3 catchme;catchme; \??\C:\Users\SMRAOC~1\AppData\Local\Temp\catchme.sys [2011-02-08 31744]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2010-07-28 3154920]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-07-13 1068032]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

S2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-03-28 246520]
S2 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [2010-10-16 600680]
S2 PEVSystemStart;PEVSystemStart; C:\ComboFix\PEV.cfxxe [2010-04-26 256512]
S2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2011-01-15 75136]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
S2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-16 271920]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-02-03 1343400]

-----------------EOF-----------------

Re: Může to být nějaký vir?

Napsal: 08 úno 2011 19:25
od Rudy
Ty pruhy svědčí buď o tom, že gr. karta nemá korektní ovladače, nebo je poškozena. Zkuste ovladače přeinstalovat. Log vypadá OK.