Stránka 1 z 2

Prosim o kontrolu

Napsal: 30 bře 2011 17:10
od assasin172
Prosim, o kontrolu ...dekuji
Logfile of random's system information tool 1.08 (written by random/random)
Run by Michal at 2011-03-30 18:03:33
Microsoft Windows 7 Home Premium
System drive C: has 24 GB (24%) free of 103 GB
Total RAM: 3071 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:03:44, on 30.3.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Michal.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2207613
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Softonic English FF - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: lxbk_device - - C:\Windows\system32\lxbkcoms.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: mysql - Unknown owner - F:\download\Jeuties.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - C:\Program Files\Soluto\SolutoService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9805 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\Soluto\soluto.exe" /userinit
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {161854F0-8304-4A88-BBC4-7B222CCF84F0}
"C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
"C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe"
C:\Windows\system32\lxbkcoms.exe -service
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Soluto\SolutoService.exe"
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" -quickstart
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe"
"C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/npn_with_spdy/ --channel=2068.02834180.170085916 /prefetch:3
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=extension --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/npn_with_spdy/ --channel=2068.027ADA80.676379449 /prefetch:3 --ignored=" --type=renderer "
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.0.0.6907_0\npSkypeChromePlugin.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=2068.0657CE00.803840999 /prefetch:4
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\rundll32.exe "C:\Users\Michal\AppData\Local\Google\Chrome\APPLIC~1\100648~1.204\gcswf32.dll",BrokerMain browser=chrome
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\Application\10.0.648.204\gcswf32.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=2068.069C0E00.1381878079 /prefetch:4 --flash-broker=3916
C:\Windows\system32\wbem\wmiprvse.exe
"F:\download\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
C:\Windows\System32\svchost.exe -k LocalServicePeerNet

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2010-10-19 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-10-19 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ffa0793e-3980-4be4-8234-048fa665f700}]
Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll [2010-09-06 1048888]
{ffa0793e-3980-4be4-8234-048fa665f700} - Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files (x86)\ICQ7.4\ICQ.exe [2011-03-01 119608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-03-28 1910152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxbkbmgr.exe]
C:\Program Files (x86)\Lexmark X1100 Series\lxbkbmgr.exe [2008-02-28 74408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RESTART_STICKY_NOTES]
C:\Windows\System32\StikyNot.exe [2009-07-14 427520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-01-26 15026056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSDMonitor]
C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload]
C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio 11\uvPL.exe [2007-03-03 341488]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xvid]
C:\Program Files (x86)\Xvid\CheckUpdate.exe [2011-01-17 8192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\READER~1.EXE [2006-10-23 40048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\ADOBEC~1.EXE [2006-10-23 734872]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-02-23 3451496]

C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SolutoService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-03-30 17:51:40 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-03-30 17:51:39 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-03-30 17:51:38 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\aswBoot.exe
2011-03-30 17:50:33 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-03-30 17:50:30 ----D---- C:\ProgramData\AVAST Software
2011-03-30 17:50:30 ----D---- C:\Program Files\AVAST Software
2011-03-30 15:58:11 ----D---- C:\Windows\pss
2011-03-30 15:41:47 ----D---- C:\rsit
2011-03-30 15:41:47 ----D---- C:\Program Files\trend micro
2011-03-30 15:39:59 ----A---- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2011-03-30 15:37:49 ----A---- C:\Windows\system32\drivers\Soluto.sys
2011-03-30 15:37:47 ----D---- C:\Program Files\Soluto
2011-03-30 15:36:51 ----D---- C:\ProgramData\Soluto
2011-03-29 19:03:29 ----D---- C:\Users\Michal\AppData\Roaming\Registry Mechanic
2011-03-29 14:48:11 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2011-03-28 16:19:39 ----A---- C:\Windows\SYSWOW64\ConduitEngine.tmp
2011-03-28 16:16:18 ----AD---- C:\ProgramData\TEMP
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidcore.dll
2011-03-25 07:17:20 ----D---- C:\Program Files (x86)\aTube Catcher
2011-03-25 07:12:29 ----D---- C:\Program Files (x86)\DVDVideoSoft
2011-03-23 21:06:09 ----D---- C:\ProgramData\MySQL
2011-03-23 16:59:54 ----D---- C:\Users\Michal\AppData\Roaming\GitExtensions
2011-03-23 16:55:37 ----D---- C:\Program Files (x86)\KDiff3
2011-03-22 21:07:28 ----D---- C:\Program Files (x86)\THQ
2011-03-22 20:53:56 ----A---- C:\Windows\SYSWOW64\CmdLineExt_x64.dll
2011-03-22 20:52:33 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-03-22 20:52:33 ----A---- C:\Windows\system32\d3dx10.dll
2011-03-22 20:52:31 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-03-22 20:52:31 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-03-22 20:52:20 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-03-22 20:52:20 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-03-17 17:14:34 ----D---- C:\Users\Michal\AppData\Roaming\Ulead Systems
2011-03-17 17:13:10 ----D---- C:\ProgramData\InterVideo
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeW7.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizePX.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeP6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeM6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeA6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresize.dll
2011-03-17 17:12:38 ----D---- C:\Program Files (x86)\Windows Media Components
2011-03-17 17:11:56 ----D---- C:\ProgramData\Ulead Systems
2011-03-17 17:11:55 ----D---- C:\Program Files (x86)\Ulead Systems
2011-03-17 16:51:09 ----D---- C:\Program Files (x86)\Movie Maker 2.6
2011-03-16 16:31:56 ----D---- C:\Program Files (x86)\Conduit
2011-03-16 16:31:51 ----D---- C:\Program Files (x86)\ConduitEngine
2011-03-16 16:31:42 ----D---- C:\Program Files (x86)\Softonic_English_FF
2011-03-16 16:29:37 ----A---- C:\Windows\SYSWOW64\pncrt.dll
2011-03-16 16:20:11 ----D---- C:\Users\Michal\AppData\Roaming\DivX
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomwave.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomtran.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomrmencoder.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomqtde.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomframe.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflashenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata2.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata1.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomaudioencoder.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\viscomaudiodata.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videotrans.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videoformat.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videocore.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\imgscaler.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\img_utils.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\gdiplus.dll
2011-03-16 16:18:26 ----D---- C:\Program Files (x86)\Zealot Software
2011-03-16 16:18:26 ----A---- C:\Windows\SYSWOW64\xvid.dll
2011-03-16 07:48:51 ----D---- C:\Users\Michal\AppData\Roaming\Crystal Player
2011-03-16 07:46:28 ----D---- C:\Users\Michal\AppData\Roaming\GHISLER
2011-03-16 07:44:24 ----D---- C:\Users\Michal\AppData\Roaming\vlc
2011-03-16 07:42:36 ----D---- C:\Program Files (x86)\VideoLAN
2011-03-16 07:37:31 ----D---- C:\Program Files (x86)\Webteh
2011-03-16 07:32:55 ----D---- C:\Program Files (x86)\Xvid
2011-03-15 18:00:05 ----A---- C:\unetbtin.exe
2011-03-14 18:00:56 ----D---- C:\Program Files (x86)\Google
2011-03-11 20:17:31 ----D---- C:\Program Files (x86)\Cheat Engine 6
2011-03-11 16:31:02 ----D---- C:\Users\Michal\AppData\Roaming\DAEMON Tools Lite
2011-03-11 15:41:11 ----D---- C:\Users\Michal\AppData\Roaming\Adobe
2011-03-09 20:37:47 ----A---- C:\Windows\my.ini.old
2011-03-09 20:36:15 ----A---- C:\Windows\my.ini
2011-03-09 19:06:34 ----D---- C:\Program Files\photoshop
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\FntCache.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\d2d1.dll
2011-03-09 15:56:51 ----A---- C:\Windows\system32\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\CPFilters.dll
2011-03-09 15:56:48 ----A---- C:\Windows\system32\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-03-09 15:56:47 ----A---- C:\Windows\system32\mstsc.exe
2011-03-07 20:04:28 ----D---- C:\ProgramData\Apple Computer
2011-03-07 20:04:28 ----D---- C:\Program Files (x86)\QuickTime
2011-03-07 20:03:01 ----D---- C:\ProgramData\Apple
2011-03-07 20:03:01 ----D---- C:\Program Files (x86)\Apple Software Update
2011-03-03 16:46:42 ----N---- C:\Windows\UniFISH.exe

======List of files/folders modified in the last 1 months======

2011-03-30 18:03:39 ----D---- C:\Windows\temp
2011-03-30 18:02:34 ----D---- C:\ProgramData\NVIDIA
2011-03-30 18:02:14 ----D---- C:\Windows\Tasks
2011-03-30 18:01:53 ----D---- C:\Windows
2011-03-30 18:01:29 ----SHD---- C:\System Volume Information
2011-03-30 18:01:29 ----RD---- C:\Program Files (x86)
2011-03-30 18:01:29 ----D---- C:\Windows\System32
2011-03-30 18:01:29 ----D---- C:\ProgramData\Norton
2011-03-30 18:01:27 ----D---- C:\Program Files (x86)\Common Files
2011-03-30 18:00:26 ----D---- C:\Users\Michal\AppData\Roaming\Skype
2011-03-30 17:59:50 ----SHD---- C:\Windows\Installer
2011-03-30 17:58:47 ----D---- C:\Windows\SysWOW64
2011-03-30 17:58:47 ----D---- C:\Windows\system32\Tasks
2011-03-30 17:58:09 ----D---- C:\Windows\system32\catroot2
2011-03-30 17:51:42 ----D---- C:\Windows\system32\drivers
2011-03-30 17:51:26 ----D---- C:\Windows\winsxs
2011-03-30 17:51:04 ----D---- C:\Windows\system32\config
2011-03-30 17:50:30 ----RD---- C:\Program Files
2011-03-30 17:50:30 ----HD---- C:\ProgramData
2011-03-30 17:46:28 ----D---- C:\Program Files\Common Files
2011-03-30 16:02:58 ----D---- C:\Users\Michal\AppData\Roaming\skypePM
2011-03-30 15:53:06 ----D---- C:\Users\Michal\AppData\Roaming\ICQ
2011-03-30 15:39:34 ----RSD---- C:\Windows\assembly
2011-03-30 15:37:55 ----D---- C:\Windows\system32\catroot
2011-03-30 15:37:49 ----DC---- C:\Windows\system32\DRVSTORE
2011-03-30 14:49:04 ----D---- C:\Windows\inf
2011-03-30 14:49:04 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-03-28 18:04:26 ----D---- C:\Users\Michal\AppData\Roaming\SQLyog
2011-03-27 21:26:43 ----D---- C:\Windows\SYSWOW64\Macromed
2011-03-25 00:14:42 ----D---- C:\Users\Michal\AppData\Roaming\uTorrent
2011-03-24 18:26:17 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-03-24 15:55:25 ----D---- C:\Windows\Microsoft.NET
2011-03-23 23:36:36 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-03-23 23:31:31 ----D---- C:\Windows\SYSWOW64\en-US
2011-03-23 23:31:31 ----D---- C:\Windows\system32\en-US
2011-03-23 23:00:23 ----D---- C:\ProgramData\Adobe
2011-03-23 22:57:32 ----D---- C:\Program Files (x86)\Adobe
2011-03-23 17:00:33 ----D---- C:\Windows\system32\NDF
2011-03-23 16:58:11 ----D---- C:\Program Files (x86)\Git
2011-03-23 16:54:30 ----D---- C:\Program Files (x86)\GitExtensions
2011-03-20 21:23:59 ----D---- C:\Windows\Prefetch
2011-03-20 15:11:43 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-03-17 17:12:36 ----RSD---- C:\Windows\Fonts
2011-03-13 12:05:01 ----A---- C:\Windows\Lexstat.ini
2011-03-11 22:00:52 ----D---- C:\ProgramData\Blizzard Entertainment
2011-03-11 15:29:51 ----D---- C:\Windows\debug
2011-03-09 22:09:57 ----A---- C:\Windows\system32\MRT.exe
2011-03-09 19:51:10 ----RD---- C:\Users
2011-03-07 20:05:07 ----D---- C:\Program Files (x86)\Internet Explorer
2011-03-04 15:10:57 ----D---- C:\Program Files (x86)\ICQ7.4

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 Soluto;Soluto; C:\Windows\system32\DRIVERS\Soluto.sys [2011-03-27 54728]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-19 834544]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-02-23 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-02-23 505176]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-02-23 280408]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-02-23 53592]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2007-02-18 296816]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-02-23 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-02-23 64344]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-06-22 131688]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 79760]
S3 as4bwim3;as4bwim3; C:\Windows\system32\drivers\as4bwim3.sys []
S3 dump_wmimmc;dump_wmimmc; \??\C:\ijji\ENGLISH\u_sf\GameGuard\dump_wmimmc.sys []
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 NPPTNT2;NPPTNT2; \??\C:\Windows\syswow64\npptNT2.sys [2005-01-02 4682]
S3 pwdrvio;pwdrvio; \??\C:\Windows\syswow64\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\Windows\syswow64\pwdspio.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-02-23 42184]
R2 Capture Device Service;Capture Device Service; C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe [2007-03-06 198168]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-03-28 2111368]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-09-06 247096]
R2 lxbk_device;lxbk_device; C:\Windows\system32\lxbkcoms.exe [2008-02-19 565928]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-31 159336]
R2 SolutoService;Soluto PCGenome Core Service; C:\Program Files\Soluto\SolutoService.exe [2011-03-27 335904]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-31 235624]
R2 TeamViewer5;TeamViewer 5; C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-10-19 2011944]
R2 TeamViewer6;TeamViewer 6; C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-14 136176]
S2 mysql;mysql; F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\mysqld-nt --defaults-file=F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\my.cnf mysql []
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-12-14 128928]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2010-10-21 3966416]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-21 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: Prosim o kontrolu

Napsal: 31 bře 2011 08:04
od Roli
Zdravím, tyhle zbytečnosti fixni v HJT :

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2207613
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll


HJT najdeš zde :

C:\Program Files\trend micro\Michal.exe

Fix znamená že spustíš HJT Obrázek jako admin

v okně které se ti otevře klikneš na Do a system scan only

v dalším okně najdeš řádky které jsem ti vypsal,

vedle nich je čtvereček do kterého uděláš zatržítko,

pak klikneš na Fix checked které je vlevo dole,

program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.


Odinstaluj ICQ6Toolbar


Smaž nepotřebné soubory

pomocí CCleaneru

návod :

Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš

Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)

čištění registru je třeba několikrát zopakovat !

Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém


Jinak nic špatného nevidím.

Re: Prosim o kontrolu

Napsal: 31 bře 2011 08:30
od chodnik74
neni zbytecny i skype toolsbar a plugin v IE? :)

Re: Prosim o kontrolu

Napsal: 31 bře 2011 08:51
od Roli
chodnik74 píše:neni zbytecny i skype toolsbar a plugin v IE? :)
Je, ale není to takové zlo jako ICQ6Toolbar :wink:

Re: Prosim o kontrolu

Napsal: 31 bře 2011 08:56
od assasin172
jj odpoledne to fixnu ... dik :arrow: Obrázek

Re: Prosim o kontrolu

Napsal: 31 bře 2011 08:59
od Roli
Není vůbec zač.

Re: Prosim o kontrolu

Napsal: 31 bře 2011 09:03
od chodnik74
Roli píše:
chodnik74 píše:neni zbytecny i skype toolsbar a plugin v IE? :)
Je, ale není to takové zlo jako ICQ6Toolbar :wink:

Jasny :) ale tak 90% toolsbaru jsou zbytecne :)

jinak neni zbytecna i sluzba:

O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

:???:

Re: Prosim o kontrolu

Napsal: 31 bře 2011 09:17
od Roli
chodnik74 píše:jinak neni zbytecna i sluzba:

O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

:???:

No pokud se používá jako prohlížeč Chrome, tak by měla zůstat spuštěná.

Re: Prosim o kontrolu

Napsal: 31 bře 2011 10:12
od chodnik74
Ja ji mel taky spustenou a tady v preventivkach mam take log a admin mi ji radil vypnout,ze je zbytecna..ze se i bez ni aktualizuje sam =)

Re: Prosim o kontrolu

Napsal: 31 bře 2011 10:38
od Roli
chodnik74 píše:Ja ji mel taky spustenou a tady v preventivkach mam take log a admin mi ji radil vypnout,ze je zbytecna..ze se i bez ni aktualizuje sam =)
To jo jenže ona se většinou spustí znovu.

Re: Prosim o kontrolu

Napsal: 31 bře 2011 11:36
od chodnik74
jakoze ikdyz ji zakazu rucne tak se sama znova obnovi :???:

Re: Prosim o kontrolu

Napsal: 31 bře 2011 12:32
od Roli
Pokud jí vyloženě ručně zakážeš, tak už by se neměla spustit.

Re: Prosim o kontrolu

Napsal: 04 dub 2011 14:45
od assasin172
Zde přikládám log po provedených změnách. Prosím o kontrolu tohoto logu ... děkuji

Logfile of random's system information tool 1.08 (written by random/random)
Run by Michal at 2011-04-04 15:33:48
Microsoft Windows 7 Home Premium
System drive C: has 23 GB (22%) free of 103 GB
Total RAM: 3071 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:33:50, on 4.4.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\CCleaner\CCleaner.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Michal.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R3 - URLSearchHook: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Softonic English FF - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: lxbk_device - - C:\Windows\system32\lxbkcoms.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - C:\Program Files\Soluto\SolutoService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9351 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\Soluto\soluto.exe" /userinit
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Windows\System32\StikyNot.exe"
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"taskhost.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {646FC814-C724-4A13-A221-F518D8764494}
"C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
C:\Windows\system32\lxbkcoms.exe -service
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" -quickstart
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"C:\Program Files\Soluto\SolutoService.exe"
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe"
"C:\Program Files (x86)\CCleaner\CCleaner.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.02261600.629724800 /prefetch:3
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=extension --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.021FD900.822386861 /prefetch:3 --ignored=" --type=renderer "
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.0.0.6907_0\npSkypeChromePlugin.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=3256.0689F000.1598941708 /prefetch:4
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
C:\Windows\system32\rundll32.exe "C:\Users\Michal\AppData\Local\Google\Chrome\APPLIC~1\100648~1.204\gcswf32.dll",BrokerMain browser=chrome
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\Application\10.0.648.204\gcswf32.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=3256.06854C00.1114752745 /prefetch:4 --flash-broker=312
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheSize/CacheSizeGroup_4/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.0A18AD80.1464293168 /prefetch:3
C:\Windows\system32\sppsvc.exe
C:\Windows\servicing\TrustedInstaller.exe
"F:\download\RSITx64.exe"

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2010-10-19 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-10-19 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ffa0793e-3980-4be4-8234-048fa665f700}]
Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{ffa0793e-3980-4be4-8234-048fa665f700} - Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 427520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files (x86)\ICQ7.4\ICQ.exe [2011-03-01 119608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-03-28 1910152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxbkbmgr.exe]
C:\Program Files (x86)\Lexmark X1100 Series\lxbkbmgr.exe [2008-02-28 74408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RESTART_STICKY_NOTES]
C:\Windows\System32\StikyNot.exe [2009-07-14 427520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-01-26 15026056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSDMonitor]
C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload]
C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio 11\uvPL.exe [2007-03-03 341488]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xvid]
C:\Program Files (x86)\Xvid\CheckUpdate.exe [2011-01-17 8192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\READER~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\ADOBEC~1.EXE []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-02-23 3451496]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]

C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SolutoService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2011-04-03 00:16:10 ----D---- C:\Program Files (x86)\GIANTS Software
2011-04-02 16:25:01 ----D---- C:\Program Files (x86)\Landwirtschafts Simulator 2011
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-03-30 17:51:40 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-03-30 17:51:39 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-03-30 17:51:38 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\aswBoot.exe
2011-03-30 17:50:33 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-03-30 17:50:30 ----D---- C:\ProgramData\AVAST Software
2011-03-30 17:50:30 ----D---- C:\Program Files\AVAST Software
2011-03-30 15:58:11 ----D---- C:\Windows\pss
2011-03-30 15:41:47 ----D---- C:\rsit
2011-03-30 15:41:47 ----D---- C:\Program Files\trend micro
2011-03-30 15:39:59 ----A---- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2011-03-30 15:37:49 ----A---- C:\Windows\system32\drivers\Soluto.sys
2011-03-30 15:37:47 ----D---- C:\Program Files\Soluto
2011-03-30 15:36:51 ----D---- C:\ProgramData\Soluto
2011-03-29 19:03:29 ----D---- C:\Users\Michal\AppData\Roaming\Registry Mechanic
2011-03-29 14:48:11 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2011-03-28 16:19:39 ----A---- C:\Windows\SYSWOW64\ConduitEngine.tmp
2011-03-28 16:16:18 ----AD---- C:\ProgramData\TEMP
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidcore.dll
2011-03-25 07:17:20 ----D---- C:\Program Files (x86)\aTube Catcher
2011-03-25 07:12:29 ----D---- C:\Program Files (x86)\DVDVideoSoft
2011-03-23 21:06:09 ----D---- C:\ProgramData\MySQL
2011-03-23 16:59:54 ----D---- C:\Users\Michal\AppData\Roaming\GitExtensions
2011-03-23 16:55:37 ----D---- C:\Program Files (x86)\KDiff3
2011-03-22 21:07:28 ----D---- C:\Program Files (x86)\THQ
2011-03-22 20:53:56 ----A---- C:\Windows\SYSWOW64\CmdLineExt_x64.dll
2011-03-22 20:52:33 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-03-22 20:52:33 ----A---- C:\Windows\system32\d3dx10.dll
2011-03-22 20:52:31 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-03-22 20:52:31 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-03-22 20:52:20 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-03-22 20:52:20 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-03-17 17:14:34 ----D---- C:\Users\Michal\AppData\Roaming\Ulead Systems
2011-03-17 17:13:10 ----D---- C:\ProgramData\InterVideo
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeW7.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizePX.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeP6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeM6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeA6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresize.dll
2011-03-17 17:12:38 ----D---- C:\Program Files (x86)\Windows Media Components
2011-03-17 17:11:56 ----D---- C:\ProgramData\Ulead Systems
2011-03-17 17:11:55 ----D---- C:\Program Files (x86)\Ulead Systems
2011-03-17 16:51:09 ----D---- C:\Program Files (x86)\Movie Maker 2.6
2011-03-16 16:31:56 ----D---- C:\Program Files (x86)\Conduit
2011-03-16 16:31:51 ----D---- C:\Program Files (x86)\ConduitEngine
2011-03-16 16:31:42 ----D---- C:\Program Files (x86)\Softonic_English_FF
2011-03-16 16:29:37 ----A---- C:\Windows\SYSWOW64\pncrt.dll
2011-03-16 16:20:11 ----D---- C:\Users\Michal\AppData\Roaming\DivX
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomwave.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomtran.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomrmencoder.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomqtde.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomframe.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflashenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata2.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata1.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomaudioencoder.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\viscomaudiodata.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videotrans.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videoformat.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videocore.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\imgscaler.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\img_utils.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\gdiplus.dll
2011-03-16 16:18:26 ----D---- C:\Program Files (x86)\Zealot Software
2011-03-16 16:18:26 ----A---- C:\Windows\SYSWOW64\xvid.dll
2011-03-16 07:48:51 ----D---- C:\Users\Michal\AppData\Roaming\Crystal Player
2011-03-16 07:46:28 ----D---- C:\Users\Michal\AppData\Roaming\GHISLER
2011-03-16 07:44:24 ----D---- C:\Users\Michal\AppData\Roaming\vlc
2011-03-16 07:42:36 ----D---- C:\Program Files (x86)\VideoLAN
2011-03-16 07:37:31 ----D---- C:\Program Files (x86)\Webteh
2011-03-16 07:32:55 ----D---- C:\Program Files (x86)\Xvid
2011-03-15 18:00:05 ----A---- C:\unetbtin.exe
2011-03-14 18:00:56 ----D---- C:\Program Files (x86)\Google
2011-03-11 20:17:31 ----D---- C:\Program Files (x86)\Cheat Engine 6
2011-03-11 16:31:02 ----D---- C:\Users\Michal\AppData\Roaming\DAEMON Tools Lite
2011-03-11 15:41:11 ----D---- C:\Users\Michal\AppData\Roaming\Adobe
2011-03-09 20:37:47 ----A---- C:\Windows\my.ini.old
2011-03-09 20:36:15 ----A---- C:\Windows\my.ini
2011-03-09 19:06:34 ----D---- C:\Program Files\photoshop
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\FntCache.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\d2d1.dll
2011-03-09 15:56:51 ----A---- C:\Windows\system32\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\CPFilters.dll
2011-03-09 15:56:48 ----A---- C:\Windows\system32\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-03-09 15:56:47 ----A---- C:\Windows\system32\mstsc.exe
2011-03-07 20:04:28 ----D---- C:\ProgramData\Apple Computer
2011-03-07 20:04:28 ----D---- C:\Program Files (x86)\QuickTime
2011-03-07 20:03:01 ----D---- C:\ProgramData\Apple
2011-03-07 20:03:01 ----D---- C:\Program Files (x86)\Apple Software Update

======List of files/folders modified in the last 1 months======

2011-04-04 15:33:39 ----D---- C:\Windows\system32\config
2011-04-04 15:32:49 ----D---- C:\Windows
2011-04-04 15:32:48 ----D---- C:\Windows\temp
2011-04-04 15:30:33 ----D---- C:\ProgramData\NVIDIA
2011-04-04 15:21:42 ----SHD---- C:\Windows\Installer
2011-04-04 15:20:51 ----D---- C:\Windows\SysWOW64
2011-04-04 15:17:51 ----D---- C:\Windows\Prefetch
2011-04-03 21:07:31 ----D---- C:\ProgramData\Adobe
2011-04-03 15:14:39 ----D---- C:\Windows\winsxs
2011-04-03 15:07:13 ----SD---- C:\Users\Michal\AppData\Roaming\Microsoft
2011-04-03 15:05:29 ----SHD---- C:\System Volume Information
2011-04-03 15:05:19 ----D---- C:\Program Files (x86)\Adobe
2011-04-03 00:16:10 ----RD---- C:\Program Files (x86)
2011-04-02 22:17:26 ----D---- C:\Users\Michal\AppData\Roaming\uTorrent
2011-04-01 20:45:39 ----D---- C:\Users\Michal\AppData\Roaming\Skype
2011-04-01 17:40:00 ----D---- C:\Users\Michal\AppData\Roaming\skypePM
2011-03-31 21:07:38 ----D---- C:\Users\Michal\AppData\Roaming\ICQ
2011-03-31 17:22:01 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-03-30 20:26:54 ----D---- C:\Windows\system32\NDF
2011-03-30 18:02:14 ----D---- C:\Windows\Tasks
2011-03-30 18:01:29 ----D---- C:\Windows\System32
2011-03-30 18:01:29 ----D---- C:\ProgramData\Norton
2011-03-30 18:01:27 ----D---- C:\Program Files (x86)\Common Files
2011-03-30 17:58:47 ----D---- C:\Windows\system32\Tasks
2011-03-30 17:58:09 ----D---- C:\Windows\system32\catroot2
2011-03-30 17:51:42 ----D---- C:\Windows\system32\drivers
2011-03-30 17:50:30 ----RD---- C:\Program Files
2011-03-30 17:50:30 ----HD---- C:\ProgramData
2011-03-30 17:46:28 ----D---- C:\Program Files\Common Files
2011-03-30 15:39:34 ----RSD---- C:\Windows\assembly
2011-03-30 15:37:55 ----D---- C:\Windows\system32\catroot
2011-03-30 15:37:49 ----DC---- C:\Windows\system32\DRVSTORE
2011-03-30 14:49:04 ----D---- C:\Windows\inf
2011-03-30 14:49:04 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-03-28 18:04:26 ----D---- C:\Users\Michal\AppData\Roaming\SQLyog
2011-03-27 21:26:43 ----D---- C:\Windows\SYSWOW64\Macromed
2011-03-24 18:26:17 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-03-24 15:55:25 ----D---- C:\Windows\Microsoft.NET
2011-03-23 23:36:36 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-03-23 23:31:31 ----D---- C:\Windows\SYSWOW64\en-US
2011-03-23 23:31:31 ----D---- C:\Windows\system32\en-US
2011-03-23 16:58:11 ----D---- C:\Program Files (x86)\Git
2011-03-23 16:54:30 ----D---- C:\Program Files (x86)\GitExtensions
2011-03-17 17:12:36 ----RSD---- C:\Windows\Fonts
2011-03-13 12:05:01 ----A---- C:\Windows\Lexstat.ini
2011-03-11 22:00:52 ----D---- C:\ProgramData\Blizzard Entertainment
2011-03-11 15:29:51 ----D---- C:\Windows\debug
2011-03-09 22:09:57 ----A---- C:\Windows\system32\MRT.exe
2011-03-09 19:51:10 ----RD---- C:\Users
2011-03-07 20:05:07 ----D---- C:\Program Files (x86)\Internet Explorer

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 Soluto;Soluto; C:\Windows\system32\DRIVERS\Soluto.sys [2011-03-27 54728]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-19 834544]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-02-23 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-02-23 505176]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-02-23 280408]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-02-23 53592]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2007-02-18 296816]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-02-23 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-02-23 64344]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-06-22 131688]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 79760]
S3 awlgqige;awlgqige; C:\Windows\system32\drivers\awlgqige.sys []
S3 dump_wmimmc;dump_wmimmc; \??\C:\ijji\ENGLISH\u_sf\GameGuard\dump_wmimmc.sys []
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 NPPTNT2;NPPTNT2; \??\C:\Windows\syswow64\npptNT2.sys [2005-01-02 4682]
S3 pwdrvio;pwdrvio; \??\C:\Windows\syswow64\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\Windows\syswow64\pwdspio.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-02-23 42184]
R2 Capture Device Service;Capture Device Service; C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe [2007-03-06 198168]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-03-28 2111368]
R2 lxbk_device;lxbk_device; C:\Windows\system32\lxbkcoms.exe [2008-02-19 565928]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-31 159336]
R2 SolutoService;Soluto PCGenome Core Service; C:\Program Files\Soluto\SolutoService.exe [2011-03-27 335904]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-31 235624]
R2 TeamViewer6;TeamViewer 6; C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-14 136176]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-12-14 128928]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2010-10-21 3966416]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-21 1255736]
S4 mysql;mysql; F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\mysqld-nt --defaults-file=F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\my.cnf mysql []
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: Prosim o kontrolu

Napsal: 04 dub 2011 14:58
od Roli
ICQ Toolbar tam sice není ale ten fix nějak nevyšel.

Tak zkus znovu tohle fixnout :

R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe


jak na to jsem již psal.

Ještě bych rád kdybys použil Mbam z mého podpisu a del mi sem z něj log, předem nic nemazat !!!

Re: Prosim o kontrolu

Napsal: 04 dub 2011 15:33
od assasin172
takže log po fixnutí:

Logfile of random's system information tool 1.08 (written by random/random)
Run by Michal at 2011-04-04 16:32:08
Microsoft Windows 7 Home Premium
System drive C: has 23 GB (22%) free of 103 GB
Total RAM: 3071 MB (52% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:32:12, on 4.4.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Michal.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R3 - URLSearchHook: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Softonic English FF - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: lxbk_device - - C:\Windows\system32\lxbkcoms.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - C:\Program Files\Soluto\SolutoService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9180 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\Soluto\soluto.exe" /userinit
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Windows\System32\StikyNot.exe"
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"taskhost.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {646FC814-C724-4A13-A221-F518D8764494}
"C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
C:\Windows\system32\lxbkcoms.exe -service
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" -quickstart
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"C:\Program Files\Soluto\SolutoService.exe"
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.02261600.629724800 /prefetch:3
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=extension --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.021FD900.822386861 /prefetch:3 --ignored=" --type=renderer "
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.0.0.6907_0\npSkypeChromePlugin.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=3256.0689F000.1598941708 /prefetch:4
C:\Windows\system32\rundll32.exe "C:\Users\Michal\AppData\Local\Google\Chrome\APPLIC~1\100648~1.204\gcswf32.dll",BrokerMain browser=chrome
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\Application\10.0.648.204\gcswf32.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=3256.06854C00.1114752745 /prefetch:4 --flash-broker=312
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheSize/CacheSizeGroup_4/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.02287600.666679802 /prefetch:3
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheSize/CacheSizeGroup_4/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.0A5ED480.448304604 /prefetch:3
taskeng.exe {7C714F3B-6716-4D6F-B6B9-8BFFBE99265D}
C:\Users\Michal\AppData\Local\Google\Update\GoogleUpdate.exe /c
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheSize/CacheSizeGroup_4/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.09E9AC00.1102599991 /prefetch:3
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe9_ Global\UsGthrCtrlFltPipeMssGthrPipe9 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"F:\download\RSITx64.exe"

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2010-10-19 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-10-19 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ffa0793e-3980-4be4-8234-048fa665f700}]
Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{ffa0793e-3980-4be4-8234-048fa665f700} - Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 427520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files (x86)\ICQ7.4\ICQ.exe [2011-03-01 119608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-03-28 1910152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxbkbmgr.exe]
C:\Program Files (x86)\Lexmark X1100 Series\lxbkbmgr.exe [2008-02-28 74408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RESTART_STICKY_NOTES]
C:\Windows\System32\StikyNot.exe [2009-07-14 427520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-01-26 15026056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSDMonitor]
C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload]
C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio 11\uvPL.exe [2007-03-03 341488]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xvid]
C:\Program Files (x86)\Xvid\CheckUpdate.exe [2011-01-17 8192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\READER~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\ADOBEC~1.EXE []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-02-23 3451496]

C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SolutoService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2011-04-03 00:16:10 ----D---- C:\Program Files (x86)\GIANTS Software
2011-04-02 16:25:01 ----D---- C:\Program Files (x86)\Landwirtschafts Simulator 2011
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-03-30 17:51:40 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-03-30 17:51:39 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-03-30 17:51:38 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\aswBoot.exe
2011-03-30 17:50:33 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-03-30 17:50:30 ----D---- C:\ProgramData\AVAST Software
2011-03-30 17:50:30 ----D---- C:\Program Files\AVAST Software
2011-03-30 15:58:11 ----D---- C:\Windows\pss
2011-03-30 15:41:47 ----D---- C:\rsit
2011-03-30 15:41:47 ----D---- C:\Program Files\trend micro
2011-03-30 15:39:59 ----A---- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2011-03-30 15:37:49 ----A---- C:\Windows\system32\drivers\Soluto.sys
2011-03-30 15:37:47 ----D---- C:\Program Files\Soluto
2011-03-30 15:36:51 ----D---- C:\ProgramData\Soluto
2011-03-29 19:03:29 ----D---- C:\Users\Michal\AppData\Roaming\Registry Mechanic
2011-03-29 14:48:11 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2011-03-28 16:19:39 ----A---- C:\Windows\SYSWOW64\ConduitEngine.tmp
2011-03-28 16:16:18 ----AD---- C:\ProgramData\TEMP
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidcore.dll
2011-03-25 07:17:20 ----D---- C:\Program Files (x86)\aTube Catcher
2011-03-25 07:12:29 ----D---- C:\Program Files (x86)\DVDVideoSoft
2011-03-23 21:06:09 ----D---- C:\ProgramData\MySQL
2011-03-23 16:59:54 ----D---- C:\Users\Michal\AppData\Roaming\GitExtensions
2011-03-23 16:55:37 ----D---- C:\Program Files (x86)\KDiff3
2011-03-22 21:07:28 ----D---- C:\Program Files (x86)\THQ
2011-03-22 20:53:56 ----A---- C:\Windows\SYSWOW64\CmdLineExt_x64.dll
2011-03-22 20:52:33 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-03-22 20:52:33 ----A---- C:\Windows\system32\d3dx10.dll
2011-03-22 20:52:31 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-03-22 20:52:31 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-03-22 20:52:20 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-03-22 20:52:20 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-03-17 17:14:34 ----D---- C:\Users\Michal\AppData\Roaming\Ulead Systems
2011-03-17 17:13:10 ----D---- C:\ProgramData\InterVideo
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeW7.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizePX.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeP6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeM6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeA6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresize.dll
2011-03-17 17:12:38 ----D---- C:\Program Files (x86)\Windows Media Components
2011-03-17 17:11:56 ----D---- C:\ProgramData\Ulead Systems
2011-03-17 17:11:55 ----D---- C:\Program Files (x86)\Ulead Systems
2011-03-17 16:51:09 ----D---- C:\Program Files (x86)\Movie Maker 2.6
2011-03-16 16:31:56 ----D---- C:\Program Files (x86)\Conduit
2011-03-16 16:31:51 ----D---- C:\Program Files (x86)\ConduitEngine
2011-03-16 16:31:42 ----D---- C:\Program Files (x86)\Softonic_English_FF
2011-03-16 16:29:37 ----A---- C:\Windows\SYSWOW64\pncrt.dll
2011-03-16 16:20:11 ----D---- C:\Users\Michal\AppData\Roaming\DivX
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomwave.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomtran.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomrmencoder.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomqtde.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomframe.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflashenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata2.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata1.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomaudioencoder.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\viscomaudiodata.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videotrans.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videoformat.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videocore.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\imgscaler.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\img_utils.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\gdiplus.dll
2011-03-16 16:18:26 ----D---- C:\Program Files (x86)\Zealot Software
2011-03-16 16:18:26 ----A---- C:\Windows\SYSWOW64\xvid.dll
2011-03-16 07:48:51 ----D---- C:\Users\Michal\AppData\Roaming\Crystal Player
2011-03-16 07:46:28 ----D---- C:\Users\Michal\AppData\Roaming\GHISLER
2011-03-16 07:44:24 ----D---- C:\Users\Michal\AppData\Roaming\vlc
2011-03-16 07:42:36 ----D---- C:\Program Files (x86)\VideoLAN
2011-03-16 07:37:31 ----D---- C:\Program Files (x86)\Webteh
2011-03-16 07:32:55 ----D---- C:\Program Files (x86)\Xvid
2011-03-15 18:00:05 ----A---- C:\unetbtin.exe
2011-03-14 18:00:56 ----D---- C:\Program Files (x86)\Google
2011-03-11 20:17:31 ----D---- C:\Program Files (x86)\Cheat Engine 6
2011-03-11 16:31:02 ----D---- C:\Users\Michal\AppData\Roaming\DAEMON Tools Lite
2011-03-11 15:41:11 ----D---- C:\Users\Michal\AppData\Roaming\Adobe
2011-03-09 20:37:47 ----A---- C:\Windows\my.ini.old
2011-03-09 20:36:15 ----A---- C:\Windows\my.ini
2011-03-09 19:06:34 ----D---- C:\Program Files\photoshop
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\FntCache.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\d2d1.dll
2011-03-09 15:56:51 ----A---- C:\Windows\system32\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\CPFilters.dll
2011-03-09 15:56:48 ----A---- C:\Windows\system32\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-03-09 15:56:47 ----A---- C:\Windows\system32\mstsc.exe
2011-03-07 20:04:28 ----D---- C:\ProgramData\Apple Computer
2011-03-07 20:04:28 ----D---- C:\Program Files (x86)\QuickTime
2011-03-07 20:03:01 ----D---- C:\ProgramData\Apple
2011-03-07 20:03:01 ----D---- C:\Program Files (x86)\Apple Software Update

======List of files/folders modified in the last 1 months======

2011-04-04 15:45:14 ----D---- C:\Windows\temp
2011-04-04 15:43:42 ----D---- C:\Windows\system32\config
2011-04-04 15:32:49 ----D---- C:\Windows
2011-04-04 15:30:33 ----D---- C:\ProgramData\NVIDIA
2011-04-04 15:21:42 ----SHD---- C:\Windows\Installer
2011-04-04 15:20:51 ----D---- C:\Windows\SysWOW64
2011-04-04 15:17:51 ----D---- C:\Windows\Prefetch
2011-04-03 21:07:31 ----D---- C:\ProgramData\Adobe
2011-04-03 15:14:39 ----D---- C:\Windows\winsxs
2011-04-03 15:07:13 ----SD---- C:\Users\Michal\AppData\Roaming\Microsoft
2011-04-03 15:05:29 ----SHD---- C:\System Volume Information
2011-04-03 15:05:19 ----D---- C:\Program Files (x86)\Adobe
2011-04-03 00:16:10 ----RD---- C:\Program Files (x86)
2011-04-02 22:17:26 ----D---- C:\Users\Michal\AppData\Roaming\uTorrent
2011-04-01 20:45:39 ----D---- C:\Users\Michal\AppData\Roaming\Skype
2011-04-01 17:40:00 ----D---- C:\Users\Michal\AppData\Roaming\skypePM
2011-03-31 21:07:38 ----D---- C:\Users\Michal\AppData\Roaming\ICQ
2011-03-31 17:22:01 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-03-30 20:26:54 ----D---- C:\Windows\system32\NDF
2011-03-30 18:02:14 ----D---- C:\Windows\Tasks
2011-03-30 18:01:29 ----D---- C:\Windows\System32
2011-03-30 18:01:29 ----D---- C:\ProgramData\Norton
2011-03-30 18:01:27 ----D---- C:\Program Files (x86)\Common Files
2011-03-30 17:58:47 ----D---- C:\Windows\system32\Tasks
2011-03-30 17:58:09 ----D---- C:\Windows\system32\catroot2
2011-03-30 17:51:42 ----D---- C:\Windows\system32\drivers
2011-03-30 17:50:30 ----RD---- C:\Program Files
2011-03-30 17:50:30 ----HD---- C:\ProgramData
2011-03-30 17:46:28 ----D---- C:\Program Files\Common Files
2011-03-30 15:39:34 ----RSD---- C:\Windows\assembly
2011-03-30 15:37:55 ----D---- C:\Windows\system32\catroot
2011-03-30 15:37:49 ----DC---- C:\Windows\system32\DRVSTORE
2011-03-30 14:49:04 ----D---- C:\Windows\inf
2011-03-30 14:49:04 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-03-28 18:04:26 ----D---- C:\Users\Michal\AppData\Roaming\SQLyog
2011-03-27 21:26:43 ----D---- C:\Windows\SYSWOW64\Macromed
2011-03-24 18:26:17 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-03-24 15:55:25 ----D---- C:\Windows\Microsoft.NET
2011-03-23 23:36:36 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-03-23 23:31:31 ----D---- C:\Windows\SYSWOW64\en-US
2011-03-23 23:31:31 ----D---- C:\Windows\system32\en-US
2011-03-23 16:58:11 ----D---- C:\Program Files (x86)\Git
2011-03-23 16:54:30 ----D---- C:\Program Files (x86)\GitExtensions
2011-03-17 17:12:36 ----RSD---- C:\Windows\Fonts
2011-03-13 12:05:01 ----A---- C:\Windows\Lexstat.ini
2011-03-11 22:00:52 ----D---- C:\ProgramData\Blizzard Entertainment
2011-03-11 15:29:51 ----D---- C:\Windows\debug
2011-03-09 22:09:57 ----A---- C:\Windows\system32\MRT.exe
2011-03-09 19:51:10 ----RD---- C:\Users
2011-03-07 20:05:07 ----D---- C:\Program Files (x86)\Internet Explorer

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 Soluto;Soluto; C:\Windows\system32\DRIVERS\Soluto.sys [2011-03-27 54728]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-19 834544]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-02-23 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-02-23 505176]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-02-23 280408]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-02-23 53592]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2007-02-18 296816]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-02-23 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-02-23 64344]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-06-22 131688]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 79760]
S3 awlgqige;awlgqige; C:\Windows\system32\drivers\awlgqige.sys []
S3 dump_wmimmc;dump_wmimmc; \??\C:\ijji\ENGLISH\u_sf\GameGuard\dump_wmimmc.sys []
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 NPPTNT2;NPPTNT2; \??\C:\Windows\syswow64\npptNT2.sys [2005-01-02 4682]
S3 pwdrvio;pwdrvio; \??\C:\Windows\syswow64\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\Windows\syswow64\pwdspio.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-02-23 42184]
R2 Capture Device Service;Capture Device Service; C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe [2007-03-06 198168]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-03-28 2111368]
R2 lxbk_device;lxbk_device; C:\Windows\system32\lxbkcoms.exe [2008-02-19 565928]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-31 159336]
R2 SolutoService;Soluto PCGenome Core Service; C:\Program Files\Soluto\SolutoService.exe [2011-03-27 335904]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-31 235624]
R2 TeamViewer6;TeamViewer 6; C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-14 136176]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-12-14 128928]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2010-10-21 3966416]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-21 1255736]
S4 mysql;mysql; F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\mysqld-nt --defaults-file=F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\my.cnf mysql []
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------


Mbam log přidám jakmile bude dokončen scan