Průzkumník se spustí sám po startu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Průzkumník se spustí sám po startu
Dobrý den
Mám malý, ale otravný problém.
Průzkumník Windows (C: /Windows/ Explorer.exe) se mi spouští vždy po zapnutí počítače. Nevíte někdo co s tím ? Dočet jsem se, že se to dá někdy zjistit z logu, tak ho sem vložím.
Za každou radu budu vděčný.
Ještě dodatek: Ve správci úloh -> Procesy je položka explorer.exe Procesor 00 někdy i 02 Průzkumník Windows
Pavel
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:27:40, on 13.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\Pavel Hlavatý\Downloads\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [DTRun] c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O15 - Trusted Zone: http://*.mcafee.com (HKLM)
O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)
O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bluetooth Device Manager - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: DEBridge - McAfee, Inc. - c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - c:\Windows\SysWOW64\flcdlock.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: HP Hotkey Monitor (hpHotkeyMonitor) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\system\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11727 bytes
Mám malý, ale otravný problém.
Průzkumník Windows (C: /Windows/ Explorer.exe) se mi spouští vždy po zapnutí počítače. Nevíte někdo co s tím ? Dočet jsem se, že se to dá někdy zjistit z logu, tak ho sem vložím.
Za každou radu budu vděčný.
Ještě dodatek: Ve správci úloh -> Procesy je položka explorer.exe Procesor 00 někdy i 02 Průzkumník Windows
Pavel
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:27:40, on 13.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\Pavel Hlavatý\Downloads\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [DTRun] c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O15 - Trusted Zone: http://*.mcafee.com (HKLM)
O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)
O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bluetooth Device Manager - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: DEBridge - McAfee, Inc. - c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - c:\Windows\SysWOW64\flcdlock.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: HP Hotkey Monitor (hpHotkeyMonitor) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\system\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11727 bytes
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Průzkumník se spustí sám po startu
Zdravim
Stiahnes>>RSIT >>logy vloz sem,
Stiahnes>>RSIT >>logy vloz sem,
Re: Průzkumník se spustí sám po startu
Logfile of random's system information tool 1.08 (written by random/random)
Run by Pavel Hlavatý at 2011-02-13 10:43:48
Microsoft Windows 7 Home Premium
System drive C: has 546 GB (92%) free of 593 GB
Total RAM: 3951 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:43:56, on 13.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
C:\Program Files\QIP 2010\qip.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\Pavel Hlavatý.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [DTRun] c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O15 - Trusted Zone: http://*.mcafee.com (HKLM)
O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)
O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bluetooth Device Manager - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: DEBridge - McAfee, Inc. - c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - c:\Windows\SysWOW64\flcdlock.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: HP Hotkey Monitor (hpHotkeyMonitor) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\system\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12311 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe"
"c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe"
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
winlogon.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\STacSV64.exe
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\Hpservice.exe
atieclxx
C:\windows\system32\svchost.exe -k NetworkService
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
C:\windows\System32\spoolsv.exe
"taskhost.exe"
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\System32\rundll32.exe" "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" /start
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe"
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe
"C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe"
"c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe"
"c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
C:\windows\system\uArcCapture.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\Motorola\Bluetooth\obexsrv.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe"
C:\windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe"
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Motorola\Bluetooth\audiosrv.exe"
"c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe"
"C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe" -Embedding
WLIDSvcM.exe 2948
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe" /hidden
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe"
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\windows\System32\svchost.exe -k secsvcs
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe" "<hpNotification><Toast><Title>HP Wireless Assistant</Title><Text>Combo: On</Text><IconPath>C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WA_tray_32_on.ico</IconPath><ID>669508837</ID><Path>C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe</Path><Parameters></Parameters></Toast></hpNotification>"
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /welcome
"C:\windows\system32\wuauclt.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
taskeng.exe {F0546A48-5401-4E30-AA64-618502C2949D}
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe" /L Analysis
"C:\Program Files\QIP 2010\qip.exe"
C:\windows\System32\svchost.exe -k swprv
"C:\Program Files\Mozilla Firefox\firefox.exe"
"C:\Program Files\Mozilla Firefox\plugin-container.exe" --channel=6000.9bf3fa0.388846287 "C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll" 6000 plugin \\.\pipe\gecko-crash-server-pipe.6000
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Users\Pavel Hlavatý\Downloads\RSITx64.exe"
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP ProtectTools Security Manager Extension - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2009-12-03 2187528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2009-12-12 117248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP ProtectTools Security Manager Extension - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2009-12-03 1471752]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HPPowerAssistant"=C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2010-06-19 1691192]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-04 2174760]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe [2010-04-05 8192]
"BTMTrayAgent"=C:\Program Files\Motorola\Bluetooth\btmshell.dll [2010-06-11 24783624]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2010-03-17 487424]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2010-03-01 256056]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2010-03-04 284696]
"PDF Complete"=C:\Program Files (x86)\PDF Complete\pdfsty.exe [2009-10-23 563736]
"File Sanitizer"=C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2009-12-12 11265536]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-08-05 98304]
"DTRun"=c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [2009-11-19 518656]
"NortonOnlineBackupReminder"=C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe [2009-06-29 600936]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-01-13 3396624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-02-13 10:43:49 ----D---- C:\Program Files\trend micro
2011-02-13 10:43:48 ----D---- C:\rsit
2011-02-13 10:04:59 ----A---- C:\windows\system32\drivers\aswSP.sys
2011-02-13 10:04:59 ----A---- C:\windows\system32\drivers\aswFsBlk.sys
2011-02-13 10:04:56 ----A---- C:\windows\system32\drivers\aswRdr.sys
2011-02-13 10:04:54 ----A---- C:\windows\system32\drivers\aswTdi.sys
2011-02-13 10:04:53 ----A---- C:\windows\system32\drivers\aswMonFlt.sys
2011-02-13 10:04:34 ----A---- C:\windows\SYSWOW64\aswBoot.exe
2011-02-12 21:17:17 ----D---- C:\ProgramData\Spybot - Search & Destroy
2011-02-12 21:17:17 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy
2011-02-12 20:54:29 ----A---- C:\windows\SYSWOW64\mshtml.dll
2011-02-12 20:54:29 ----A---- C:\windows\system32\mshtml.dll
2011-02-12 20:54:28 ----A---- C:\windows\system32\wininet.dll
2011-02-12 20:54:28 ----A---- C:\windows\system32\urlmon.dll
2011-02-12 20:54:27 ----A---- C:\windows\SYSWOW64\wininet.dll
2011-02-12 20:54:27 ----A---- C:\windows\SYSWOW64\urlmon.dll
2011-02-12 20:54:27 ----A---- C:\windows\SYSWOW64\ieframe.dll
2011-02-12 20:54:26 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2011-02-12 20:54:26 ----A---- C:\windows\system32\ieframe.dll
2011-02-12 20:54:24 ----A---- C:\windows\SYSWOW64\mstime.dll
2011-02-12 20:54:24 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2011-02-12 20:54:24 ----A---- C:\windows\system32\mstime.dll
2011-02-12 20:54:24 ----A---- C:\windows\system32\msfeeds.dll
2011-02-12 20:54:24 ----A---- C:\windows\system32\ieui.dll
2011-02-12 20:54:24 ----A---- C:\windows\system32\iertutil.dll
2011-02-12 20:54:24 ----A---- C:\windows\system32\iedkcs32.dll
2011-02-12 20:54:23 ----A---- C:\windows\SYSWOW64\ieui.dll
2011-02-12 20:54:23 ----A---- C:\windows\SYSWOW64\iertutil.dll
2011-02-12 20:54:23 ----A---- C:\windows\system32\iepeers.dll
2011-02-12 20:54:17 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2011-02-12 20:54:17 ----A---- C:\windows\SYSWOW64\msfeedsbs.dll
2011-02-12 20:54:17 ----A---- C:\windows\SYSWOW64\iepeers.dll
2011-02-12 20:54:17 ----A---- C:\windows\system32\mshtmled.dll
2011-02-12 20:54:17 ----A---- C:\windows\system32\msfeedsbs.dll
2011-02-12 20:54:16 ----A---- C:\windows\SYSWOW64\msfeedssync.exe
2011-02-12 20:54:16 ----A---- C:\windows\SYSWOW64\licmgr10.dll
2011-02-12 20:54:16 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2011-02-12 20:54:16 ----A---- C:\windows\system32\msfeedssync.exe
2011-02-12 20:54:16 ----A---- C:\windows\system32\licmgr10.dll
2011-02-12 20:54:16 ----A---- C:\windows\system32\jsproxy.dll
2011-02-12 20:54:09 ----A---- C:\windows\SYSWOW64\d3d10warp.dll
2011-02-12 20:54:09 ----A---- C:\windows\system32\d3d10warp.dll
2011-02-12 20:54:09 ----A---- C:\windows\system32\d2d1.dll
2011-02-12 20:54:08 ----A---- C:\windows\SYSWOW64\d2d1.dll
2011-02-12 20:54:08 ----A---- C:\windows\system32\WMVDECOD.DLL
2011-02-12 20:54:08 ----A---- C:\windows\system32\mf.dll
2011-02-12 20:54:08 ----A---- C:\windows\system32\DWrite.dll
2011-02-12 20:54:07 ----A---- C:\windows\SYSWOW64\mf.dll
2011-02-12 20:54:07 ----A---- C:\windows\SYSWOW64\DWrite.dll
2011-02-12 20:54:07 ----A---- C:\windows\system32\XpsPrint.dll
2011-02-12 20:54:07 ----A---- C:\windows\system32\FntCache.dll
2011-02-12 20:54:06 ----A---- C:\windows\SYSWOW64\XpsPrint.dll
2011-02-12 20:54:04 ----A---- C:\windows\system32\XpsGdiConverter.dll
2011-02-12 20:54:04 ----A---- C:\windows\system32\ExplorerFrame.dll
2011-02-12 20:54:03 ----A---- C:\windows\SYSWOW64\XpsGdiConverter.dll
2011-02-12 20:54:03 ----A---- C:\windows\SYSWOW64\WMVDECOD.DLL
2011-02-12 20:54:03 ----A---- C:\windows\SYSWOW64\d3d10_1core.dll
2011-02-12 20:54:03 ----A---- C:\windows\system32\drivers\dxgkrnl.sys
2011-02-12 20:54:03 ----A---- C:\windows\system32\d3d10_1core.dll
2011-02-12 20:54:02 ----A---- C:\windows\SYSWOW64\XpsRasterService.dll
2011-02-12 20:54:02 ----A---- C:\windows\SYSWOW64\mfreadwrite.dll
2011-02-12 20:54:02 ----A---- C:\windows\SYSWOW64\ExplorerFrame.dll
2011-02-12 20:54:02 ----A---- C:\windows\SYSWOW64\d3d10_1.dll
2011-02-12 20:54:02 ----A---- C:\windows\system32\XpsRasterService.dll
2011-02-12 20:54:02 ----A---- C:\windows\system32\mfreadwrite.dll
2011-02-12 20:54:02 ----A---- C:\windows\system32\mfps.dll
2011-02-12 20:54:02 ----A---- C:\windows\system32\drivers\dxgmms1.sys
2011-02-12 20:54:02 ----A---- C:\windows\system32\d3d10_1.dll
2011-02-12 20:54:02 ----A---- C:\windows\system32\cdd.dll
2011-02-12 20:53:58 ----A---- C:\windows\system32\win32k.sys
2011-02-12 20:53:56 ----A---- C:\windows\system32\winsrv.dll
2011-02-12 20:53:55 ----A---- C:\windows\SYSWOW64\kerberos.dll
2011-02-12 20:53:55 ----A---- C:\windows\system32\kerberos.dll
2011-02-12 20:53:53 ----A---- C:\windows\SYSWOW64\vbscript.dll
2011-02-12 20:53:53 ----A---- C:\windows\SYSWOW64\jscript.dll
2011-02-12 20:53:53 ----A---- C:\windows\system32\vbscript.dll
2011-02-12 20:53:53 ----A---- C:\windows\system32\jscript.dll
2011-02-12 20:53:51 ----A---- C:\windows\system32\ntoskrnl.exe
2011-02-12 20:53:51 ----A---- C:\windows\system32\ntdll.dll
2011-02-12 20:53:50 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2011-02-12 20:53:50 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2011-02-12 20:53:50 ----A---- C:\windows\SYSWOW64\ntdll.dll
2011-02-05 22:23:18 ----D---- C:\windows\SYSWOW64\Wat
2011-02-05 22:23:18 ----D---- C:\windows\system32\Wat
2011-02-05 19:25:00 ----A---- C:\windows\SYSWOW64\PresentationHostProxy.dll
2011-02-05 19:25:00 ----A---- C:\windows\SYSWOW64\PresentationHost.exe
2011-02-05 19:25:00 ----A---- C:\windows\SYSWOW64\netfxperf.dll
2011-02-05 19:25:00 ----A---- C:\windows\SYSWOW64\mscoree.dll
2011-02-05 19:25:00 ----A---- C:\windows\SYSWOW64\dfshim.dll
2011-02-05 19:25:00 ----A---- C:\windows\system32\PresentationHostProxy.dll
2011-02-05 19:25:00 ----A---- C:\windows\system32\PresentationHost.exe
2011-02-05 19:25:00 ----A---- C:\windows\system32\netfxperf.dll
2011-02-05 19:25:00 ----A---- C:\windows\system32\mscoree.dll
2011-02-05 19:24:59 ----A---- C:\windows\system32\dfshim.dll
2011-02-05 19:24:48 ----A---- C:\windows\system32\browserchoice.exe
2011-02-05 19:18:11 ----A---- C:\windows\system32\drivers\usbvideo.sys
2011-02-05 19:18:11 ----A---- C:\windows\system32\drivers\ks.sys
2011-02-05 19:16:52 ----D---- C:\Program Files (x86)\SopCast
2011-02-05 18:44:35 ----D---- C:\Program Files (x86)\Age of Empires
2011-02-05 09:26:35 ----A---- C:\windows\system32\wmp.dll
2011-02-05 09:26:33 ----A---- C:\windows\SYSWOW64\wmp.dll
2011-02-05 09:26:31 ----A---- C:\windows\SYSWOW64\wmploc.DLL
2011-02-05 09:26:30 ----A---- C:\windows\system32\wmploc.DLL
2011-02-05 09:26:28 ----A---- C:\windows\SYSWOW64\tzres.dll
2011-02-05 09:26:28 ----A---- C:\windows\system32\tzres.dll
2011-02-05 09:26:19 ----A---- C:\windows\SYSWOW64\t2embed.dll
2011-02-05 09:26:19 ----A---- C:\windows\system32\t2embed.dll
2011-02-05 09:26:16 ----A---- C:\windows\system32\ole32.dll
2011-02-05 09:26:13 ----A---- C:\windows\SYSWOW64\ole32.dll
2011-02-05 09:26:13 ----A---- C:\windows\system32\schedsvc.dll
2011-02-05 09:26:12 ----A---- C:\windows\SYSWOW64\taskschd.dll
2011-02-05 09:26:12 ----A---- C:\windows\SYSWOW64\taskeng.exe
2011-02-05 09:26:12 ----A---- C:\windows\SYSWOW64\taskcomp.dll
2011-02-05 09:26:12 ----A---- C:\windows\system32\wmicmiplugin.dll
2011-02-05 09:26:12 ----A---- C:\windows\system32\taskschd.dll
2011-02-05 09:26:12 ----A---- C:\windows\system32\taskeng.exe
2011-02-05 09:26:12 ----A---- C:\windows\system32\taskcomp.dll
2011-02-05 09:26:12 ----A---- C:\windows\system32\schtasks.exe
2011-02-05 09:26:11 ----A---- C:\windows\SYSWOW64\schtasks.exe
2011-02-05 09:26:09 ----A---- C:\windows\SYSWOW64\StructuredQuery.dll
2011-02-05 09:26:09 ----A---- C:\windows\system32\StructuredQuery.dll
2011-02-05 09:26:08 ----A---- C:\windows\SYSWOW64\atmfd.dll
2011-02-05 09:26:08 ----A---- C:\windows\system32\atmfd.dll
2011-02-05 09:26:07 ----A---- C:\windows\SYSWOW64\atmlib.dll
2011-02-05 09:26:07 ----A---- C:\windows\system32\atmlib.dll
2011-02-05 09:25:57 ----A---- C:\windows\system32\shell32.dll
2011-02-05 09:25:55 ----A---- C:\windows\SYSWOW64\shell32.dll
2011-02-05 09:25:52 ----A---- C:\windows\SYSWOW64\inetcomm.dll
2011-02-05 09:25:52 ----A---- C:\windows\system32\inetcomm.dll
2011-02-05 09:25:49 ----A---- C:\windows\SYSWOW64\CPFilters.dll
2011-02-05 09:25:49 ----A---- C:\windows\system32\CPFilters.dll
2011-02-05 09:25:48 ----A---- C:\windows\system32\msdri.dll
2011-02-05 09:25:45 ----A---- C:\windows\system32\drivers\tcpip.sys
2011-02-05 09:25:42 ----A---- C:\windows\SYSWOW64\schannel.dll
2011-02-05 09:25:42 ----A---- C:\windows\system32\schannel.dll
2011-02-05 09:25:39 ----A---- C:\windows\SYSWOW64\comctl32.dll
2011-02-05 09:25:39 ----A---- C:\windows\system32\comctl32.dll
2011-02-05 09:25:38 ----A---- C:\windows\SYSWOW64\oleaut32.dll
2011-02-05 09:25:38 ----A---- C:\windows\system32\oleaut32.dll
2011-02-05 09:25:36 ----A---- C:\windows\SYSWOW64\rtutils.dll
2011-02-05 09:25:36 ----A---- C:\windows\system32\rtutils.dll
2011-02-05 09:25:29 ----A---- C:\windows\system32\spoolsv.exe
2011-02-05 09:25:27 ----A---- C:\windows\SYSWOW64\webio.dll
2011-02-05 09:25:27 ----A---- C:\windows\SYSWOW64\iccvid.dll
2011-02-05 09:25:27 ----A---- C:\windows\system32\webio.dll
2011-02-05 09:25:27 ----A---- C:\windows\system32\drivers\fvevol.sys
2011-02-05 09:25:22 ----A---- C:\windows\SYSWOW64\wmpmde.dll
2011-02-05 09:25:22 ----A---- C:\windows\system32\wmpmde.dll
2011-02-05 09:25:11 ----A---- C:\windows\SYSWOW64\msxml3.dll
2011-02-05 09:25:11 ----A---- C:\windows\system32\msxml3.dll
2011-02-05 09:25:10 ----A---- C:\windows\SYSWOW64\mfc40u.dll
2011-02-05 09:25:10 ----A---- C:\windows\SYSWOW64\mfc40.dll
2011-02-05 09:25:10 ----A---- C:\windows\system32\drivers\Diskdump.sys
2011-02-05 09:25:10 ----A---- C:\windows\system32\consent.exe
2011-02-05 09:25:09 ----A---- C:\windows\SYSWOW64\odbc32.dll
2011-02-05 09:25:09 ----A---- C:\windows\system32\odbc32.dll
2011-02-05 09:25:08 ----A---- C:\windows\system32\srvsvc.dll
2011-02-05 09:25:08 ----A---- C:\windows\system32\drivers\srv2.sys
2011-02-05 09:25:08 ----A---- C:\windows\system32\drivers\srv.sys
2011-02-05 09:25:07 ----A---- C:\windows\SYSWOW64\sscore.dll
2011-02-05 09:25:07 ----A---- C:\windows\system32\drivers\srvnet.sys
2011-02-04 19:47:56 ----D---- C:\windows\rescache
2011-02-04 19:45:04 ----ASH---- C:\pagefile.sys
2011-02-04 18:42:53 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\IObit
2011-02-04 18:42:53 ----D---- C:\Program Files (x86)\Advanced SystemCare 3
2011-02-04 17:30:48 ----D---- C:\xProjekty
2011-02-04 17:23:43 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\WinRAR
2011-02-04 15:53:35 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-02-04 15:53:30 ----D---- C:\Program Files (x86)\Microsoft Works
2011-02-04 15:53:14 ----D---- C:\windows\PCHEALTH
2011-02-04 15:53:14 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-02-04 15:52:11 ----D---- C:\Program Files\Microsoft Office
2011-02-04 15:49:03 ----D---- C:\Program Files (x86)\Microsoft Office
2011-02-04 15:48:10 ----RHD---- C:\MSOCache
2011-02-04 15:24:37 ----D---- C:\ProgramData\VirtualizedApplications
2011-02-04 13:56:53 ----D---- C:\Program Files (x86)\Counter-Strike 1.6
2011-02-04 13:51:58 ----D---- C:\Program Files\CCleaner
2011-02-04 13:40:46 ----D---- C:\Program Files\QIP 2010
2011-02-04 13:36:58 ----D---- C:\Program Files (x86)\WinRAR
2011-02-04 13:32:32 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\skypePM
2011-02-04 13:31:33 ----RD---- C:\Program Files (x86)\Skype
2011-02-04 13:31:33 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\Skype
2011-02-04 13:26:48 ----D---- C:\Program Files (x86)\The KMPlayer
2011-02-04 13:21:28 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\ArcSoft
2011-02-04 13:19:00 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\Mozilla
2011-02-04 13:18:56 ----D---- C:\Program Files\Mozilla Firefox
2011-02-04 13:15:53 ----A---- C:\windows\myClean.bat
2011-02-04 13:02:42 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\CorelHomeOffice
2011-02-04 13:02:31 ----RSH---- C:\ProgramData\1EFDA7FD4F.sys
2011-02-04 13:02:31 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\Corel
2011-02-04 13:02:29 ----ASH---- C:\ProgramData\KGyGaAvL.sys
2011-02-04 12:59:56 ----D---- C:\ProgramData\Microsoft Help
2011-02-04 12:58:54 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\SoftGrid Client
2011-02-04 12:58:35 ----N---- C:\windows\system32\MpSigStub.exe
2011-02-04 12:58:16 ----A---- C:\windows\SYSWOW64\PerfStringBackup.INI
2011-02-04 12:57:54 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\TP
2011-02-04 12:24:06 ----A---- C:\windows\system32\aswBoot.exe
2011-02-04 12:23:42 ----D---- C:\ProgramData\Alwil Software
2011-02-04 12:23:42 ----D---- C:\Program Files\Alwil Software
2011-02-04 12:16:17 ----D---- C:\my
2011-02-04 12:13:25 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\Macromedia
2011-02-04 12:12:53 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\Adobe
2011-02-04 11:07:28 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\ATI
2011-02-04 11:07:28 ----D---- C:\ProgramData\ATI
2011-02-04 11:06:32 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\Intel Corporation
2011-02-04 11:05:43 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\Identities
2011-02-04 11:00:34 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\Hewlett-Packard
2011-02-04 11:00:14 ----D---- C:\ProgramData\Symantec
2011-02-04 11:00:14 ----D---- C:\Program Files (x86)\Symantec
2011-02-04 10:58:26 ----SHD---- C:\HPMBackup
2011-02-04 10:57:33 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\hpqLog
2011-02-04 10:56:01 ----D---- C:\ProgramData\WinZip
2011-02-04 10:56:00 ----D---- C:\Program Files (x86)\WinZip
2011-02-04 10:55:28 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\DigitalPersona
2011-02-04 10:55:08 ----SD---- C:\Users\Pavel Hlavatý\AppData\Roaming\Microsoft
2011-02-04 10:54:03 ----ASH---- C:\hiberfil.sys
======List of files/folders modified in the last 1 months======
2011-02-13 10:43:54 ----D---- C:\windows\Temp
2011-02-13 10:43:49 ----RD---- C:\Program Files
2011-02-13 10:20:16 ----SHD---- C:\System Volume Information
2011-02-13 10:04:59 ----D---- C:\windows\system32\drivers
2011-02-13 10:04:50 ----SHD---- C:\windows\Installer
2011-02-13 10:04:35 ----D---- C:\Windows
2011-02-13 10:04:34 ----D---- C:\windows\SysWOW64
2011-02-13 10:03:45 ----D---- C:\ProgramData\HPQLOG
2011-02-13 10:03:41 ----D---- C:\windows\system32\config
2011-02-13 10:03:21 ----A---- C:\windows\SYSWOW64\log.txt
2011-02-13 09:50:26 ----D---- C:\windows\system32\catroot2
2011-02-13 09:50:09 ----D---- C:\windows\winsxs
2011-02-13 09:48:48 ----D---- C:\windows\SYSWOW64\migration
2011-02-13 09:48:48 ----D---- C:\windows\system32\migration
2011-02-13 09:48:48 ----D---- C:\windows\System32
2011-02-13 09:48:48 ----D---- C:\Program Files\Internet Explorer
2011-02-13 09:48:48 ----D---- C:\Program Files (x86)\Internet Explorer
2011-02-12 21:17:17 ----RD---- C:\Program Files (x86)
2011-02-12 21:17:17 ----HD---- C:\ProgramData
2011-02-12 16:57:59 ----D---- C:\ProgramData\PDFC
2011-02-12 16:57:26 ----D---- C:\windows\Prefetch
2011-02-12 16:34:10 ----D---- C:\windows\Tasks
2011-02-12 16:34:10 ----D---- C:\windows\system32\wfp
2011-02-12 16:34:10 ----D---- C:\windows\system32\DriverStore
2011-02-12 16:34:10 ----D---- C:\windows\inf
2011-02-12 16:34:03 ----D---- C:\windows\system32\CodeIntegrity
2011-02-12 16:34:02 ----D---- C:\ProgramData\FLEXnet
2011-02-12 16:33:54 ----D---- C:\windows\system32\wbem
2011-02-12 16:33:54 ----D---- C:\windows\registration
2011-02-12 16:30:55 ----D---- C:\windows\system32\LogFiles
2011-02-09 17:22:55 ----D---- C:\windows\system32\Tasks
2011-02-09 16:07:15 ----D---- C:\windows\system32\catroot
2011-02-07 19:19:10 ----D---- C:\windows\SYSWOW64\winrm
2011-02-07 19:19:10 ----D---- C:\windows\SYSWOW64\slmgr
2011-02-07 19:19:10 ----D---- C:\windows\SYSWOW64\migwiz
2011-02-07 19:19:10 ----D---- C:\windows\SYSWOW64\en-US
2011-02-07 19:19:10 ----D---- C:\windows\SYSWOW64\en
2011-02-07 19:19:10 ----D---- C:\windows\SYSWOW64\drivers\en-US
2011-02-07 19:19:10 ----D---- C:\windows\SYSWOW64\drivers
2011-02-07 19:19:10 ----D---- C:\windows\servicing
2011-02-07 19:19:10 ----D---- C:\windows\ehome
2011-02-07 19:19:10 ----D---- C:\Program Files\Windows Sidebar
2011-02-07 19:19:10 ----D---- C:\Program Files\Windows Photo Viewer
2011-02-07 19:19:10 ----D---- C:\Program Files\Windows Media Player
2011-02-07 19:19:10 ----D---- C:\Program Files\Windows Mail
2011-02-07 19:19:10 ----D---- C:\Program Files\Windows Journal
2011-02-07 19:19:10 ----D---- C:\Program Files\Windows Defender
2011-02-07 19:19:10 ----D---- C:\Program Files\Common Files\System
2011-02-07 19:19:10 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-02-07 19:19:10 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-02-07 19:19:10 ----D---- C:\Program Files (x86)\Windows Media Player
2011-02-07 19:19:10 ----D---- C:\Program Files (x86)\Windows Mail
2011-02-07 19:19:10 ----D---- C:\Program Files (x86)\Windows Defender
2011-02-07 19:19:06 ----D---- C:\windows\SYSWOW64\sl-SI
2011-02-07 19:19:05 ----D---- C:\windows\SYSWOW64\WCN
2011-02-07 19:19:05 ----D---- C:\windows\SYSWOW64\wbem
2011-02-07 19:19:05 ----D---- C:\windows\SYSWOW64\Printing_Admin_Scripts
2011-02-07 19:19:05 ----D---- C:\windows\SYSWOW64\DriverStore
2011-02-07 19:19:05 ----D---- C:\windows\SYSWOW64\Dism
2011-02-07 19:19:04 ----D---- C:\windows\system32\winrm
2011-02-07 19:19:04 ----D---- C:\windows\system32\sysprep
2011-02-07 19:19:04 ----D---- C:\windows\system32\slmgr
2011-02-07 19:19:04 ----D---- C:\windows\system32\oobe
2011-02-07 19:19:04 ----D---- C:\windows\system32\migwiz
2011-02-07 19:19:04 ----D---- C:\windows\system32\en-US
2011-02-07 19:19:04 ----D---- C:\windows\system32\en
2011-02-07 19:19:04 ----D---- C:\windows\system32\Boot
2011-02-07 19:19:04 ----D---- C:\windows\PolicyDefinitions
2011-02-07 19:19:04 ----D---- C:\windows\en-US
2011-02-07 19:19:00 ----D---- C:\windows\system32\sl-SI
2011-02-07 19:18:58 ----D---- C:\windows\system32\WCN
2011-02-07 19:18:58 ----D---- C:\windows\system32\drivers\en-US
2011-02-07 19:18:58 ----D---- C:\windows\system32\Dism
2011-02-07 19:18:57 ----D---- C:\windows\system32\Printing_Admin_Scripts
2011-02-07 19:18:49 ----D---- C:\windows\SYSWOW64\sk-SK
2011-02-07 19:18:46 ----D---- C:\windows\system32\sk-SK
2011-02-07 19:18:39 ----D---- C:\windows\SYSWOW64\hr-HR
2011-02-07 19:18:37 ----D---- C:\windows\system32\hr-HR
2011-02-07 19:18:26 ----D---- C:\Program Files\DVD Maker
2011-02-07 19:18:15 ----D---- C:\windows\Speech
2011-02-07 18:29:18 ----D---- C:\windows\Logs
2011-02-07 17:59:33 ----D---- C:\windows\Microsoft.NET
2011-02-07 17:59:26 ----RSD---- C:\windows\assembly
2011-02-06 17:53:54 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-02-05 22:23:33 ----D---- C:\windows\SYSWOW64\cs-CZ
2011-02-05 22:23:33 ----D---- C:\windows\system32\cs-CZ
2011-02-05 22:23:17 ----D---- C:\windows\AppPatch
2011-02-05 19:21:10 ----RSD---- C:\windows\Fonts
2011-02-05 19:18:21 ----D---- C:\windows\SoftwareDistribution
2011-02-04 19:45:48 ----D---- C:\windows\Panther
2011-02-04 17:08:40 ----A---- C:\windows\system32\PerfStringBackup.INI
2011-02-04 16:56:46 ----D---- C:\Program Files (x86)\Hewlett-Packard
2011-02-04 15:53:22 ----D---- C:\Program Files (x86)\Common Files
2011-02-04 15:52:49 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-02-04 15:52:08 ----D---- C:\windows\ShellNew
2011-02-04 15:40:59 ----SD---- C:\ProgramData\Microsoft
2011-02-04 13:31:31 ----D---- C:\ProgramData\Skype
2011-02-04 13:21:29 ----HD---- C:\ProgramData\ArcSoft
2011-02-04 13:20:19 ----D---- C:\Program Files (x86)\Microsoft
2011-02-04 13:11:11 ----D---- C:\Program Files\Common Files\McAfee
2011-02-04 12:53:52 ----D---- C:\windows\system32\drivers\UMDF
2011-02-04 11:05:40 ----SHD---- C:\$Recycle.Bin
2011-02-04 11:00:31 ----RD---- C:\Program Files (x86)\Online Services
2011-02-04 11:00:07 ----HD---- C:\SYSTEM.SAV
2011-02-04 11:00:07 ----D---- C:\swsetup
2011-02-04 10:58:44 ----D---- C:\ProgramData\Hewlett-Packard
2011-02-04 10:58:33 ----D---- C:\Program Files\Hewlett-Packard
2011-02-04 10:55:07 ----RD---- C:\Users
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2009-07-08 30008]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2010-03-04 540696]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 SafeBoot;SafeBoot; C:\windows\system32\drivers\SafeBoot.sys [2009-12-16 56648]
R0 SbAlg;SbAlg; C:\windows\system32\drivers\SbAlg.sys [2009-06-04 60160]
R0 SbFsLock;SbFsLock; C:\windows\system32\drivers\SbFsLock.sys [2009-12-16 15688]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr.sys [2011-01-13 29264]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2011-01-13 273488]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2011-01-13 51792]
R1 RsvLock;RsvLock; C:\windows\system32\drivers\RsvLock.sys [2009-12-16 58184]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [2011-01-13 20560]
R2 aswMonFlt;aswMonFlt; \??\C:\windows\system32\drivers\aswMonFlt.sys [2011-01-13 62032]
R3 Accelerometer;HP Accelerometer; C:\windows\system32\DRIVERS\Accelerometer.sys [2009-07-08 41272]
R3 Afc;PPdus ASPI Shell; C:\windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2010-08-05 6859776]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2010-08-04 264192]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2009-12-04 32640]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\windows\system32\drivers\AtiHdmi.sys [2010-05-06 125456]
R3 HECIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2010-02-16 25912]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\windows\system32\DRIVERS\netr28x.sys [2010-06-29 931168]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2009-12-19 1803904]
R3 STHDA;IDT High Definition Audio CODEC; C:\windows\system32\DRIVERS\stwrt64.sys [2010-03-17 505856]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-06-04 1379376]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 BthEnum;Bluetooth Enumerator Service; C:\windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2010-06-24 552448]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2010-06-24 80384]
S3 BTMCOM;Bluetooth Serial Port; C:\windows\System32\Drivers\btmcom.sys [2010-04-10 52736]
S3 BTMUSB;Motorola Bluetooth Radio Service; C:\windows\System32\Drivers\btmusb.sys [2010-06-29 3232768]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys [2009-10-21 40760]
S3 pciide;pciide; C:\windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2009-11-11 232480]
S3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2010-01-12 325152]
S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2009-07-14 109056]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe [2009-03-03 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2010-08-05 203264]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-01-13 40384]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2010-05-20 677128]
R2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2009-11-25 462088]
R2 HP Health Check Service;HP Health Check Service; C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [2010-06-30 121344]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2010-06-19 103992]
R2 HP ProtectTools Service;HP ProtectTools Service; c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2009-11-18 36864]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-04-05 103992]
R2 HPDayStarterService;HP DayStarter Service; c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe [2010-05-10 90112]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-06-25 92216]
R2 HpFkCryptService;Drive Encryption Service; c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-12-16 281192]
R2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2009-12-12 297984]
R2 hpHotkeyMonitor;HP Hotkey Monitor; C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [2010-03-01 264248]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2009-07-08 30520]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2009-06-17 73728]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-11-04 268824]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2009-10-23 635416]
R2 STacSV;Audio Service; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\STacSV64.exe [2010-03-17 244736]
R2 uArcCapture;ArcCapture; C:\windows\system\uArcCapture.exe [2009-12-04 506472]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-04 2320920]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2010-06-29 4181256]
R3 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2010-05-20 1096968]
R3 DEBridge;DEBridge; c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe [2009-12-16 704512]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-12-05 1028096]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2010-06-25 665656]
S2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2009-12-14 2019120]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; c:\Windows\SysWOW64\flcdlock.exe [2009-11-17 362040]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-12-05 647680]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-02-04 407336]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2011-02-05 1255736]
-----------------EOF-----------------
Run by Pavel Hlavatý at 2011-02-13 10:43:48
Microsoft Windows 7 Home Premium
System drive C: has 546 GB (92%) free of 593 GB
Total RAM: 3951 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:43:56, on 13.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
C:\Program Files\QIP 2010\qip.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\Pavel Hlavatý.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [DTRun] c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O15 - Trusted Zone: http://*.mcafee.com (HKLM)
O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)
O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bluetooth Device Manager - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: DEBridge - McAfee, Inc. - c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - c:\Windows\SysWOW64\flcdlock.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: HP Hotkey Monitor (hpHotkeyMonitor) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\system\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12311 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe"
"c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe"
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
winlogon.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\STacSV64.exe
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\Hpservice.exe
atieclxx
C:\windows\system32\svchost.exe -k NetworkService
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
C:\windows\System32\spoolsv.exe
"taskhost.exe"
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\System32\rundll32.exe" "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" /start
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe"
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe
"C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe"
"c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe"
"c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
C:\windows\system\uArcCapture.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\Motorola\Bluetooth\obexsrv.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe"
C:\windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe"
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Motorola\Bluetooth\audiosrv.exe"
"c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe"
"C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe" -Embedding
WLIDSvcM.exe 2948
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe" /hidden
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe"
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\windows\System32\svchost.exe -k secsvcs
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe" "<hpNotification><Toast><Title>HP Wireless Assistant</Title><Text>Combo: On</Text><IconPath>C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WA_tray_32_on.ico</IconPath><ID>669508837</ID><Path>C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe</Path><Parameters></Parameters></Toast></hpNotification>"
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /welcome
"C:\windows\system32\wuauclt.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
taskeng.exe {F0546A48-5401-4E30-AA64-618502C2949D}
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe" /L Analysis
"C:\Program Files\QIP 2010\qip.exe"
C:\windows\System32\svchost.exe -k swprv
"C:\Program Files\Mozilla Firefox\firefox.exe"
"C:\Program Files\Mozilla Firefox\plugin-container.exe" --channel=6000.9bf3fa0.388846287 "C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll" 6000 plugin \\.\pipe\gecko-crash-server-pipe.6000
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Users\Pavel Hlavatý\Downloads\RSITx64.exe"
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP ProtectTools Security Manager Extension - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2009-12-03 2187528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2009-12-12 117248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP ProtectTools Security Manager Extension - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2009-12-03 1471752]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HPPowerAssistant"=C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2010-06-19 1691192]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-04 2174760]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe [2010-04-05 8192]
"BTMTrayAgent"=C:\Program Files\Motorola\Bluetooth\btmshell.dll [2010-06-11 24783624]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2010-03-17 487424]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2010-03-01 256056]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2010-03-04 284696]
"PDF Complete"=C:\Program Files (x86)\PDF Complete\pdfsty.exe [2009-10-23 563736]
"File Sanitizer"=C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2009-12-12 11265536]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-08-05 98304]
"DTRun"=c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [2009-11-19 518656]
"NortonOnlineBackupReminder"=C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe [2009-06-29 600936]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-01-13 3396624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-02-13 10:43:49 ----D---- C:\Program Files\trend micro
2011-02-13 10:43:48 ----D---- C:\rsit
2011-02-13 10:04:59 ----A---- C:\windows\system32\drivers\aswSP.sys
2011-02-13 10:04:59 ----A---- C:\windows\system32\drivers\aswFsBlk.sys
2011-02-13 10:04:56 ----A---- C:\windows\system32\drivers\aswRdr.sys
2011-02-13 10:04:54 ----A---- C:\windows\system32\drivers\aswTdi.sys
2011-02-13 10:04:53 ----A---- C:\windows\system32\drivers\aswMonFlt.sys
2011-02-13 10:04:34 ----A---- C:\windows\SYSWOW64\aswBoot.exe
2011-02-12 21:17:17 ----D---- C:\ProgramData\Spybot - Search & Destroy
2011-02-12 21:17:17 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy
2011-02-12 20:54:29 ----A---- C:\windows\SYSWOW64\mshtml.dll
2011-02-12 20:54:29 ----A---- C:\windows\system32\mshtml.dll
2011-02-12 20:54:28 ----A---- C:\windows\system32\wininet.dll
2011-02-12 20:54:28 ----A---- C:\windows\system32\urlmon.dll
2011-02-12 20:54:27 ----A---- C:\windows\SYSWOW64\wininet.dll
2011-02-12 20:54:27 ----A---- C:\windows\SYSWOW64\urlmon.dll
2011-02-12 20:54:27 ----A---- C:\windows\SYSWOW64\ieframe.dll
2011-02-12 20:54:26 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2011-02-12 20:54:26 ----A---- C:\windows\system32\ieframe.dll
2011-02-12 20:54:24 ----A---- C:\windows\SYSWOW64\mstime.dll
2011-02-12 20:54:24 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2011-02-12 20:54:24 ----A---- C:\windows\system32\mstime.dll
2011-02-12 20:54:24 ----A---- C:\windows\system32\msfeeds.dll
2011-02-12 20:54:24 ----A---- C:\windows\system32\ieui.dll
2011-02-12 20:54:24 ----A---- C:\windows\system32\iertutil.dll
2011-02-12 20:54:24 ----A---- C:\windows\system32\iedkcs32.dll
2011-02-12 20:54:23 ----A---- C:\windows\SYSWOW64\ieui.dll
2011-02-12 20:54:23 ----A---- C:\windows\SYSWOW64\iertutil.dll
2011-02-12 20:54:23 ----A---- C:\windows\system32\iepeers.dll
2011-02-12 20:54:17 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2011-02-12 20:54:17 ----A---- C:\windows\SYSWOW64\msfeedsbs.dll
2011-02-12 20:54:17 ----A---- C:\windows\SYSWOW64\iepeers.dll
2011-02-12 20:54:17 ----A---- C:\windows\system32\mshtmled.dll
2011-02-12 20:54:17 ----A---- C:\windows\system32\msfeedsbs.dll
2011-02-12 20:54:16 ----A---- C:\windows\SYSWOW64\msfeedssync.exe
2011-02-12 20:54:16 ----A---- C:\windows\SYSWOW64\licmgr10.dll
2011-02-12 20:54:16 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2011-02-12 20:54:16 ----A---- C:\windows\system32\msfeedssync.exe
2011-02-12 20:54:16 ----A---- C:\windows\system32\licmgr10.dll
2011-02-12 20:54:16 ----A---- C:\windows\system32\jsproxy.dll
2011-02-12 20:54:09 ----A---- C:\windows\SYSWOW64\d3d10warp.dll
2011-02-12 20:54:09 ----A---- C:\windows\system32\d3d10warp.dll
2011-02-12 20:54:09 ----A---- C:\windows\system32\d2d1.dll
2011-02-12 20:54:08 ----A---- C:\windows\SYSWOW64\d2d1.dll
2011-02-12 20:54:08 ----A---- C:\windows\system32\WMVDECOD.DLL
2011-02-12 20:54:08 ----A---- C:\windows\system32\mf.dll
2011-02-12 20:54:08 ----A---- C:\windows\system32\DWrite.dll
2011-02-12 20:54:07 ----A---- C:\windows\SYSWOW64\mf.dll
2011-02-12 20:54:07 ----A---- C:\windows\SYSWOW64\DWrite.dll
2011-02-12 20:54:07 ----A---- C:\windows\system32\XpsPrint.dll
2011-02-12 20:54:07 ----A---- C:\windows\system32\FntCache.dll
2011-02-12 20:54:06 ----A---- C:\windows\SYSWOW64\XpsPrint.dll
2011-02-12 20:54:04 ----A---- C:\windows\system32\XpsGdiConverter.dll
2011-02-12 20:54:04 ----A---- C:\windows\system32\ExplorerFrame.dll
2011-02-12 20:54:03 ----A---- C:\windows\SYSWOW64\XpsGdiConverter.dll
2011-02-12 20:54:03 ----A---- C:\windows\SYSWOW64\WMVDECOD.DLL
2011-02-12 20:54:03 ----A---- C:\windows\SYSWOW64\d3d10_1core.dll
2011-02-12 20:54:03 ----A---- C:\windows\system32\drivers\dxgkrnl.sys
2011-02-12 20:54:03 ----A---- C:\windows\system32\d3d10_1core.dll
2011-02-12 20:54:02 ----A---- C:\windows\SYSWOW64\XpsRasterService.dll
2011-02-12 20:54:02 ----A---- C:\windows\SYSWOW64\mfreadwrite.dll
2011-02-12 20:54:02 ----A---- C:\windows\SYSWOW64\ExplorerFrame.dll
2011-02-12 20:54:02 ----A---- C:\windows\SYSWOW64\d3d10_1.dll
2011-02-12 20:54:02 ----A---- C:\windows\system32\XpsRasterService.dll
2011-02-12 20:54:02 ----A---- C:\windows\system32\mfreadwrite.dll
2011-02-12 20:54:02 ----A---- C:\windows\system32\mfps.dll
2011-02-12 20:54:02 ----A---- C:\windows\system32\drivers\dxgmms1.sys
2011-02-12 20:54:02 ----A---- C:\windows\system32\d3d10_1.dll
2011-02-12 20:54:02 ----A---- C:\windows\system32\cdd.dll
2011-02-12 20:53:58 ----A---- C:\windows\system32\win32k.sys
2011-02-12 20:53:56 ----A---- C:\windows\system32\winsrv.dll
2011-02-12 20:53:55 ----A---- C:\windows\SYSWOW64\kerberos.dll
2011-02-12 20:53:55 ----A---- C:\windows\system32\kerberos.dll
2011-02-12 20:53:53 ----A---- C:\windows\SYSWOW64\vbscript.dll
2011-02-12 20:53:53 ----A---- C:\windows\SYSWOW64\jscript.dll
2011-02-12 20:53:53 ----A---- C:\windows\system32\vbscript.dll
2011-02-12 20:53:53 ----A---- C:\windows\system32\jscript.dll
2011-02-12 20:53:51 ----A---- C:\windows\system32\ntoskrnl.exe
2011-02-12 20:53:51 ----A---- C:\windows\system32\ntdll.dll
2011-02-12 20:53:50 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2011-02-12 20:53:50 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2011-02-12 20:53:50 ----A---- C:\windows\SYSWOW64\ntdll.dll
2011-02-05 22:23:18 ----D---- C:\windows\SYSWOW64\Wat
2011-02-05 22:23:18 ----D---- C:\windows\system32\Wat
2011-02-05 19:25:00 ----A---- C:\windows\SYSWOW64\PresentationHostProxy.dll
2011-02-05 19:25:00 ----A---- C:\windows\SYSWOW64\PresentationHost.exe
2011-02-05 19:25:00 ----A---- C:\windows\SYSWOW64\netfxperf.dll
2011-02-05 19:25:00 ----A---- C:\windows\SYSWOW64\mscoree.dll
2011-02-05 19:25:00 ----A---- C:\windows\SYSWOW64\dfshim.dll
2011-02-05 19:25:00 ----A---- C:\windows\system32\PresentationHostProxy.dll
2011-02-05 19:25:00 ----A---- C:\windows\system32\PresentationHost.exe
2011-02-05 19:25:00 ----A---- C:\windows\system32\netfxperf.dll
2011-02-05 19:25:00 ----A---- C:\windows\system32\mscoree.dll
2011-02-05 19:24:59 ----A---- C:\windows\system32\dfshim.dll
2011-02-05 19:24:48 ----A---- C:\windows\system32\browserchoice.exe
2011-02-05 19:18:11 ----A---- C:\windows\system32\drivers\usbvideo.sys
2011-02-05 19:18:11 ----A---- C:\windows\system32\drivers\ks.sys
2011-02-05 19:16:52 ----D---- C:\Program Files (x86)\SopCast
2011-02-05 18:44:35 ----D---- C:\Program Files (x86)\Age of Empires
2011-02-05 09:26:35 ----A---- C:\windows\system32\wmp.dll
2011-02-05 09:26:33 ----A---- C:\windows\SYSWOW64\wmp.dll
2011-02-05 09:26:31 ----A---- C:\windows\SYSWOW64\wmploc.DLL
2011-02-05 09:26:30 ----A---- C:\windows\system32\wmploc.DLL
2011-02-05 09:26:28 ----A---- C:\windows\SYSWOW64\tzres.dll
2011-02-05 09:26:28 ----A---- C:\windows\system32\tzres.dll
2011-02-05 09:26:19 ----A---- C:\windows\SYSWOW64\t2embed.dll
2011-02-05 09:26:19 ----A---- C:\windows\system32\t2embed.dll
2011-02-05 09:26:16 ----A---- C:\windows\system32\ole32.dll
2011-02-05 09:26:13 ----A---- C:\windows\SYSWOW64\ole32.dll
2011-02-05 09:26:13 ----A---- C:\windows\system32\schedsvc.dll
2011-02-05 09:26:12 ----A---- C:\windows\SYSWOW64\taskschd.dll
2011-02-05 09:26:12 ----A---- C:\windows\SYSWOW64\taskeng.exe
2011-02-05 09:26:12 ----A---- C:\windows\SYSWOW64\taskcomp.dll
2011-02-05 09:26:12 ----A---- C:\windows\system32\wmicmiplugin.dll
2011-02-05 09:26:12 ----A---- C:\windows\system32\taskschd.dll
2011-02-05 09:26:12 ----A---- C:\windows\system32\taskeng.exe
2011-02-05 09:26:12 ----A---- C:\windows\system32\taskcomp.dll
2011-02-05 09:26:12 ----A---- C:\windows\system32\schtasks.exe
2011-02-05 09:26:11 ----A---- C:\windows\SYSWOW64\schtasks.exe
2011-02-05 09:26:09 ----A---- C:\windows\SYSWOW64\StructuredQuery.dll
2011-02-05 09:26:09 ----A---- C:\windows\system32\StructuredQuery.dll
2011-02-05 09:26:08 ----A---- C:\windows\SYSWOW64\atmfd.dll
2011-02-05 09:26:08 ----A---- C:\windows\system32\atmfd.dll
2011-02-05 09:26:07 ----A---- C:\windows\SYSWOW64\atmlib.dll
2011-02-05 09:26:07 ----A---- C:\windows\system32\atmlib.dll
2011-02-05 09:25:57 ----A---- C:\windows\system32\shell32.dll
2011-02-05 09:25:55 ----A---- C:\windows\SYSWOW64\shell32.dll
2011-02-05 09:25:52 ----A---- C:\windows\SYSWOW64\inetcomm.dll
2011-02-05 09:25:52 ----A---- C:\windows\system32\inetcomm.dll
2011-02-05 09:25:49 ----A---- C:\windows\SYSWOW64\CPFilters.dll
2011-02-05 09:25:49 ----A---- C:\windows\system32\CPFilters.dll
2011-02-05 09:25:48 ----A---- C:\windows\system32\msdri.dll
2011-02-05 09:25:45 ----A---- C:\windows\system32\drivers\tcpip.sys
2011-02-05 09:25:42 ----A---- C:\windows\SYSWOW64\schannel.dll
2011-02-05 09:25:42 ----A---- C:\windows\system32\schannel.dll
2011-02-05 09:25:39 ----A---- C:\windows\SYSWOW64\comctl32.dll
2011-02-05 09:25:39 ----A---- C:\windows\system32\comctl32.dll
2011-02-05 09:25:38 ----A---- C:\windows\SYSWOW64\oleaut32.dll
2011-02-05 09:25:38 ----A---- C:\windows\system32\oleaut32.dll
2011-02-05 09:25:36 ----A---- C:\windows\SYSWOW64\rtutils.dll
2011-02-05 09:25:36 ----A---- C:\windows\system32\rtutils.dll
2011-02-05 09:25:29 ----A---- C:\windows\system32\spoolsv.exe
2011-02-05 09:25:27 ----A---- C:\windows\SYSWOW64\webio.dll
2011-02-05 09:25:27 ----A---- C:\windows\SYSWOW64\iccvid.dll
2011-02-05 09:25:27 ----A---- C:\windows\system32\webio.dll
2011-02-05 09:25:27 ----A---- C:\windows\system32\drivers\fvevol.sys
2011-02-05 09:25:22 ----A---- C:\windows\SYSWOW64\wmpmde.dll
2011-02-05 09:25:22 ----A---- C:\windows\system32\wmpmde.dll
2011-02-05 09:25:11 ----A---- C:\windows\SYSWOW64\msxml3.dll
2011-02-05 09:25:11 ----A---- C:\windows\system32\msxml3.dll
2011-02-05 09:25:10 ----A---- C:\windows\SYSWOW64\mfc40u.dll
2011-02-05 09:25:10 ----A---- C:\windows\SYSWOW64\mfc40.dll
2011-02-05 09:25:10 ----A---- C:\windows\system32\drivers\Diskdump.sys
2011-02-05 09:25:10 ----A---- C:\windows\system32\consent.exe
2011-02-05 09:25:09 ----A---- C:\windows\SYSWOW64\odbc32.dll
2011-02-05 09:25:09 ----A---- C:\windows\system32\odbc32.dll
2011-02-05 09:25:08 ----A---- C:\windows\system32\srvsvc.dll
2011-02-05 09:25:08 ----A---- C:\windows\system32\drivers\srv2.sys
2011-02-05 09:25:08 ----A---- C:\windows\system32\drivers\srv.sys
2011-02-05 09:25:07 ----A---- C:\windows\SYSWOW64\sscore.dll
2011-02-05 09:25:07 ----A---- C:\windows\system32\drivers\srvnet.sys
2011-02-04 19:47:56 ----D---- C:\windows\rescache
2011-02-04 19:45:04 ----ASH---- C:\pagefile.sys
2011-02-04 18:42:53 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\IObit
2011-02-04 18:42:53 ----D---- C:\Program Files (x86)\Advanced SystemCare 3
2011-02-04 17:30:48 ----D---- C:\xProjekty
2011-02-04 17:23:43 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\WinRAR
2011-02-04 15:53:35 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-02-04 15:53:30 ----D---- C:\Program Files (x86)\Microsoft Works
2011-02-04 15:53:14 ----D---- C:\windows\PCHEALTH
2011-02-04 15:53:14 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-02-04 15:52:11 ----D---- C:\Program Files\Microsoft Office
2011-02-04 15:49:03 ----D---- C:\Program Files (x86)\Microsoft Office
2011-02-04 15:48:10 ----RHD---- C:\MSOCache
2011-02-04 15:24:37 ----D---- C:\ProgramData\VirtualizedApplications
2011-02-04 13:56:53 ----D---- C:\Program Files (x86)\Counter-Strike 1.6
2011-02-04 13:51:58 ----D---- C:\Program Files\CCleaner
2011-02-04 13:40:46 ----D---- C:\Program Files\QIP 2010
2011-02-04 13:36:58 ----D---- C:\Program Files (x86)\WinRAR
2011-02-04 13:32:32 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\skypePM
2011-02-04 13:31:33 ----RD---- C:\Program Files (x86)\Skype
2011-02-04 13:31:33 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\Skype
2011-02-04 13:26:48 ----D---- C:\Program Files (x86)\The KMPlayer
2011-02-04 13:21:28 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\ArcSoft
2011-02-04 13:19:00 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\Mozilla
2011-02-04 13:18:56 ----D---- C:\Program Files\Mozilla Firefox
2011-02-04 13:15:53 ----A---- C:\windows\myClean.bat
2011-02-04 13:02:42 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\CorelHomeOffice
2011-02-04 13:02:31 ----RSH---- C:\ProgramData\1EFDA7FD4F.sys
2011-02-04 13:02:31 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\Corel
2011-02-04 13:02:29 ----ASH---- C:\ProgramData\KGyGaAvL.sys
2011-02-04 12:59:56 ----D---- C:\ProgramData\Microsoft Help
2011-02-04 12:58:54 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\SoftGrid Client
2011-02-04 12:58:35 ----N---- C:\windows\system32\MpSigStub.exe
2011-02-04 12:58:16 ----A---- C:\windows\SYSWOW64\PerfStringBackup.INI
2011-02-04 12:57:54 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\TP
2011-02-04 12:24:06 ----A---- C:\windows\system32\aswBoot.exe
2011-02-04 12:23:42 ----D---- C:\ProgramData\Alwil Software
2011-02-04 12:23:42 ----D---- C:\Program Files\Alwil Software
2011-02-04 12:16:17 ----D---- C:\my
2011-02-04 12:13:25 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\Macromedia
2011-02-04 12:12:53 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\Adobe
2011-02-04 11:07:28 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\ATI
2011-02-04 11:07:28 ----D---- C:\ProgramData\ATI
2011-02-04 11:06:32 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\Intel Corporation
2011-02-04 11:05:43 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\Identities
2011-02-04 11:00:34 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\Hewlett-Packard
2011-02-04 11:00:14 ----D---- C:\ProgramData\Symantec
2011-02-04 11:00:14 ----D---- C:\Program Files (x86)\Symantec
2011-02-04 10:58:26 ----SHD---- C:\HPMBackup
2011-02-04 10:57:33 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\hpqLog
2011-02-04 10:56:01 ----D---- C:\ProgramData\WinZip
2011-02-04 10:56:00 ----D---- C:\Program Files (x86)\WinZip
2011-02-04 10:55:28 ----D---- C:\Users\Pavel Hlavatý\AppData\Roaming\DigitalPersona
2011-02-04 10:55:08 ----SD---- C:\Users\Pavel Hlavatý\AppData\Roaming\Microsoft
2011-02-04 10:54:03 ----ASH---- C:\hiberfil.sys
======List of files/folders modified in the last 1 months======
2011-02-13 10:43:54 ----D---- C:\windows\Temp
2011-02-13 10:43:49 ----RD---- C:\Program Files
2011-02-13 10:20:16 ----SHD---- C:\System Volume Information
2011-02-13 10:04:59 ----D---- C:\windows\system32\drivers
2011-02-13 10:04:50 ----SHD---- C:\windows\Installer
2011-02-13 10:04:35 ----D---- C:\Windows
2011-02-13 10:04:34 ----D---- C:\windows\SysWOW64
2011-02-13 10:03:45 ----D---- C:\ProgramData\HPQLOG
2011-02-13 10:03:41 ----D---- C:\windows\system32\config
2011-02-13 10:03:21 ----A---- C:\windows\SYSWOW64\log.txt
2011-02-13 09:50:26 ----D---- C:\windows\system32\catroot2
2011-02-13 09:50:09 ----D---- C:\windows\winsxs
2011-02-13 09:48:48 ----D---- C:\windows\SYSWOW64\migration
2011-02-13 09:48:48 ----D---- C:\windows\system32\migration
2011-02-13 09:48:48 ----D---- C:\windows\System32
2011-02-13 09:48:48 ----D---- C:\Program Files\Internet Explorer
2011-02-13 09:48:48 ----D---- C:\Program Files (x86)\Internet Explorer
2011-02-12 21:17:17 ----RD---- C:\Program Files (x86)
2011-02-12 21:17:17 ----HD---- C:\ProgramData
2011-02-12 16:57:59 ----D---- C:\ProgramData\PDFC
2011-02-12 16:57:26 ----D---- C:\windows\Prefetch
2011-02-12 16:34:10 ----D---- C:\windows\Tasks
2011-02-12 16:34:10 ----D---- C:\windows\system32\wfp
2011-02-12 16:34:10 ----D---- C:\windows\system32\DriverStore
2011-02-12 16:34:10 ----D---- C:\windows\inf
2011-02-12 16:34:03 ----D---- C:\windows\system32\CodeIntegrity
2011-02-12 16:34:02 ----D---- C:\ProgramData\FLEXnet
2011-02-12 16:33:54 ----D---- C:\windows\system32\wbem
2011-02-12 16:33:54 ----D---- C:\windows\registration
2011-02-12 16:30:55 ----D---- C:\windows\system32\LogFiles
2011-02-09 17:22:55 ----D---- C:\windows\system32\Tasks
2011-02-09 16:07:15 ----D---- C:\windows\system32\catroot
2011-02-07 19:19:10 ----D---- C:\windows\SYSWOW64\winrm
2011-02-07 19:19:10 ----D---- C:\windows\SYSWOW64\slmgr
2011-02-07 19:19:10 ----D---- C:\windows\SYSWOW64\migwiz
2011-02-07 19:19:10 ----D---- C:\windows\SYSWOW64\en-US
2011-02-07 19:19:10 ----D---- C:\windows\SYSWOW64\en
2011-02-07 19:19:10 ----D---- C:\windows\SYSWOW64\drivers\en-US
2011-02-07 19:19:10 ----D---- C:\windows\SYSWOW64\drivers
2011-02-07 19:19:10 ----D---- C:\windows\servicing
2011-02-07 19:19:10 ----D---- C:\windows\ehome
2011-02-07 19:19:10 ----D---- C:\Program Files\Windows Sidebar
2011-02-07 19:19:10 ----D---- C:\Program Files\Windows Photo Viewer
2011-02-07 19:19:10 ----D---- C:\Program Files\Windows Media Player
2011-02-07 19:19:10 ----D---- C:\Program Files\Windows Mail
2011-02-07 19:19:10 ----D---- C:\Program Files\Windows Journal
2011-02-07 19:19:10 ----D---- C:\Program Files\Windows Defender
2011-02-07 19:19:10 ----D---- C:\Program Files\Common Files\System
2011-02-07 19:19:10 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-02-07 19:19:10 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-02-07 19:19:10 ----D---- C:\Program Files (x86)\Windows Media Player
2011-02-07 19:19:10 ----D---- C:\Program Files (x86)\Windows Mail
2011-02-07 19:19:10 ----D---- C:\Program Files (x86)\Windows Defender
2011-02-07 19:19:06 ----D---- C:\windows\SYSWOW64\sl-SI
2011-02-07 19:19:05 ----D---- C:\windows\SYSWOW64\WCN
2011-02-07 19:19:05 ----D---- C:\windows\SYSWOW64\wbem
2011-02-07 19:19:05 ----D---- C:\windows\SYSWOW64\Printing_Admin_Scripts
2011-02-07 19:19:05 ----D---- C:\windows\SYSWOW64\DriverStore
2011-02-07 19:19:05 ----D---- C:\windows\SYSWOW64\Dism
2011-02-07 19:19:04 ----D---- C:\windows\system32\winrm
2011-02-07 19:19:04 ----D---- C:\windows\system32\sysprep
2011-02-07 19:19:04 ----D---- C:\windows\system32\slmgr
2011-02-07 19:19:04 ----D---- C:\windows\system32\oobe
2011-02-07 19:19:04 ----D---- C:\windows\system32\migwiz
2011-02-07 19:19:04 ----D---- C:\windows\system32\en-US
2011-02-07 19:19:04 ----D---- C:\windows\system32\en
2011-02-07 19:19:04 ----D---- C:\windows\system32\Boot
2011-02-07 19:19:04 ----D---- C:\windows\PolicyDefinitions
2011-02-07 19:19:04 ----D---- C:\windows\en-US
2011-02-07 19:19:00 ----D---- C:\windows\system32\sl-SI
2011-02-07 19:18:58 ----D---- C:\windows\system32\WCN
2011-02-07 19:18:58 ----D---- C:\windows\system32\drivers\en-US
2011-02-07 19:18:58 ----D---- C:\windows\system32\Dism
2011-02-07 19:18:57 ----D---- C:\windows\system32\Printing_Admin_Scripts
2011-02-07 19:18:49 ----D---- C:\windows\SYSWOW64\sk-SK
2011-02-07 19:18:46 ----D---- C:\windows\system32\sk-SK
2011-02-07 19:18:39 ----D---- C:\windows\SYSWOW64\hr-HR
2011-02-07 19:18:37 ----D---- C:\windows\system32\hr-HR
2011-02-07 19:18:26 ----D---- C:\Program Files\DVD Maker
2011-02-07 19:18:15 ----D---- C:\windows\Speech
2011-02-07 18:29:18 ----D---- C:\windows\Logs
2011-02-07 17:59:33 ----D---- C:\windows\Microsoft.NET
2011-02-07 17:59:26 ----RSD---- C:\windows\assembly
2011-02-06 17:53:54 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-02-05 22:23:33 ----D---- C:\windows\SYSWOW64\cs-CZ
2011-02-05 22:23:33 ----D---- C:\windows\system32\cs-CZ
2011-02-05 22:23:17 ----D---- C:\windows\AppPatch
2011-02-05 19:21:10 ----RSD---- C:\windows\Fonts
2011-02-05 19:18:21 ----D---- C:\windows\SoftwareDistribution
2011-02-04 19:45:48 ----D---- C:\windows\Panther
2011-02-04 17:08:40 ----A---- C:\windows\system32\PerfStringBackup.INI
2011-02-04 16:56:46 ----D---- C:\Program Files (x86)\Hewlett-Packard
2011-02-04 15:53:22 ----D---- C:\Program Files (x86)\Common Files
2011-02-04 15:52:49 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-02-04 15:52:08 ----D---- C:\windows\ShellNew
2011-02-04 15:40:59 ----SD---- C:\ProgramData\Microsoft
2011-02-04 13:31:31 ----D---- C:\ProgramData\Skype
2011-02-04 13:21:29 ----HD---- C:\ProgramData\ArcSoft
2011-02-04 13:20:19 ----D---- C:\Program Files (x86)\Microsoft
2011-02-04 13:11:11 ----D---- C:\Program Files\Common Files\McAfee
2011-02-04 12:53:52 ----D---- C:\windows\system32\drivers\UMDF
2011-02-04 11:05:40 ----SHD---- C:\$Recycle.Bin
2011-02-04 11:00:31 ----RD---- C:\Program Files (x86)\Online Services
2011-02-04 11:00:07 ----HD---- C:\SYSTEM.SAV
2011-02-04 11:00:07 ----D---- C:\swsetup
2011-02-04 10:58:44 ----D---- C:\ProgramData\Hewlett-Packard
2011-02-04 10:58:33 ----D---- C:\Program Files\Hewlett-Packard
2011-02-04 10:55:07 ----RD---- C:\Users
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2009-07-08 30008]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2010-03-04 540696]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 SafeBoot;SafeBoot; C:\windows\system32\drivers\SafeBoot.sys [2009-12-16 56648]
R0 SbAlg;SbAlg; C:\windows\system32\drivers\SbAlg.sys [2009-06-04 60160]
R0 SbFsLock;SbFsLock; C:\windows\system32\drivers\SbFsLock.sys [2009-12-16 15688]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr.sys [2011-01-13 29264]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2011-01-13 273488]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2011-01-13 51792]
R1 RsvLock;RsvLock; C:\windows\system32\drivers\RsvLock.sys [2009-12-16 58184]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [2011-01-13 20560]
R2 aswMonFlt;aswMonFlt; \??\C:\windows\system32\drivers\aswMonFlt.sys [2011-01-13 62032]
R3 Accelerometer;HP Accelerometer; C:\windows\system32\DRIVERS\Accelerometer.sys [2009-07-08 41272]
R3 Afc;PPdus ASPI Shell; C:\windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2010-08-05 6859776]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2010-08-04 264192]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2009-12-04 32640]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\windows\system32\drivers\AtiHdmi.sys [2010-05-06 125456]
R3 HECIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2010-02-16 25912]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\windows\system32\DRIVERS\netr28x.sys [2010-06-29 931168]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2009-12-19 1803904]
R3 STHDA;IDT High Definition Audio CODEC; C:\windows\system32\DRIVERS\stwrt64.sys [2010-03-17 505856]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-06-04 1379376]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 BthEnum;Bluetooth Enumerator Service; C:\windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2010-06-24 552448]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2010-06-24 80384]
S3 BTMCOM;Bluetooth Serial Port; C:\windows\System32\Drivers\btmcom.sys [2010-04-10 52736]
S3 BTMUSB;Motorola Bluetooth Radio Service; C:\windows\System32\Drivers\btmusb.sys [2010-06-29 3232768]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys [2009-10-21 40760]
S3 pciide;pciide; C:\windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2009-11-11 232480]
S3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2010-01-12 325152]
S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2009-07-14 109056]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe [2009-03-03 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2010-08-05 203264]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-01-13 40384]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2010-05-20 677128]
R2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2009-11-25 462088]
R2 HP Health Check Service;HP Health Check Service; C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [2010-06-30 121344]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2010-06-19 103992]
R2 HP ProtectTools Service;HP ProtectTools Service; c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2009-11-18 36864]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-04-05 103992]
R2 HPDayStarterService;HP DayStarter Service; c:\Program Files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe [2010-05-10 90112]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-06-25 92216]
R2 HpFkCryptService;Drive Encryption Service; c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-12-16 281192]
R2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2009-12-12 297984]
R2 hpHotkeyMonitor;HP Hotkey Monitor; C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [2010-03-01 264248]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2009-07-08 30520]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2009-06-17 73728]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-11-04 268824]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2009-10-23 635416]
R2 STacSV;Audio Service; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\STacSV64.exe [2010-03-17 244736]
R2 uArcCapture;ArcCapture; C:\windows\system\uArcCapture.exe [2009-12-04 506472]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-04 2320920]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2010-06-29 4181256]
R3 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2010-05-20 1096968]
R3 DEBridge;DEBridge; c:\Program Files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe [2009-12-16 704512]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-12-05 1028096]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2010-06-25 665656]
S2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2009-12-14 2019120]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; c:\Windows\SysWOW64\flcdlock.exe [2009-11-17 362040]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-12-05 647680]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-02-04 407336]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2011-02-05 1255736]
-----------------EOF-----------------
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Průzkumník se spustí sám po startu
PROSIM CITAJTE POZORNE NAVOD!!!,
Použij ComboFix podle tohoto návodu: http://www.bleepingcomputer.com/combofi ... t-combofix
Log znej vloz sem.
Použij ComboFix podle tohoto návodu: http://www.bleepingcomputer.com/combofi ... t-combofix
Log znej vloz sem.
Re: Průzkumník se spustí sám po startu
Tak už jsem to udělal. Snad to pomůže.
ComboFix 11-02-12.02 - Pavel Hlavatý 13.02.2011 11:42:18.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.3951.2786 [GMT 1:00]
Spuštěný z: c:\users\Pavel Hlavatý\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-13 do 2011-02-13 )))))))))))))))))))))))))))))))
.
2011-02-13 09:43 . 2011-02-13 10:38 -------- d-----w- c:\program files\trend micro
2011-02-13 09:43 . 2011-02-13 09:43 -------- d-----w- C:\rsit
2011-02-12 20:17 . 2011-02-12 20:36 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-02-12 20:17 . 2011-02-12 20:18 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2011-02-12 19:53 . 2011-01-05 04:00 3127808 ----a-w- c:\windows\system32\win32k.sys
2011-02-12 19:53 . 2010-12-21 06:16 214016 ----a-w- c:\windows\system32\winsrv.dll
2011-02-12 19:53 . 2010-12-18 06:11 714752 ----a-w- c:\windows\system32\kerberos.dll
2011-02-12 19:53 . 2010-12-18 05:29 541184 ----a-w- c:\windows\SysWow64\kerberos.dll
2011-02-12 19:53 . 2011-01-05 06:20 612352 ----a-w- c:\windows\system32\vbscript.dll
2011-02-12 19:53 . 2011-01-05 05:37 428032 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-02-12 19:53 . 2010-10-27 05:18 5510528 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-02-12 19:53 . 2010-10-27 05:16 1739176 ----a-w- c:\windows\system32\ntdll.dll
2011-02-12 19:53 . 2010-10-27 04:43 3901824 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-02-12 19:53 . 2010-10-27 04:43 3957120 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-02-12 19:53 . 2010-10-27 04:40 1293120 ----a-w- c:\windows\SysWow64\ntdll.dll
2011-02-12 16:05 . 2011-02-02 16:10 7844688 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A71A419A-6BE3-421E-BDBF-3B4AD4EE1039}\mpengine.dll
2011-02-05 21:23 . 2011-02-05 21:23 -------- d-----w- c:\windows\SysWow64\Wat
2011-02-05 21:23 . 2011-02-05 21:23 -------- d-----w- c:\windows\system32\Wat
2011-02-05 18:25 . 2009-11-25 11:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2011-02-05 18:25 . 2009-11-25 11:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2011-02-05 18:25 . 2009-11-25 11:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2011-02-05 18:25 . 2009-11-25 11:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2011-02-05 18:25 . 2009-11-25 11:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2011-02-05 18:25 . 2009-11-25 11:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2011-02-05 18:25 . 2009-11-25 11:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-02-05 18:25 . 2009-11-25 11:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2011-02-05 18:25 . 2009-11-25 11:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2011-02-05 18:24 . 2009-11-25 11:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2011-02-05 18:24 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2011-02-05 18:21 . 2011-02-05 18:21 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2011-02-05 18:18 . 2010-03-04 04:40 184832 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2011-02-05 18:18 . 2010-03-04 04:32 243712 ----a-w- c:\windows\system32\drivers\ks.sys
2011-02-05 18:16 . 2011-02-05 18:16 -------- d-----w- c:\program files (x86)\SopCast
2011-02-05 17:44 . 2011-02-05 17:46 -------- d-----w- c:\program files (x86)\Age of Empires
2011-02-04 18:47 . 2011-02-08 15:14 -------- d-----w- c:\windows\rescache
2011-02-04 17:42 . 2011-02-12 20:13 -------- d-----w- c:\program files (x86)\Advanced SystemCare 3
2011-02-04 16:30 . 2011-02-04 16:43 -------- d-----w- C:\xProjekty
2011-02-04 14:53 . 2011-02-05 18:20 -------- d-----w- c:\program files (x86)\Microsoft Works
2011-02-04 14:53 . 2011-02-04 14:53 -------- d-----w- c:\windows\PCHEALTH
2011-02-04 14:53 . 2011-02-04 14:53 -------- d-----w- c:\program files (x86)\Microsoft.NET
2011-02-04 14:48 . 2011-02-04 14:48 -------- d-----r- C:\MSOCache
2011-02-04 14:24 . 2011-02-04 14:29 -------- d-----w- c:\programdata\VirtualizedApplications
2011-02-04 13:07 . 2011-02-04 13:07 -------- d-----w- c:\program files (x86)\Common Files\Steam
2011-02-04 12:56 . 2011-02-12 15:34 -------- d-----w- c:\program files (x86)\Counter-Strike 1.6
2011-02-04 12:51 . 2011-02-04 12:51 -------- d-----w- c:\program files\CCleaner
2011-02-04 12:40 . 2011-02-04 12:41 -------- d-----w- c:\program files\QIP 2010
2011-02-04 12:31 . 2011-02-04 12:31 -------- d-----w- c:\program files (x86)\Common Files\Skype
2011-02-04 12:31 . 2011-02-04 12:31 -------- d-----r- c:\program files (x86)\Skype
2011-02-04 12:26 . 2011-02-04 12:26 -------- d-----w- c:\program files (x86)\The KMPlayer
2011-02-04 12:15 . 2010-02-10 14:09 384 ----a-w- c:\windows\myClean.bat
2011-02-04 12:02 . 2011-02-04 12:02 88 --sh--r- c:\programdata\1EFDA7FD4F.sys
2011-02-04 12:02 . 2011-02-04 12:02 2516 --sha-w- c:\programdata\KGyGaAvL.sys
2011-02-04 11:59 . 2011-02-06 18:05 -------- d-----w- c:\programdata\Microsoft Help
2011-02-04 11:58 . 2011-02-02 16:11 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-02-04 11:24 . 2011-01-13 08:47 237168 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-04 11:23 . 2011-02-13 09:04 -------- d-----w- c:\programdata\Alwil Software
2011-02-04 11:23 . 2011-02-04 11:23 -------- d-----w- c:\program files\Alwil Software
2011-02-04 11:16 . 2011-02-05 18:17 -------- d-----w- C:\my
2011-02-04 10:07 . 2011-02-04 10:07 -------- d-----w- c:\programdata\ATI
2011-02-04 10:00 . 2011-02-04 10:00 -------- d-----w- c:\programdata\Symantec
2011-02-04 10:00 . 2011-02-04 10:00 -------- d-----w- c:\program files (x86)\Symantec
2011-02-04 09:58 . 2011-02-04 09:58 -------- d-----w- C:\HPMBackup
2011-02-04 09:56 . 2011-02-04 09:56 -------- d-----w- c:\programdata\WinZip
2011-02-04 09:55 . 2011-02-13 10:39 -------- d-----w- c:\users\Pavel Hlavatý
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QLBController"="c:\program files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" [2010-03-01 256056]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
"PDF Complete"="c:\program files (x86)\PDF Complete\pdfsty.exe" [2009-10-23 563736]
"File Sanitizer"="c:\program files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe" [2009-12-12 11265536]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-08-05 98304]
"DTRun"="c:\program files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe" [2009-11-19 518656]
"NortonOnlineBackupReminder"="c:\program files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-06-29 600936]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP]
DeviceNP.dll [BU]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
R2 HP Power Assistant Service;HP Power Assistant Service;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2010-06-18 103992]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-04-05 103992]
R2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2009-12-14 2019120]
R3 BTMCOM;Bluetooth Serial Port;c:\windows\system32\Drivers\btmcom.sys [2010-04-10 52736]
R3 BTMUSB;Motorola Bluetooth Radio Service;c:\windows\system32\Drivers\btmusb.sys [2010-06-29 3232768]
R3 DAMDrv;DAMDrv;c:\windows\system32\DRIVERS\DAMDrv64.sys [2009-10-21 40760]
R3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\SysWOW64\flcdlock.exe [2009-11-17 362040]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [2009-11-11 232480]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-01-12 325152]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-02-05 1255736]
S0 SafeBoot;SafeBoot; [x]
S0 SbAlg;SbAlg; [x]
S0 SbFsLock;SbFsLock; [x]
S1 RsvLock;RsvLock; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe [2009-03-03 89600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-08-04 203264]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files\Motorola\Bluetooth\obexsrv.exe [2010-05-20 677128]
S2 HP ProtectTools Service;HP ProtectTools Service;c:\program files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2009-11-18 36864]
S2 HPDayStarterService;HP DayStarter Service;c:\program files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe [2010-05-10 90112]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-06-25 92216]
S2 HpFkCryptService;Drive Encryption Service;c:\program files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-12-16 281192]
S2 HPFSService;File Sanitizer for HP ProtectTools;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2009-12-12 297984]
S2 hpHotkeyMonitor;HP Hotkey Monitor;c:\program files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [2010-03-01 264248]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2009-07-08 30520]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe [2009-10-23 635416]
S2 uArcCapture;ArcCapture;c:\windows\system\uArcCapture.exe [2009-12-04 506472]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-04 2320920]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-08-04 6859776]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-08-04 264192]
S3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver;c:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2009-12-04 32640]
S3 Bluetooth Device Manager;Bluetooth Device Manager;c:\program files\Motorola\Bluetooth\devmgrsrv.exe [2010-06-29 4181256]
S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files\Motorola\Bluetooth\audiosrv.exe [2010-05-20 1096968]
S3 DEBridge;DEBridge;c:\program files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe [2009-12-16 704512]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-12-05 1028096]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [2010-06-29 931168]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 19:11 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF1093.cfxxe" [X]
"HPPowerAssistant"="c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe" [2010-06-18 1691192]
"SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe" [BU]
"HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe" [2010-04-05 8192]
"BTMTrayAgent"="c:\program files\Motorola\Bluetooth\btmshell.dll" [2010-06-10 24783624]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-17 487424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uStart Page = hxxp://google.cz/
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://www.bing.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{bd707fe6-39f6-4bda-9265-86a76719bdc5} - c:\program files\Motorola\Bluetooth\btmiesend.htm
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //FWEvent.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
FF - ProfilePath - c:\users\Pavel Hlavatý\AppData\Roaming\Mozilla\Firefox\Profiles\ja6hsue6.default\
FF - prefs.js: browser.startup.homepage - google.cz
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - user.js: general.useragent.extra.brc -
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Motorola\Bluetooth\btplayerctrl.exe
.
**************************************************************************
.
Celkový čas: 2011-02-13 11:51:41 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-13 10:51
Před spuštěním: Volných bajtů: 571 875 971 072
Po spuštění: Volných bajtů: 571 381 596 160
- - End Of File - - F14FCB324DACC63AE1631497EC2D731A
ComboFix 11-02-12.02 - Pavel Hlavatý 13.02.2011 11:42:18.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.3951.2786 [GMT 1:00]
Spuštěný z: c:\users\Pavel Hlavatý\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-13 do 2011-02-13 )))))))))))))))))))))))))))))))
.
2011-02-13 09:43 . 2011-02-13 10:38 -------- d-----w- c:\program files\trend micro
2011-02-13 09:43 . 2011-02-13 09:43 -------- d-----w- C:\rsit
2011-02-12 20:17 . 2011-02-12 20:36 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-02-12 20:17 . 2011-02-12 20:18 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2011-02-12 19:53 . 2011-01-05 04:00 3127808 ----a-w- c:\windows\system32\win32k.sys
2011-02-12 19:53 . 2010-12-21 06:16 214016 ----a-w- c:\windows\system32\winsrv.dll
2011-02-12 19:53 . 2010-12-18 06:11 714752 ----a-w- c:\windows\system32\kerberos.dll
2011-02-12 19:53 . 2010-12-18 05:29 541184 ----a-w- c:\windows\SysWow64\kerberos.dll
2011-02-12 19:53 . 2011-01-05 06:20 612352 ----a-w- c:\windows\system32\vbscript.dll
2011-02-12 19:53 . 2011-01-05 05:37 428032 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-02-12 19:53 . 2010-10-27 05:18 5510528 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-02-12 19:53 . 2010-10-27 05:16 1739176 ----a-w- c:\windows\system32\ntdll.dll
2011-02-12 19:53 . 2010-10-27 04:43 3901824 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-02-12 19:53 . 2010-10-27 04:43 3957120 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-02-12 19:53 . 2010-10-27 04:40 1293120 ----a-w- c:\windows\SysWow64\ntdll.dll
2011-02-12 16:05 . 2011-02-02 16:10 7844688 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A71A419A-6BE3-421E-BDBF-3B4AD4EE1039}\mpengine.dll
2011-02-05 21:23 . 2011-02-05 21:23 -------- d-----w- c:\windows\SysWow64\Wat
2011-02-05 21:23 . 2011-02-05 21:23 -------- d-----w- c:\windows\system32\Wat
2011-02-05 18:25 . 2009-11-25 11:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2011-02-05 18:25 . 2009-11-25 11:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2011-02-05 18:25 . 2009-11-25 11:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2011-02-05 18:25 . 2009-11-25 11:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2011-02-05 18:25 . 2009-11-25 11:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2011-02-05 18:25 . 2009-11-25 11:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2011-02-05 18:25 . 2009-11-25 11:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-02-05 18:25 . 2009-11-25 11:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2011-02-05 18:25 . 2009-11-25 11:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2011-02-05 18:24 . 2009-11-25 11:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2011-02-05 18:24 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2011-02-05 18:21 . 2011-02-05 18:21 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2011-02-05 18:18 . 2010-03-04 04:40 184832 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2011-02-05 18:18 . 2010-03-04 04:32 243712 ----a-w- c:\windows\system32\drivers\ks.sys
2011-02-05 18:16 . 2011-02-05 18:16 -------- d-----w- c:\program files (x86)\SopCast
2011-02-05 17:44 . 2011-02-05 17:46 -------- d-----w- c:\program files (x86)\Age of Empires
2011-02-04 18:47 . 2011-02-08 15:14 -------- d-----w- c:\windows\rescache
2011-02-04 17:42 . 2011-02-12 20:13 -------- d-----w- c:\program files (x86)\Advanced SystemCare 3
2011-02-04 16:30 . 2011-02-04 16:43 -------- d-----w- C:\xProjekty
2011-02-04 14:53 . 2011-02-05 18:20 -------- d-----w- c:\program files (x86)\Microsoft Works
2011-02-04 14:53 . 2011-02-04 14:53 -------- d-----w- c:\windows\PCHEALTH
2011-02-04 14:53 . 2011-02-04 14:53 -------- d-----w- c:\program files (x86)\Microsoft.NET
2011-02-04 14:48 . 2011-02-04 14:48 -------- d-----r- C:\MSOCache
2011-02-04 14:24 . 2011-02-04 14:29 -------- d-----w- c:\programdata\VirtualizedApplications
2011-02-04 13:07 . 2011-02-04 13:07 -------- d-----w- c:\program files (x86)\Common Files\Steam
2011-02-04 12:56 . 2011-02-12 15:34 -------- d-----w- c:\program files (x86)\Counter-Strike 1.6
2011-02-04 12:51 . 2011-02-04 12:51 -------- d-----w- c:\program files\CCleaner
2011-02-04 12:40 . 2011-02-04 12:41 -------- d-----w- c:\program files\QIP 2010
2011-02-04 12:31 . 2011-02-04 12:31 -------- d-----w- c:\program files (x86)\Common Files\Skype
2011-02-04 12:31 . 2011-02-04 12:31 -------- d-----r- c:\program files (x86)\Skype
2011-02-04 12:26 . 2011-02-04 12:26 -------- d-----w- c:\program files (x86)\The KMPlayer
2011-02-04 12:15 . 2010-02-10 14:09 384 ----a-w- c:\windows\myClean.bat
2011-02-04 12:02 . 2011-02-04 12:02 88 --sh--r- c:\programdata\1EFDA7FD4F.sys
2011-02-04 12:02 . 2011-02-04 12:02 2516 --sha-w- c:\programdata\KGyGaAvL.sys
2011-02-04 11:59 . 2011-02-06 18:05 -------- d-----w- c:\programdata\Microsoft Help
2011-02-04 11:58 . 2011-02-02 16:11 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-02-04 11:24 . 2011-01-13 08:47 237168 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-04 11:23 . 2011-02-13 09:04 -------- d-----w- c:\programdata\Alwil Software
2011-02-04 11:23 . 2011-02-04 11:23 -------- d-----w- c:\program files\Alwil Software
2011-02-04 11:16 . 2011-02-05 18:17 -------- d-----w- C:\my
2011-02-04 10:07 . 2011-02-04 10:07 -------- d-----w- c:\programdata\ATI
2011-02-04 10:00 . 2011-02-04 10:00 -------- d-----w- c:\programdata\Symantec
2011-02-04 10:00 . 2011-02-04 10:00 -------- d-----w- c:\program files (x86)\Symantec
2011-02-04 09:58 . 2011-02-04 09:58 -------- d-----w- C:\HPMBackup
2011-02-04 09:56 . 2011-02-04 09:56 -------- d-----w- c:\programdata\WinZip
2011-02-04 09:55 . 2011-02-13 10:39 -------- d-----w- c:\users\Pavel Hlavatý
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QLBController"="c:\program files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" [2010-03-01 256056]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
"PDF Complete"="c:\program files (x86)\PDF Complete\pdfsty.exe" [2009-10-23 563736]
"File Sanitizer"="c:\program files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe" [2009-12-12 11265536]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-08-05 98304]
"DTRun"="c:\program files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe" [2009-11-19 518656]
"NortonOnlineBackupReminder"="c:\program files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-06-29 600936]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP]
DeviceNP.dll [BU]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
R2 HP Power Assistant Service;HP Power Assistant Service;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2010-06-18 103992]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-04-05 103992]
R2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2009-12-14 2019120]
R3 BTMCOM;Bluetooth Serial Port;c:\windows\system32\Drivers\btmcom.sys [2010-04-10 52736]
R3 BTMUSB;Motorola Bluetooth Radio Service;c:\windows\system32\Drivers\btmusb.sys [2010-06-29 3232768]
R3 DAMDrv;DAMDrv;c:\windows\system32\DRIVERS\DAMDrv64.sys [2009-10-21 40760]
R3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\SysWOW64\flcdlock.exe [2009-11-17 362040]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [2009-11-11 232480]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-01-12 325152]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-02-05 1255736]
S0 SafeBoot;SafeBoot; [x]
S0 SbAlg;SbAlg; [x]
S0 SbFsLock;SbFsLock; [x]
S1 RsvLock;RsvLock; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe [2009-03-03 89600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-08-04 203264]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files\Motorola\Bluetooth\obexsrv.exe [2010-05-20 677128]
S2 HP ProtectTools Service;HP ProtectTools Service;c:\program files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2009-11-18 36864]
S2 HPDayStarterService;HP DayStarter Service;c:\program files\Hewlett-Packard\HP QuickLook\32-bit\HPDayStarterService.exe [2010-05-10 90112]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-06-25 92216]
S2 HpFkCryptService;Drive Encryption Service;c:\program files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-12-16 281192]
S2 HPFSService;File Sanitizer for HP ProtectTools;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2009-12-12 297984]
S2 hpHotkeyMonitor;HP Hotkey Monitor;c:\program files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [2010-03-01 264248]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2009-07-08 30520]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-03-04 13336]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe [2009-10-23 635416]
S2 uArcCapture;ArcCapture;c:\windows\system\uArcCapture.exe [2009-12-04 506472]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-04 2320920]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-08-04 6859776]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-08-04 264192]
S3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver;c:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2009-12-04 32640]
S3 Bluetooth Device Manager;Bluetooth Device Manager;c:\program files\Motorola\Bluetooth\devmgrsrv.exe [2010-06-29 4181256]
S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files\Motorola\Bluetooth\audiosrv.exe [2010-05-20 1096968]
S3 DEBridge;DEBridge;c:\program files\Hewlett-Packard\Drive Encryption\SbHpAuthenticatorService.exe [2009-12-16 704512]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-12-05 1028096]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [2010-06-29 931168]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 19:11 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF1093.cfxxe" [X]
"HPPowerAssistant"="c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe" [2010-06-18 1691192]
"SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe" [BU]
"HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe" [2010-04-05 8192]
"BTMTrayAgent"="c:\program files\Motorola\Bluetooth\btmshell.dll" [2010-06-10 24783624]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-17 487424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uStart Page = hxxp://google.cz/
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://www.bing.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {{bd707fe6-39f6-4bda-9265-86a76719bdc5} - c:\program files\Motorola\Bluetooth\btmiesend.htm
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //FWEvent.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
FF - ProfilePath - c:\users\Pavel Hlavatý\AppData\Roaming\Mozilla\Firefox\Profiles\ja6hsue6.default\
FF - prefs.js: browser.startup.homepage - google.cz
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - user.js: general.useragent.extra.brc -
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Motorola\Bluetooth\btplayerctrl.exe
.
**************************************************************************
.
Celkový čas: 2011-02-13 11:51:41 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-13 10:51
Před spuštěním: Volných bajtů: 571 875 971 072
Po spuštění: Volných bajtů: 571 381 596 160
- - End Of File - - F14FCB324DACC63AE1631497EC2D731A
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Průzkumník se spustí sám po startu
Pri tejto akcii je nutné mať ComboFix na ploche.
Vypni>FIREWALL>Antivir>Antispyware>vsetko rezidentne.
Otvor Notepad (Poznámkový blok) a zkopíruj do neho celý zeleny tex:
Potom klik na Subor -> Uložiť ako.. .. -> Ako je Názov souboru tak do toho riadku napiš:CFScript.txt
Typ súboru tak tam vyberies *všetky súbory
A ulož ho na plochu.> Pozor CFScript.txt>Neotvarat a nemoze byt ani>CFScript.txt.txt A Urobis Toto :

Po skonceni skenu vlož log čo ComboFix vytvorí
Vypni>FIREWALL>Antivir>Antispyware>vsetko rezidentne.
Otvor Notepad (Poznámkový blok) a zkopíruj do neho celý zeleny tex:
Kód: Vybrat vše
KillAll::
DDS::
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //FWEvent.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\wwwTyp súboru tak tam vyberies *všetky súbory
A ulož ho na plochu.> Pozor CFScript.txt>Neotvarat a nemoze byt ani>CFScript.txt.txt A Urobis Toto :

Po skonceni skenu vlož log čo ComboFix vytvorí
Re: Průzkumník se spustí sám po startu
Nevím jak je to možné, ale po projetí tim ComboFixem se už průzkumník neotvírá.
Problém by teda měl byt vyřešen...
Děkuji za ochotu a pomoc, to se dnes už jen tak nevidí
Problém by teda měl byt vyřešen...
Děkuji za ochotu a pomoc, to se dnes už jen tak nevidí
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Průzkumník se spustí sám po startu
Nemas zaco.


Přispějete na provoz fóra?