Prosím o kontrolu logu z DDS
Napsal: 04 bře 2011 12:48
Ahoj,
jako hlupak jsem klikl ve spamovy poste na pekny obrazek pekne slecinky
a ejhle ... asi vir ....
prosim o pomoc. Zde je log z DDS. Predem moc děkuju.
DDS (Ver_10-12-12.02) - NTFSx86
Run by Administrator at 12:39:58,82 on p 04.03.2011
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_19
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2039.1352 [GMT 1:00]
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
============== Running Processes ===============
C:\WINDOWS\System32\svchost.exe -k Cognizance
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Hewlett-Packard\IAM\bin\asghost.exe
C:\WINDOWS\system32\AccelerometerSt.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\WINDOWS\SMINST\Scheduler.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE
svchost.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\O2 Mobilni internet\O2 Mobilni internet.exe
c:\WINDOWS\system32\ifxspmgt.exe
svchost.exe "C:\WINDOWS\system32\algn.exe"
C:\WINDOWS\system32\IFXTCS.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\AMT\LMS.exe
c:\WINDOWS\system32\IfxPsdSv.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
c:\Program Files\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\WINDOWS\TEMP\161.exe
C:\WINDOWS\Temp\m.27E.tmp.exe
C:\Documents and Settings\LocalService\Data aplikací\AntiVirus AntiSpyware 2011\securitymanager.exe
c:\program files\adobe\reader 9.0\reader\spplugins\adobedialog.exe
c:\program files\common files\mssoap\binaries\mssoap1microsoft.exe
c:\program files\microsoft silverlight\4.0.60129.0\sr-cyrl-cs\resourcessystem.exe
c:\program files\microsoft silverlight\4.0.60129.0\hr\silverlightresources.exe
C:\Documents and Settings\Administrator\Plocha\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://domredi.com/1/
mDefault_Page_URL = hxxp://www.hp.com
uInternet Connection Wizard,ShellNext = hxxp://www.codecguide.com/
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Credential Manager for HP ProtectTools: {df21f1db-80c6-11d3-9483-b03d0ec10000} - c:\program files\hewlett-packard\iam\bin\ItIEAddIn.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\Wcescomm.exe"
uRun: [Mobile Partner] "c:\program files\o2 mobilni internet\O2 Mobilni internet.exe"
uRun: [Java developer Script Browse] c:\windows\jusched.exe
mRun: [MsmqIntCert] regsvr32 /s mqrt.dll
mRun: [AccelerometerSysTrayApplet] c:\windows\system32\AccelerometerSt.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [Cpqset] c:\program files\hewlett-packard\default settings\cpqset.exe
mRun: [Recguard] c:\windows\sminst\Recguard.exe
mRun: [Reminder] c:\windows\creator\Remind_XP.exe
mRun: [Scheduler] c:\windows\sminst\Scheduler.exe
mRun: [PININST] c:\system.sav\util\pininst.exe c:\system.sav\util\PININST.INI
mRun: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [PTHOSTTR] c:\program files\hewlett-packard\hp protecttools security manager\PTHOSTTR.EXE /Start
mRun: [CognizanceTS] rundll32.exe c:\progra~1\hewlet~1\iam\bin\ASTSVCC.dll,RegisterModule
mRun: [IFXSPMGT] c:\windows\system32\ifxspmgt.exe /NotifyLogon
mRun: [atchk] "c:\program files\intel\amt\atchk.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [161] c:\windows\temp\161.exe
mRun: [gdrete1sdffdfc] c:\program files\adobe\reader 9.0\reader\spplugins\adobedialog.exe
mRun: [WiSC10gdrete11.2.8800.00108171148] c:\program files\common files\mssoap\binaries\mssoap1microsoft.exe
mRun: [FrontPagegdrete14.0.2.2717] c:\program files\microsoft frontpage\version3.0\bin\fpmmcmicrosoft.exe
mRun: [systemresources] c:\program files\microsoft silverlight\4.0.60129.0\hr\silverlightresources.exe
mRun: [mscorlibsystem] c:\program files\microsoft silverlight\4.0.60129.0\sr-cyrl-cs\resourcessystem.exe
mRun: [systemmscorrc] c:\program files\microsoft silverlight\4.0.60129.0\zh-hans\resourcessilverlight.exe
mRunServices: [161] c:\windows\temp\161.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRun: [AntiVirus AntiSpyware 2011] "c:\documents and settings\localservice\data aplikací\antivirus antispyware 2011\AntiVirus AntiSpyware.exe" /STARTUP
dRun: [AntiVirus AntiSpyware 2011 Security] c:\documents and settings\localservice\data aplikací\antivirus antispyware 2011\securitymanager.exe
StartupFolder: c:\docume~1\alluse~1\nabdka~1\programy\posput~1\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\nabdka~1\programy\posput~1\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: DeviceNP - DeviceNP.dll
Notify: igfxcui - igfxdev.dll
Notify: OneCard - c:\program files\hewlett-packard\iam\bin\ASWLNPkg.dll
AppInit_DLLs: APSHook.dll
LSA: Notification Packages = scecli ASWLNPkg
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admini~1\dataap~1\mozilla\firefox\profiles\c8o6l5gt.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.1&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsl40023dba;MpKsl40023dba;c:\documents and settings\all users\data aplikací\microsoft\microsoft antimalware\definition updates\{1c2d797b-2fc9-435f-9f3c-b490f9a82bfc}\MpKsl40023dba.sys [2011-3-4 28752]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [2007-7-24 38816]
R1 tidnet;TID NDIS Protocol Driver;c:\windows\system32\drivers\tidnet.sys [2009-9-15 19200]
R2 ASBroker;Logon Session Broker;c:\windows\system32\svchost.exe -k Cognizance [2004-8-18 14336]
R2 ASChannel;Local Communication Channel;c:\windows\system32\svchost.exe -k Cognizance [2004-8-18 14336]
R2 atchksrv;Intel(R) Active Management Technology System Status Service;c:\program files\intel\amt\atchksrv.exe [2009-11-27 182808]
R2 UNS;Intel(R) Active Management Technology User Notification Service;c:\program files\intel\amt\UNS.exe [2009-11-27 1464856]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [2010-12-14 100736]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2006-4-25 41216]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2004-8-18 69120]
S2 Dot3svcBITS;Automatická konfigurace pevné sítě Dot3svcBITS;c:\windows\system32\algn.exe srv --> c:\windows\system32\algn.exe srv [?]
S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\drivers\axtmvflt.sys [2010-2-9 3456]
S3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\drivers\axtmvmdm.sys [2010-2-9 40064]
S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\drivers\axtmvprt.sys [2010-2-9 38784]
S3 DAMDrv;DAMDrv;c:\windows\system32\drivers\DAMDrv.sys [2009-11-27 30008]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\system32\flcdlock.exe [2007-6-8 172131]
S3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2006-2-28 87808]
S3 HP24X;HP PC Card Smart Card Reader;c:\windows\system32\drivers\HP24X.sys [2007-7-17 35072]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\drivers\ewdcsc.sys [2010-12-14 24448]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-8-2 32512]
=============== Created Last 30 ================
2011-03-04 11:01:31 134144 --s-a-w- c:\program files\common files\mssoap\binaries\MSSOAP1Microsoft.exe
2011-03-04 11:00:09 -------- d-----w- C:\AntiVirus AntiSpyware 2011
2011-03-04 09:34:37 28752 ----a-w- c:\docume~1\alluse~1\dataap~1\microsoft\microsoft antimalware\definition updates\{1c2d797b-2fc9-435f-9f3c-b490f9a82bfc}\MpKsl40023dba.sys
2011-03-04 06:01:03 114688 ----a-w- c:\windows\system32\chg.exe
2011-03-03 21:58:37 5943120 ----a-w- c:\docume~1\alluse~1\dataap~1\microsoft\microsoft antimalware\definition updates\{1c2d797b-2fc9-435f-9f3c-b490f9a82bfc}\mpengine.dll
2011-03-03 21:45:31 0 ----a-w- c:\windows\system32\actmovies.sys
2011-03-03 18:03:46 343626675 --sha-w- c:\windows\system32\adsnwm.sys
==================== Find3M ====================
2011-01-21 14:44:07 440320 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-12 07:40:59 4874 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04:07 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34:22 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 22:14:39 668160 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 22:14:39 61952 ----a-w- c:\windows\system32\tdc.ocx
2010-12-20 22:14:37 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-12-20 22:13:08 370176 ----a-w- c:\windows\system32\html.iec
2010-12-20 17:25:50 729088 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-09 15:15:19 713216 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 15:14:06 2029056 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-09 15:14:05 2150912 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 14:30:13 33280 ----a-w- c:\windows\system32\csrsrv.dll
2008-06-17 09:35:56 212992 ----a-r- c:\program files\MSP_Uninstall.exe
2007-04-04 07:24:02 90112 ----a-r- c:\program files\axesstel.dll
============= FINISH: 12:40:49,71 ===============
jako hlupak jsem klikl ve spamovy poste na pekny obrazek pekne slecinky

prosim o pomoc. Zde je log z DDS. Predem moc děkuju.
DDS (Ver_10-12-12.02) - NTFSx86
Run by Administrator at 12:39:58,82 on p 04.03.2011
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_19
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2039.1352 [GMT 1:00]
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
============== Running Processes ===============
C:\WINDOWS\System32\svchost.exe -k Cognizance
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Hewlett-Packard\IAM\bin\asghost.exe
C:\WINDOWS\system32\AccelerometerSt.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\WINDOWS\SMINST\Scheduler.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE
svchost.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\O2 Mobilni internet\O2 Mobilni internet.exe
c:\WINDOWS\system32\ifxspmgt.exe
svchost.exe "C:\WINDOWS\system32\algn.exe"
C:\WINDOWS\system32\IFXTCS.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\AMT\LMS.exe
c:\WINDOWS\system32\IfxPsdSv.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
c:\Program Files\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\WINDOWS\TEMP\161.exe
C:\WINDOWS\Temp\m.27E.tmp.exe
C:\Documents and Settings\LocalService\Data aplikací\AntiVirus AntiSpyware 2011\securitymanager.exe
c:\program files\adobe\reader 9.0\reader\spplugins\adobedialog.exe
c:\program files\common files\mssoap\binaries\mssoap1microsoft.exe
c:\program files\microsoft silverlight\4.0.60129.0\sr-cyrl-cs\resourcessystem.exe
c:\program files\microsoft silverlight\4.0.60129.0\hr\silverlightresources.exe
C:\Documents and Settings\Administrator\Plocha\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://domredi.com/1/
mDefault_Page_URL = hxxp://www.hp.com
uInternet Connection Wizard,ShellNext = hxxp://www.codecguide.com/
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Credential Manager for HP ProtectTools: {df21f1db-80c6-11d3-9483-b03d0ec10000} - c:\program files\hewlett-packard\iam\bin\ItIEAddIn.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\Wcescomm.exe"
uRun: [Mobile Partner] "c:\program files\o2 mobilni internet\O2 Mobilni internet.exe"
uRun: [Java developer Script Browse] c:\windows\jusched.exe
mRun: [MsmqIntCert] regsvr32 /s mqrt.dll
mRun: [AccelerometerSysTrayApplet] c:\windows\system32\AccelerometerSt.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [Cpqset] c:\program files\hewlett-packard\default settings\cpqset.exe
mRun: [Recguard] c:\windows\sminst\Recguard.exe
mRun: [Reminder] c:\windows\creator\Remind_XP.exe
mRun: [Scheduler] c:\windows\sminst\Scheduler.exe
mRun: [PININST] c:\system.sav\util\pininst.exe c:\system.sav\util\PININST.INI
mRun: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [PTHOSTTR] c:\program files\hewlett-packard\hp protecttools security manager\PTHOSTTR.EXE /Start
mRun: [CognizanceTS] rundll32.exe c:\progra~1\hewlet~1\iam\bin\ASTSVCC.dll,RegisterModule
mRun: [IFXSPMGT] c:\windows\system32\ifxspmgt.exe /NotifyLogon
mRun: [atchk] "c:\program files\intel\amt\atchk.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [161] c:\windows\temp\161.exe
mRun: [gdrete1sdffdfc] c:\program files\adobe\reader 9.0\reader\spplugins\adobedialog.exe
mRun: [WiSC10gdrete11.2.8800.00108171148] c:\program files\common files\mssoap\binaries\mssoap1microsoft.exe
mRun: [FrontPagegdrete14.0.2.2717] c:\program files\microsoft frontpage\version3.0\bin\fpmmcmicrosoft.exe
mRun: [systemresources] c:\program files\microsoft silverlight\4.0.60129.0\hr\silverlightresources.exe
mRun: [mscorlibsystem] c:\program files\microsoft silverlight\4.0.60129.0\sr-cyrl-cs\resourcessystem.exe
mRun: [systemmscorrc] c:\program files\microsoft silverlight\4.0.60129.0\zh-hans\resourcessilverlight.exe
mRunServices: [161] c:\windows\temp\161.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRun: [AntiVirus AntiSpyware 2011] "c:\documents and settings\localservice\data aplikací\antivirus antispyware 2011\AntiVirus AntiSpyware.exe" /STARTUP
dRun: [AntiVirus AntiSpyware 2011 Security] c:\documents and settings\localservice\data aplikací\antivirus antispyware 2011\securitymanager.exe
StartupFolder: c:\docume~1\alluse~1\nabdka~1\programy\posput~1\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\nabdka~1\programy\posput~1\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: DeviceNP - DeviceNP.dll
Notify: igfxcui - igfxdev.dll
Notify: OneCard - c:\program files\hewlett-packard\iam\bin\ASWLNPkg.dll
AppInit_DLLs: APSHook.dll
LSA: Notification Packages = scecli ASWLNPkg
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admini~1\dataap~1\mozilla\firefox\profiles\c8o6l5gt.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.1&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsl40023dba;MpKsl40023dba;c:\documents and settings\all users\data aplikací\microsoft\microsoft antimalware\definition updates\{1c2d797b-2fc9-435f-9f3c-b490f9a82bfc}\MpKsl40023dba.sys [2011-3-4 28752]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [2007-7-24 38816]
R1 tidnet;TID NDIS Protocol Driver;c:\windows\system32\drivers\tidnet.sys [2009-9-15 19200]
R2 ASBroker;Logon Session Broker;c:\windows\system32\svchost.exe -k Cognizance [2004-8-18 14336]
R2 ASChannel;Local Communication Channel;c:\windows\system32\svchost.exe -k Cognizance [2004-8-18 14336]
R2 atchksrv;Intel(R) Active Management Technology System Status Service;c:\program files\intel\amt\atchksrv.exe [2009-11-27 182808]
R2 UNS;Intel(R) Active Management Technology User Notification Service;c:\program files\intel\amt\UNS.exe [2009-11-27 1464856]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [2010-12-14 100736]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2006-4-25 41216]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2004-8-18 69120]
S2 Dot3svcBITS;Automatická konfigurace pevné sítě Dot3svcBITS;c:\windows\system32\algn.exe srv --> c:\windows\system32\algn.exe srv [?]
S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\drivers\axtmvflt.sys [2010-2-9 3456]
S3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\drivers\axtmvmdm.sys [2010-2-9 40064]
S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\drivers\axtmvprt.sys [2010-2-9 38784]
S3 DAMDrv;DAMDrv;c:\windows\system32\drivers\DAMDrv.sys [2009-11-27 30008]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\system32\flcdlock.exe [2007-6-8 172131]
S3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2006-2-28 87808]
S3 HP24X;HP PC Card Smart Card Reader;c:\windows\system32\drivers\HP24X.sys [2007-7-17 35072]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\drivers\ewdcsc.sys [2010-12-14 24448]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-8-2 32512]
=============== Created Last 30 ================
2011-03-04 11:01:31 134144 --s-a-w- c:\program files\common files\mssoap\binaries\MSSOAP1Microsoft.exe
2011-03-04 11:00:09 -------- d-----w- C:\AntiVirus AntiSpyware 2011
2011-03-04 09:34:37 28752 ----a-w- c:\docume~1\alluse~1\dataap~1\microsoft\microsoft antimalware\definition updates\{1c2d797b-2fc9-435f-9f3c-b490f9a82bfc}\MpKsl40023dba.sys
2011-03-04 06:01:03 114688 ----a-w- c:\windows\system32\chg.exe
2011-03-03 21:58:37 5943120 ----a-w- c:\docume~1\alluse~1\dataap~1\microsoft\microsoft antimalware\definition updates\{1c2d797b-2fc9-435f-9f3c-b490f9a82bfc}\mpengine.dll
2011-03-03 21:45:31 0 ----a-w- c:\windows\system32\actmovies.sys
2011-03-03 18:03:46 343626675 --sha-w- c:\windows\system32\adsnwm.sys
==================== Find3M ====================
2011-01-21 14:44:07 440320 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-12 07:40:59 4874 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04:07 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34:22 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 22:14:39 668160 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 22:14:39 61952 ----a-w- c:\windows\system32\tdc.ocx
2010-12-20 22:14:37 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-12-20 22:13:08 370176 ----a-w- c:\windows\system32\html.iec
2010-12-20 17:25:50 729088 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-09 15:15:19 713216 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 15:14:06 2029056 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-09 15:14:05 2150912 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 14:30:13 33280 ----a-w- c:\windows\system32\csrsrv.dll
2008-06-17 09:35:56 212992 ----a-r- c:\program files\MSP_Uninstall.exe
2007-04-04 07:24:02 90112 ----a-r- c:\program files\axesstel.dll
============= FINISH: 12:40:49,71 ===============