Stránka 1 z 1

vytížení cpu na 100%

Napsal: 21 dub 2011 12:46
od Moody
omlouvám se že se vracím k mému starému dotazu http://www.viry.cz/forum/viewtopic.php?f=13&t=110694&
ale když CF odstranil infikovaný soubor svchost.exe - od té doby se často vytěžuje CPU - klidně i na 100% . ale žádný z puštěných procesů to není. Po hardwarové stránce je vše v pořádku , ovladače aktualizovány , registry jsou pročištěny v CC...
Používám MSEssentials + ZoneAlarm firewall. Dnes jsem provedl kompletní scan spyware terminatorovi a nic to nenašlo , jen nějaké sledovací cookies. Jinak svchost.exe se nachází v standartním umístění v Windows/System32 ale i v dalších umístěních.
když pustím svchost.exe v umístění Windows/System32 , tak se nepřidá do běžících procesů.. Už si nevím rady :?:
_____________________________
Mám přiložit log z CF?

Děkuji za všechny rady...
:worship:

Re: vytížení cpu na 100%

Napsal: 21 dub 2011 14:58
od Moody
nikdo neví co s tím? :(

Re: vytížení cpu na 100%

Napsal: 21 dub 2011 15:14
od chodnik74
1) udělej snímek obrazovky Správce úloh,kde půjde vidět které procesy nejvíce vytěžují procesor

Jak udělat snímek :???:
http://www.viry.cz/forum/viewtopic.php?f=11&t=14114

2) soubor,který svchost.exe uploadni na VIRUSTOTAL a vlož sem odkaz :)
http://www.virustotal.com/index.html

Re: vytížení cpu na 100%

Napsal: 21 dub 2011 16:41
od Moody
VT:
http://www.virustotal.com/file-scan/rep ... 1303399870#

IMGShack:

http://img810.imageshack.us/g/ulohy.jpg/
(nyní bylo vytížení procesoru v klidu na 82 %)

PS: při hledání svchost.exe mi našlo několik svchost.exe , ale v jiných umístěních..

Re: vytížení cpu na 100%

Napsal: 21 dub 2011 16:49
od filip544
Záskok než se chodnik74 objevý.

V jakých umístěních jste našel svchost.exe?

+ Dejte Log z RSIT http://www.viry.cz/forum/viewtopic.php?f=24&t=81939 pro Rádce. :)
Vypadá to že máte opravdu zavirovaný PC. :o

Re: vytížení cpu na 100%

Napsal: 21 dub 2011 17:10
od Moody
takže umístění :

1.C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356
2. C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356
3. C:/Windows/ERDNT/Cache64
3. C:/Windows/ERDNT/Cache86
4. C:/Windows/SysWOW64
5. C:/Windows/System32 - zde bývá podle Windows stardatně..

Díky za rady :)

Re: vytížení cpu na 100%

Napsal: 21 dub 2011 17:12
od filip544
OK.Věděl bych jak to napravit ale nejsem rádce takže nemohu používat programy v podobě CF atd.
Dejte sem ten log z RSIT a pak se uvidí dál.

Re: vytížení cpu na 100%

Napsal: 21 dub 2011 17:15
od Moody
Logfile of random's system information tool 1.08 (written by random/random)
Run by Petr at 2011-04-21 18:13:10
Microsoft Windows 7 Ultimate
System drive C: has 27 GB (27%) free of 100 GB
Total RAM: 2046 MB (24% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:13:43, on 21.4.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.7930.16406)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files (x86)\Razer\Abyssus\razerhid.exe
C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files (x86)\Razer\Abyssus\razertra.exe
C:\Program Files (x86)\Razer\Abyssus\razerofa.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files\trend micro\Petr.exe
C:\Program Files (x86)\Winamp\winamp.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://search13.net/search.php?clid=486&q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://google.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2645238
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://seznam.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: &Crawler Toolbar Helper - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FBLayouts Plugin - {FF4E1D1D-705B-4379-AB33-22D98C1ABF55} - (no file)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: HopSurf toolbar - {E9FAB13D-4600-49E1-90D1-EE961C859D39} - C:\Program Files (x86)\Comodo\HopSurfToolbar\HopSurfToolbar_IE.dll
O3 - Toolbar: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [Abyssus] C:\Program Files (x86)\Razer\Abyssus\razerhid.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-21-3571306171-2943904893-4274187742-1008\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3571306171-2943904893-4274187742-1008\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\iobit\advanced systemcare 3\spictrl.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\iobit\advanced systemcare 3\spictrl.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\iobit\advanced systemcare 3\spictrl.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\iobit\advanced systemcare 3\spictrl.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {672EE252-D813-4F5E-81BB-5DD163DD4FA5} (Active602XMLFiller Control) - https://www.mojedatovaschranka.cz/stati ... ?3,16,13,0
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{94B0A123-6D1F-49EA-8810-E21AA1CEE75C}: NameServer = 213.46.172.36,213.46.172.37
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\PROGRAM FILES (X86)\TUNEUP UTILITIES 2011\TUNEUPUTILITIESSERVICE64.EXE
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11481 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\SysWOW64\ZoneLabs\vsmon.exe -service
"C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {FC911B3D-2B90-462F-8D2B-2AB9700EDA25}
"C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe"
C:\Windows\system32\rundll32.exe "C:\Windows\SysWOW64\rdpd3d9.dll",kfojbxjp
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
"C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe"
"C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe"
"C:\Program Files (x86)\Common Files\Logishrd\LVMVFM\LVPrS64H.exe" -Embedding
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\PROGRAM FILES (X86)\TUNEUP UTILITIES 2011\TUNEUPUTILITIESSERVICE64.EXE"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
WLIDSvcM.exe 2176
"taskhost.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe"
"C:\Program Files (x86)\Razer\Abyssus\razerhid.exe"
"C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
"C:\Program Files (x86)\Razer\Abyssus\razertra.exe"
"C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /set_event="FFAPI_StartEvent_b7c_1206b" /icon="hidden"
"C:\Program Files (x86)\Razer\Abyssus\razerofa.exe"
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"
"C:\Windows\system32\wuauclt.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\PROGRAM FILES (X86)\TUNEUP UTILITIES 2011\TuneUpUtilitiesApp64.EXE" /TUStart /pid:2148
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
"C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe" /SILENT
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe31_ Global\UsGthrCtrlFltPipeMssGthrPipe31 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 592 596 604 65536 600
"C:\Users\Petr\Desktop\RSITx64 (1).exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Program Files (x86)\Winamp\winamp.exe" -Embedding

======Scheduled tasks folder======

C:\Windows\tasks\At1.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3571306171-2943904893-4274187742-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3571306171-2943904893-4274187742-1000UA.job
C:\Windows\tasks\ParetoLogic Registration3.job
C:\Windows\tasks\ParetoLogic Update Version3.job
C:\Windows\tasks\PC Health Advisor Defrag.job
C:\Windows\tasks\PC Health Advisor.job
C:\Windows\tasks\Sttnlnqy.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}]
ZoneAlarm Security Engine Registrar - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2011-02-15 903672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-04-12 43520]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
&Crawler Toolbar Helper - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll [2011-04-08 1236104]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}]
ZoneAlarm Security Engine Registrar - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll [2011-02-15 599544]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
ZoneAlarm Security Toolbar - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll [2010-12-01 2735200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-02-09 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF4E1D1D-705B-4379-AB33-22D98C1ABF55}]
FBLayouts Plugin

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{E9FAB13D-4600-49E1-90D1-EE961C859D39} - HopSurf toolbar - C:\Program Files\Comodo\HopSurfToolbar\HopSurfToolbar_IE.dll [2011-01-15 1619136]
{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - ZoneAlarm Security Engine - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2011-02-15 903672]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll [2010-09-06 1048888]
{E9FAB13D-4600-49E1-90D1-EE961C859D39} - HopSurf toolbar - C:\Program Files (x86)\Comodo\HopSurfToolbar\HopSurfToolbar_IE.dll [2011-01-15 1122496]
{91da5e8a-3318-4f8c-b67e-5964de3ab546} - ZoneAlarm Security Toolbar - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll [2010-12-01 2735200]
{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - ZoneAlarm Security Engine - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll [2011-02-15 599544]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler Toolbar - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll [2011-04-08 1236104]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ISW"=C:\Program Files\CheckPoint\ZAForceField\ForceField.exe [2011-02-15 1123320]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 1436224]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpywareTerminatorUpdate"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2011-04-21 3318784]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2011-03-17 2988488]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe /s []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Vid]
C:\Program Files (x86)\Logitech\Vid HD\Vid.exe [2011-01-13 6129496]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-03-28 1910152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-04-30 10806816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files (x86)\Winamp\winampa.exe [2010-12-09 74752]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Abyssus"=C:\Program Files (x86)\Razer\Abyssus\razerhid.exe [2010-05-10 223744]
"ZoneAlarm Client"=C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe [2011-03-18 1043968]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2010-01-19 43632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2010-09-01 250368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutorun"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2011-04-21 18:11:49 ----D---- C:\rsit
2011-04-21 15:01:56 ----D---- C:\Users\Petr\AppData\Roaming\.minecraft
2011-04-21 12:25:55 ----D---- C:\Users\Petr\AppData\Roaming\SUPERAntiSpyware.com
2011-04-21 12:25:55 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2011-04-21 12:25:50 ----D---- C:\ProgramData\!SASCORE
2011-04-21 12:25:45 ----D---- C:\Program Files\SUPERAntiSpyware
2011-04-21 12:03:34 ----D---- C:\Users\Petr\AppData\Roaming\ParetoLogic
2011-04-21 12:03:34 ----D---- C:\Users\Petr\AppData\Roaming\DriverCure
2011-04-21 12:02:52 ----D---- C:\ProgramData\ParetoLogic
2011-04-21 12:02:52 ----D---- C:\Program Files (x86)\ParetoLogic
2011-04-21 10:28:09 ----A---- C:\Windows\system32\TURegOpt.exe
2011-04-21 10:27:22 ----D---- C:\Program Files (x86)\TuneUp Utilities 2011
2011-04-21 08:42:04 ----D---- C:\Program Files (x86)\Crawler
2011-04-21 08:41:52 ----D---- C:\Users\Petr\AppData\Roaming\Spyware Terminator
2011-04-21 08:41:43 ----D---- C:\ProgramData\Spyware Terminator
2011-04-21 08:41:35 ----D---- C:\Program Files (x86)\Spyware Terminator
2011-04-20 19:37:57 ----D---- C:\Program Files (x86)\Microsoft Security Client
2011-04-20 19:37:39 ----D---- C:\Program Files\Microsoft Security Client
2011-04-19 17:37:11 ----D---- C:\Program Files (x86)\Wolfenstein - Enemy Territory
2011-04-19 15:38:34 ----D---- C:\CFLog
2011-04-19 15:07:34 ----D---- C:\Program Files (x86)\Z8Games
2011-04-19 14:19:14 ----D---- C:\Users\Petr\AppData\Roaming\Sierra Entertainment
2011-04-19 14:18:44 ----RHD---- C:\Users\Petr\AppData\Roaming\SecuROM
2011-04-19 14:10:54 ----D---- C:\Windows\85EBB28365AF4C539EBE7C0A232762F7.TMP
2011-04-19 14:01:38 ----D---- C:\Program Files (x86)\Sierra Entertainment
2011-04-19 12:35:54 ----SD---- C:\ComboFix
2011-04-19 11:26:27 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2011-04-19 11:26:27 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2011-04-19 11:26:27 ----A---- C:\Windows\system32\OpenCL.dll
2011-04-19 11:26:27 ----A---- C:\Windows\system32\nvoglv64.dll
2011-04-19 11:26:27 ----A---- C:\Windows\system32\nvgenco642060.dll
2011-04-19 11:26:27 ----A---- C:\Windows\system32\nvdispco6420140.dll
2011-04-19 11:26:27 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-04-19 11:26:26 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2011-04-19 11:26:26 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2011-04-19 11:26:26 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2011-04-19 11:26:26 ----A---- C:\Windows\system32\nvd3dumx.dll
2011-04-19 11:26:26 ----A---- C:\Windows\system32\nvcuvid.dll
2011-04-19 11:26:26 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-04-19 11:26:26 ----A---- C:\Windows\system32\nvcuda.dll
2011-04-19 11:26:25 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2011-04-19 11:26:25 ----A---- C:\Windows\system32\nvcompiler.dll
2011-04-18 20:16:17 ----D---- C:\3cda7a0bf8205269000d35336f
2011-04-18 20:15:29 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-04-18 20:15:29 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-04-18 20:15:29 ----A---- C:\Windows\system32\atmlib.dll
2011-04-18 20:15:29 ----A---- C:\Windows\system32\atmfd.dll
2011-04-18 20:14:57 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-04-18 20:14:57 ----A---- C:\Windows\system32\inetcomm.dll
2011-04-18 20:14:41 ----A---- C:\Windows\system32\FXSCOVER.exe
2011-04-18 20:14:26 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-04-18 20:14:26 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-04-18 20:14:26 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-04-18 20:14:26 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-04-18 20:14:07 ----A---- C:\Windows\system32\win32k.sys
2011-04-18 20:13:49 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2011-04-18 20:13:49 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2011-04-18 20:13:49 ----A---- C:\Windows\system32\mfc42u.dll
2011-04-18 20:13:49 ----A---- C:\Windows\system32\mfc42.dll
2011-04-18 20:13:33 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-04-18 20:13:33 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-04-18 20:13:33 ----A---- C:\Windows\system32\drivers\srv.sys
2011-04-18 20:13:15 ----A---- C:\Windows\system32\kdcom.dll
2011-04-18 20:13:15 ----A---- C:\Windows\system32\kd1394.dll
2011-04-18 20:13:14 ----A---- C:\Windows\system32\winresume.exe
2011-04-18 20:13:14 ----A---- C:\Windows\system32\winload.exe
2011-04-18 20:13:14 ----A---- C:\Windows\system32\kdusb.dll
2011-04-18 20:12:54 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-04-18 20:12:54 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-04-18 20:12:28 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-04-18 20:12:28 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-04-18 20:12:28 ----A---- C:\Windows\system32\FntCache.dll
2011-04-18 20:12:28 ----A---- C:\Windows\system32\DWrite.dll
2011-04-18 20:12:28 ----A---- C:\Windows\system32\d2d1.dll
2011-04-18 20:12:17 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-04-18 20:12:17 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-04-18 20:12:17 ----A---- C:\Windows\system32\mstscax.dll
2011-04-18 20:12:17 ----A---- C:\Windows\system32\mstsc.exe
2011-04-18 20:11:32 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-04-18 20:11:32 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-04-18 20:11:32 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-04-18 20:11:32 ----A---- C:\Windows\system32\d3d10_1.dll
2011-04-18 20:11:08 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-04-18 20:11:08 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-04-18 20:11:08 ----A---- C:\Windows\system32\ieui.dll
2011-04-18 20:11:08 ----A---- C:\Windows\system32\ieframe.dll
2011-04-18 20:11:07 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-04-18 20:11:07 ----A---- C:\Windows\system32\mshtml.dll
2011-04-18 20:10:27 ----A---- C:\Windows\SYSWOW64\wcncsvc.dll
2011-04-18 20:10:27 ----A---- C:\Windows\system32\wcncsvc.dll
2011-04-18 19:53:40 ----D---- C:\Program Files\IObit
2011-04-18 19:18:36 ----A---- C:\Windows\SYSWOW64\xRaidSetup.exe
2011-04-18 19:18:36 ----A---- C:\Windows\SYSWOW64\xRaidAPI.dll
2011-04-18 19:10:14 ----D---- C:\Program Files (x86)\Driver-Soft
2011-04-18 19:04:15 ----HDC---- C:\ProgramData\{CC51AE54-B346-4954-ADDB-30BD4F138CF2}
2011-04-16 20:56:03 ----A---- C:\VHCSS.dll
2011-04-16 17:38:11 ----D---- C:\ProgramData\boost_interprocess
2011-04-16 17:18:51 ----D---- C:\Users\Petr\AppData\Roaming\TS3Client
2011-04-14 12:47:04 ----D---- C:\RaidTool
2011-04-14 12:43:40 ----D---- C:\Program Files (x86)\GIGABYTE
2011-04-12 18:52:25 ----D---- C:\Program Files (x86)\SystemRequirementsLab
2011-04-12 18:52:01 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-04-12 18:52:01 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-04-12 18:52:01 ----A---- C:\Windows\SYSWOW64\java.exe
2011-04-12 18:35:20 ----D---- C:\Program Files\Intel Corporation
2011-04-12 18:34:06 ----A---- C:\Windows\system32\javaws.exe
2011-04-12 18:34:06 ----A---- C:\Windows\system32\javaw.exe
2011-04-12 18:34:06 ----A---- C:\Windows\system32\java.exe
2011-04-12 18:34:06 ----A---- C:\Windows\system32\deployJava1.dll
2011-04-12 18:33:46 ----D---- C:\Program Files\Java
2011-04-09 15:00:10 ----D---- C:\Program Files (x86)\Game_Maker8
2011-04-07 23:19:16 ----A---- C:\Windows\system32\nvvsvc.exe
2011-04-07 23:19:16 ----A---- C:\Windows\system32\nvsvcr.dll
2011-04-07 23:19:16 ----A---- C:\Windows\system32\nvmctray.dll
2011-04-07 23:19:14 ----A---- C:\Windows\system32\easyUpdatusAPIU64.dll
2011-04-07 23:19:06 ----A---- C:\Windows\system32\nvcpl.dll
2011-04-07 23:18:42 ----A---- C:\Windows\system32\nvsvc64.dll
2011-04-02 10:24:44 ----D---- C:\Program Files (x86)\Activision
2011-04-02 10:20:16 ----A---- C:\Windows\RomeTW.ini
2011-04-02 10:03:43 ----D---- C:\Program Files (x86)\UltraISO
2011-04-01 17:30:44 ----D---- C:\ProgramData\Spybot - Search & Destroy
2011-04-01 17:30:44 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy
2011-04-01 16:01:08 ----D---- C:\Users\Petr\AppData\Roaming\CheckPoint
2011-04-01 16:00:24 ----D---- C:\Program Files (x86)\Conduit
2011-04-01 16:00:21 ----D---- C:\Program Files (x86)\ZoneAlarm_Security
2011-04-01 16:00:08 ----D---- C:\Program Files\CheckPoint
2011-04-01 15:59:56 ----A---- C:\Windows\SYSWOW64\vsregexp.dll
2011-04-01 15:59:40 ----A---- C:\Windows\system32\drivers\netio.sys
2011-04-01 15:59:00 ----A---- C:\Windows\SYSWOW64\zlcommdb.dll
2011-04-01 15:59:00 ----A---- C:\Windows\SYSWOW64\zlcomm.dll
2011-04-01 15:58:55 ----A---- C:\Windows\SYSWOW64\vswmi.dll
2011-04-01 15:58:46 ----A---- C:\Windows\SYSWOW64\zpeng25.dll
2011-04-01 15:58:46 ----A---- C:\Windows\SYSWOW64\vsxml.dll
2011-04-01 15:58:45 ----D---- C:\Windows\SYSWOW64\ZoneLabs
2011-04-01 15:58:45 ----A---- C:\Windows\SYSWOW64\vspubapi.dll
2011-04-01 15:58:45 ----A---- C:\Windows\SYSWOW64\vsmonapi.dll
2011-04-01 15:58:42 ----A---- C:\Windows\SYSWOW64\vsdata.dll
2011-04-01 15:58:42 ----A---- C:\Windows\system32\drivers\~GLH0023.TMP
2011-04-01 15:58:34 ----N---- C:\Windows\system32\drivers\vsdatant.sys
2011-04-01 15:58:33 ----D---- C:\Program Files (x86)\Zone Labs
2011-04-01 15:58:16 ----D---- C:\ProgramData\CheckPoint
2011-04-01 15:58:15 ----D---- C:\Windows\Internet Logs
2011-04-01 15:58:15 ----A---- C:\Windows\SYSWOW64\vsutil.dll
2011-04-01 15:58:15 ----A---- C:\Windows\SYSWOW64\vsinit.dll
2011-03-31 20:58:35 ----D---- C:\Windows\temp
2011-03-31 20:57:34 ----SHD---- C:\$RECYCLE.BIN
2011-03-31 20:38:30 ----A---- C:\Windows\NIRCMD.exe
2011-03-31 20:37:58 ----A---- C:\Windows\SWXCACLS.exe
2011-03-31 19:05:33 ----A---- C:\Windows\zip.exe
2011-03-31 19:05:33 ----A---- C:\Windows\SWSC.exe
2011-03-31 19:05:33 ----A---- C:\Windows\SWREG.exe
2011-03-31 19:05:33 ----A---- C:\Windows\sed.exe
2011-03-31 19:05:33 ----A---- C:\Windows\PEV.exe
2011-03-31 19:05:33 ----A---- C:\Windows\MBR.exe
2011-03-31 19:05:33 ----A---- C:\Windows\grep.exe
2011-03-31 19:03:32 ----D---- C:\Windows\ERDNT
2011-03-31 19:03:08 ----D---- C:\Qoobox
2011-03-31 17:45:49 ----D---- C:\Program Files\trend micro
2011-03-31 17:41:35 ----D---- C:\Users\Petr\AppData\Roaming\Malwarebytes
2011-03-31 17:41:25 ----D---- C:\ProgramData\Malwarebytes
2011-03-31 17:41:22 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-03-31 17:41:22 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-03-30 15:10:44 ----D---- C:\Windows\SYSWOW64\Wat
2011-03-30 15:10:44 ----D---- C:\Windows\system32\Wat
2011-03-29 22:13:33 ----D---- C:\Program Files\Windows Live
2011-03-29 22:11:49 ----D---- C:\Program Files (x86)\Bing Bar Installer
2011-03-29 21:47:53 ----D---- C:\Windows\system32\SPReview
2011-03-29 21:47:00 ----D---- C:\Windows\system32\EventProviders
2011-03-29 15:46:59 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2011-03-28 19:31:07 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-03-28 19:31:07 ----A---- C:\Windows\system32\d3d10warp.dll
2011-03-28 19:31:04 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-03-28 19:31:03 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-03-28 19:31:03 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-03-28 19:31:03 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-03-28 19:31:03 ----A---- C:\Windows\system32\cdd.dll
2011-03-28 19:30:42 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-03-28 19:30:42 ----A---- C:\Windows\system32\ntdll.dll
2011-03-28 19:30:41 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-03-28 19:30:41 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-03-28 19:30:40 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-03-28 17:57:44 ----A---- C:\Windows\system32\EncDec.dll
2011-03-28 17:57:44 ----A---- C:\Windows\system32\CPFilters.dll
2011-03-28 17:57:43 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-03-28 17:57:42 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-03-28 17:57:41 ----A---- C:\Windows\system32\sbe.dll
2011-03-28 17:57:40 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-03-28 17:57:11 ----A---- C:\Windows\system32\msxml6.dll
2011-03-28 17:57:11 ----A---- C:\Windows\system32\msxml3.dll
2011-03-28 17:57:10 ----A---- C:\Windows\system32\upnp.dll
2011-03-28 17:57:09 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-03-28 17:57:06 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-03-28 17:57:06 ----A---- C:\Windows\system32\winhttp.dll
2011-03-28 17:56:59 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-03-28 17:56:59 ----A---- C:\Windows\system32\WebClnt.dll
2011-03-28 17:56:59 ----A---- C:\Windows\system32\davclnt.dll
2011-03-28 17:56:58 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-03-28 17:56:58 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-03-28 17:56:58 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2011-03-28 17:56:58 ----A---- C:\Windows\system32\wscapi.dll
2011-03-28 17:56:57 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2011-03-28 17:56:57 ----A---- C:\Windows\SYSWOW64\slwga.dll
2011-03-28 17:56:57 ----A---- C:\Windows\system32\wscsvc.dll
2011-03-28 17:56:57 ----A---- C:\Windows\system32\slwga.dll
2011-03-28 17:56:46 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2011-03-28 17:56:46 ----A---- C:\Windows\system32\kerberos.dll
2011-03-28 17:56:14 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-03-28 17:56:13 ----A---- C:\Windows\system32\XpsPrint.dll
2011-03-28 17:56:05 ----A---- C:\Windows\system32\winsrv.dll
2011-03-28 17:41:19 ----D---- C:\ProgramData\AVAST Software
2011-03-28 17:41:19 ----D---- C:\Program Files\AVAST Software
2011-03-27 22:19:01 ----D---- C:\Users\Petr\AppData\Roaming\Opera
2011-03-27 22:10:20 ----D---- C:\Program Files (x86)\Opera
2011-03-27 20:50:55 ----D---- C:\Program Files (x86)\AutoTune Files
2011-03-27 20:50:51 ----D---- C:\Program Files (x86)\Nová složka

======List of files/folders modified in the last 1 months======

2011-04-21 17:56:43 ----D---- C:\Program Files (x86)\Counter-Strike Source
2011-04-21 17:53:59 ----D---- C:\Users\Petr\AppData\Roaming\Skype
2011-04-21 16:07:38 ----D---- C:\Users\Petr\AppData\Roaming\skypePM
2011-04-21 16:03:42 ----D---- C:\Windows\SysWOW64
2011-04-21 16:03:38 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-04-21 14:34:39 ----D---- C:\Windows\system32\config
2011-04-21 12:25:55 ----D---- C:\ProgramData
2011-04-21 12:25:45 ----RD---- C:\Program Files
2011-04-21 12:17:08 ----D---- C:\Windows\Prefetch
2011-04-21 12:16:28 ----D---- C:\ProgramData\NVIDIA
2011-04-21 12:16:25 ----D---- C:\Windows\SYSWOW64\logishrd
2011-04-21 12:16:25 ----D---- C:\Windows\system32\logishrd
2011-04-21 12:16:11 ----AD---- C:\Windows
2011-04-21 12:04:09 ----D---- C:\Windows\system32\Tasks
2011-04-21 12:04:08 ----D---- C:\Windows\Tasks
2011-04-21 12:02:58 ----D---- C:\Program Files (x86)\Common Files
2011-04-21 12:02:52 ----D---- C:\Program Files (x86)
2011-04-21 12:02:52 ----D---- C:\Program Files (x86)
2011-04-21 11:38:16 ----D---- C:\Users\Petr\AppData\Roaming\TuneUp Software
2011-04-21 11:33:09 ----SHD---- C:\System Volume Information
2011-04-21 11:03:13 ----D---- C:\Windows\System32
2011-04-21 10:45:04 ----D---- C:\ProgramData\CyberLink
2011-04-21 10:45:03 ----SHD---- C:\Windows\Installer
2011-04-21 10:37:46 ----D---- C:\Program Files (x86)\Livestream Procaster
2011-04-21 09:33:50 ----DC---- C:\Windows\system32\DRVSTORE
2011-04-21 09:33:49 ----D---- C:\Windows\system32\DriverStore
2011-04-21 09:33:49 ----D---- C:\Windows\system32\catroot
2011-04-21 09:33:49 ----D---- C:\Windows\inf
2011-04-21 09:32:33 ----D---- C:\Windows\system32\drivers
2011-04-21 08:18:42 ----RSD---- C:\Windows\assembly
2011-04-21 08:18:42 ----D---- C:\Windows\Microsoft.NET
2011-04-20 20:39:09 ----D---- C:\Windows\system32\NDF
2011-04-20 19:38:04 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-04-20 18:17:47 ----D---- C:\Windows\system32\oobe
2011-04-20 18:15:06 ----D---- C:\Windows\system32\catroot2
2011-04-20 18:13:33 ----D---- C:\Users\Petr\AppData\Roaming\uTorrent
2011-04-19 21:42:09 ----D---- C:\Stažené Torrenty
2011-04-19 17:47:48 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2011-04-19 15:36:01 ----D---- C:\Users\Petr\AppData\Roaming\Winamp
2011-04-19 14:02:20 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-04-19 11:31:38 ----D---- C:\Program Files\NVIDIA Corporation
2011-04-19 11:29:56 ----RD---- C:\Users
2011-04-19 11:29:54 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2011-04-19 09:51:30 ----D---- C:\Windows\system32\drivers\etc
2011-04-19 08:48:43 ----D---- C:\Users\Petr\AppData\Roaming\vlc
2011-04-18 20:29:50 ----D---- C:\Windows\winsxs
2011-04-18 20:27:06 ----D---- C:\Windows\system32\Boot
2011-04-18 20:24:11 ----D---- C:\ProgramData\IObit
2011-04-18 20:18:37 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-04-18 20:09:07 ----D---- C:\Windows\Logs
2011-04-18 19:52:38 ----D---- C:\Users\Petr\AppData\Roaming\IObit
2011-04-18 19:52:34 ----D---- C:\Program Files (x86)\IObit
2011-04-18 19:25:00 ----A---- C:\Windows\system32\aswBoot.exe
2011-04-18 19:18:37 ----D---- C:\Windows\RaidTool
2011-04-14 18:47:51 ----D---- C:\Windows\system32\wfp
2011-04-14 18:47:47 ----D---- C:\Windows\system32\wbem
2011-04-14 18:47:47 ----D---- C:\Windows\registration
2011-04-14 12:42:30 ----A---- C:\Windows\GSetup.ini
2011-04-12 19:38:47 ----D---- C:\Users\Petr\AppData\Roaming\Audacity
2011-04-12 18:51:45 ----D---- C:\Program Files (x86)\Java
2011-04-11 16:11:41 ----D---- C:\Program Files (x86)\Audacity 1.3 Beta (Unicode)
2011-04-08 07:14:00 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2011-04-08 07:14:00 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2011-04-08 07:14:00 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2011-04-08 07:14:00 ----A---- C:\Windows\system32\nvwgf2umx.dll
2011-04-08 07:14:00 ----A---- C:\Windows\system32\nvapi64.dll
2011-04-02 16:29:39 ----D---- C:\Program Files (x86)\Garena
2011-04-02 11:14:11 ----D---- C:\Windows\SYSWOW64\directx
2011-04-02 11:11:16 ----D---- C:\Temp
2011-04-02 10:24:52 ----D---- C:\Program Files\Activision
2011-04-01 16:22:51 ----D---- C:\Windows\SYSWOW64\drivers
2011-03-31 20:53:16 ----A---- C:\Windows\system.ini
2011-03-31 20:45:43 ----D---- C:\Windows\AppPatch
2011-03-31 20:45:39 ----D---- C:\Program Files\Common Files
2011-03-31 19:02:43 ----D---- C:\Users\Petr\AppData\Roaming\ICQ
2011-03-30 20:03:52 ----D---- C:\Program Files (x86)\Pando Networks
2011-03-30 19:54:08 ----D---- C:\Program Files (x86)\SlySoft
2011-03-30 19:52:50 ----D---- C:\Program Files (x86)\Fiddler2
2011-03-30 19:52:20 ----D---- C:\Warcraft III
2011-03-30 19:50:31 ----D---- C:\Program Files (x86)\Radical Games
2011-03-30 18:57:50 ----A---- C:\Windows\system32\authuitu.dll
2011-03-30 18:57:48 ----A---- C:\Windows\SYSWOW64\authuitu.dll
2011-03-30 18:57:44 ----A---- C:\Windows\system32\uxtuneup.dll
2011-03-30 18:57:40 ----A---- C:\Windows\SYSWOW64\uxtuneup.dll
2011-03-30 18:36:11 ----HD---- C:\Windows\system32\GroupPolicy
2011-03-30 18:17:56 ----D---- C:\Windows\system32\cs-CZ
2011-03-30 18:16:28 ----RSD---- C:\Windows\Fonts
2011-03-30 18:16:28 ----D---- C:\Windows\SYSWOW64\oobe
2011-03-30 18:16:28 ----D---- C:\Windows\SYSWOW64\migwiz
2011-03-30 18:16:28 ----D---- C:\Windows\SYSWOW64\Dism
2011-03-30 18:16:28 ----D---- C:\Windows\system32\migwiz
2011-03-30 18:16:28 ----D---- C:\Windows\system32\manifeststore
2011-03-30 18:16:28 ----D---- C:\Windows\ehome
2011-03-30 18:16:27 ----D---- C:\Program Files\Windows Media Player
2011-03-30 18:16:27 ----D---- C:\Program Files\DVD Maker
2011-03-30 18:16:27 ----D---- C:\Program Files (x86)\Windows Portable Devices
2011-03-30 18:16:27 ----D---- C:\Program Files (x86)\Windows Media Player
2011-03-30 18:16:24 ----D---- C:\Windows\TAPI
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\wbem
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\sppui
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\Setup
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\migration
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\manifeststore
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\es-ES
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\da-DK
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\cs
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\AdvancedInstallers
2011-03-30 18:16:24 ----D---- C:\Windows\system32\sppui
2011-03-30 18:16:24 ----D---- C:\Windows\system32\Setup
2011-03-30 18:16:24 ----D---- C:\Windows\system32\migration
2011-03-30 18:16:23 ----SHD---- C:\Windows\BitLockerDiscoveryVolumeContents
2011-03-30 18:16:23 ----D---- C:\Windows\system32\es-ES
2011-03-30 18:16:23 ----D---- C:\Windows\system32\en-US
2011-03-30 18:16:23 ----D---- C:\Windows\system32\drivers\UMDF
2011-03-30 18:16:23 ----D---- C:\Windows\system32\drivers\cs-CZ
2011-03-30 18:16:23 ----D---- C:\Windows\system32\Dism
2011-03-30 18:16:23 ----D---- C:\Windows\system32\da-DK
2011-03-30 18:16:23 ----D---- C:\Windows\system32\cs
2011-03-30 18:16:23 ----D---- C:\Windows\system32\AdvancedInstallers
2011-03-30 18:16:23 ----D---- C:\Windows\servicing
2011-03-30 18:16:23 ----D---- C:\Windows\PolicyDefinitions
2011-03-30 18:16:23 ----D---- C:\Program Files\Windows Sidebar
2011-03-30 18:16:23 ----D---- C:\Program Files\Windows Photo Viewer
2011-03-30 18:16:23 ----D---- C:\Program Files\Windows Mail
2011-03-30 18:16:23 ----D---- C:\Program Files\Windows Journal
2011-03-30 18:16:23 ----D---- C:\Program Files\Windows Defender
2011-03-30 18:16:23 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-03-30 18:16:23 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-03-30 18:16:23 ----D---- C:\Program Files (x86)\Windows Mail
2011-03-30 18:16:13 ----D---- C:\Windows\SYSWOW64\XPSViewer
2011-03-30 18:16:13 ----D---- C:\Windows\SYSWOW64\Speech
2011-03-30 18:16:12 ----D---- C:\Windows\SYSWOW64\MUI
2011-03-30 18:16:11 ----D---- C:\Windows\system32\spp
2011-03-30 18:16:11 ----D---- C:\Windows\system32\Speech
2011-03-30 18:16:11 ----D---- C:\Windows\system32\MUI
2011-03-30 18:16:10 ----D---- C:\Windows\system32\CodeIntegrity
2011-03-30 18:16:09 ----D---- C:\Windows\security
2011-03-30 18:16:01 ----D---- C:\Program Files (x86)\Windows Live
2011-03-30 18:16:01 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-03-30 18:15:55 ----D---- C:\Program Files\Windows Portable Devices
2011-03-30 18:08:46 ----SD---- C:\ProgramData\Microsoft
2011-03-30 18:08:33 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-03-30 15:10:05 ----D---- C:\Boot
2011-03-29 18:51:36 ----D---- C:\Windows\debug
2011-03-28 21:13:58 ----D---- C:\Program Files (x86)\Zrychleni Pocitace
2011-03-28 21:12:18 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-03-28 18:37:50 ----D---- C:\Program Files\COMODO
2011-03-28 17:48:32 ----D---- C:\Program Files (x86)\VstPlugins
2011-03-27 20:21:40 ----SD---- C:\Users\Petr\AppData\Roaming\Microsoft
2011-03-27 14:49:46 ----D---- C:\ProgramData\Microsoft Help

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2010-01-27 115312]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-04-02 526392]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [2010-01-29 115600]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-10-24 188928]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2007-02-18 296816]
R1 Vsdatant;Zone Alarm Firewall Driver; C:\Windows\system32\DRIVERS\vsdatant.sys [2010-05-15 458840]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-12-18 314016]
R2 ISWKL;ZoneAlarm Toolbar ISWKL; \??\C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys [2011-02-15 33528]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-12-18 43680]
R2 sp_rsdrv2;Spyware Terminator Driver Filter; C:\Windows\system32\DRIVERS\stflt.sys [2010-07-07 50696]
R3 Abyssus;Razer Abyssus; C:\Windows\system32\drivers\Abyssus.sys [2009-10-30 10880]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-02-03 33856]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-04-30 2359200]
R3 LVPr2M64;Logitech LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys [2010-05-07 30304]
R3 LVRS64;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs64.sys [2010-11-10 341856]
R3 LVUVC64;Logitech Webcam C210(UVC); C:\Windows\system32\DRIVERS\lvuvc64.sys [2010-11-10 4162784]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 72064]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\PROGRAM FILES (X86)\TUNEUP UTILITIES 2011\TuneUpUtilitiesDriver64.sys [2011-02-10 11856]
R3 vhidmini;Razer Gaming Device; C:\Windows\system32\DRIVERS\vHidDev.sys [2009-12-21 7552]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 79760]
S2 hwpsgt;hwpsgt; C:\Windows\system32\DRIVERS\hwpsgt.sys []
S2 lemsgt;lemsgt; C:\Windows\system32\DRIVERS\lemsgt.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 cpudrv64;cpudrv64; \??\C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [2009-12-18 17864]
S3 cpuz132;cpuz132; \??\C:\Users\Petr\AppData\Local\Temp\cpuz132\cpuz132_x64.sys []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2011-04-14 20544]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files (x86)\Garena\safedrv.sys []
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2010-12-27 30528]
S3 LVPr2Mon;LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys [2010-05-07 30304]
S3 MarkFun_NT;MarkFun_NT; \??\C:\Program Files (x86)\GIGABYTE\ET5Pro\markfun.a64 []
S3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 40832]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 ScreamBAudioSvc;ScreamBee Audio; C:\Windows\system32\drivers\ScreamingBAudio64.sys [2009-11-26 38992]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys []
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 TFsExDisk;TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys []
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2010-08-05 144720]
S3 VBoxNetFlt;VBoxNetFlt Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys []
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
R2 602XML Updater;602Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
R2 AdvancedSystemCareService;Advanced SystemCare Service; C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe [2011-04-14 352144]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-03-28 2111368]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-09-06 247096]
R2 IswSvc;ZoneAlarm Toolbar IswSvc; C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe [2011-02-15 822264]
R2 LVPrcS64;Process Monitor; C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe [2010-05-07 197976]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 12784]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-04-07 1012328]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-04-08 2218600]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-04-19 75136]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe [2011-04-21 948775]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-04-07 378472]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\PROGRAM FILES (X86)\TUNEUP UTILITIES 2011\TUNEUPUTILITIESSERVICE64.EXE [2011-03-30 2026304]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 vsmon;TrueVector Internet Monitor; C:\Windows\SysWOW64\ZoneLabs\vsmon.exe [2011-03-18 2435592]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-07-08 136176]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-07-08 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-04-18 1255736]
S4 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

-----------------EOF-----------------

Re: vytížení cpu na 100%

Napsal: 21 dub 2011 19:04
od chodnik74
Děkuji filip544 za doplnění a spolupráci :) Čili asi to vážně vypadá,že máme svchost i tam kde být nemá..upozorním někoho z Rádců,aby se na to podíval :)

Re: vytížení cpu na 100%

Napsal: 21 dub 2011 19:23
od Roli
Zdravím, tohle fixni v HJT :

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://search13.net/search.php?clid=486&q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2645238
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll


HJT najdeš zde :

C:\Program Files\trend micro\Petr.exe

Fix znamená že spustíš HJT Obrázek jako admin

v okně které se ti otevře klikneš na Do a system scan only

v dalším okně najdeš řádky které jsem ti vypsal,

vedle nich je čtvereček do kterého uděláš zatržítko,

pak klikneš na Fix checked které je vlevo dole,

program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.


Přes Start >> Všechny programy >> Příslušenství >> Spustit >> napiš - services.msc >> Enter. Najdi službu :

Google Update Service

Služba Google Update

ICQ Service


klikni na ni pravým myšítkem, zvol vlastnosti, na další kartě nejprve službu zastav tlačítkem Zastavit a u položky Typ spouštění zvol Zakázáno.


Odinstaluj ICQ6Toolbar


Stáhni a ulož na plochu ComboFix,

spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.

Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,

pak ještě jednou klik na ANO a už to jede.

Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.

Při skenovaní může být PC i restartováno nelekat se.

Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,

protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.

Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt

(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.


V případě nejasností je ZDE obrázkový návod.

Re: vytížení cpu na 100%

Napsal: 21 dub 2011 20:51
od Moody
Zde je log z CB2.txt
http://textsave.de/?p=59572

(text překročil množství znaků zde na foru)

jinak služba google update nešla zakázat , ani po restartu..

Re: vytížení cpu na 100%

Napsal: 21 dub 2011 20:57
od Moody

Re: vytížení cpu na 100%

Napsal: 21 dub 2011 21:18
od Roli
Mě to nejde stáhnout můžeš to nahodit třeba SEM, dík.