Stránka 1 z 1

Problém s PC - vypíná se, chodí spamové emaily

Napsal: 13 črc 2011 12:15
od blaster_blaster
Dobrý den,

prosím o kontrolu logu - chodí mi spamové emaily z mé vlastní schránky, problém u poskytovatele prý není.
Děkuji za pomoc.


Logfile of random's system information tool 1.09 (written by random/random)
Run by Pavel at 2011-07-13 13:10:08
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 22 GB (9%) free of 238 GB
Total RAM: 4061 MB (60% free)

HijackThis download failed

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k apphost
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
C:\Windows\system32\CISVC.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe"
"C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"
C:\Windows\System32\svchost.exe -k ipripsvc
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe"
C:\Windows\system32\mqsvc.exe
"C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE"
C:\Windows\System32\tcpsvcs.exe
C:\Windows\System32\snmp.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe"
C:\Windows\system32\TODDSrv.exe
"C:\Program Files\TOSHIBA\TECO\TecoService.exe"
C:\Windows\system32\svchost.exe -k iissvcs
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe"
WLIDSvcM.exe 2624
C:\Windows\system32\wbem\wmiprvse.exe
"c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe"
"C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe"
"C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\TOSHIBA\TECO\Teco.exe" /r
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE" /logon
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" -tray
"C:\Program Files (x86)\W3i\InstallIQUpdater\InstallIQUpdater.exe" /silent /autorun
"C:\Users\Pavel\AppData\Local\Google\Update\1.3.21.57\GoogleCrashHandler.exe" /crashhandler
"C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe"
"C:\Program Files (x86)\Common Files\Panasonic\HD Writer AutoStart\HDWriterAutoStart.exe"
"C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe"
"C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE" /tsr
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
"C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
"C:\Program Files (x86)\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
"C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe"
"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer.exe" /watchfiles startup
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosA2dp.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosBtHid.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosHdpProc.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosBtHsp.exe"
"C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe"
{1900C593-FE9A-4F40-A4E6-46F4504AAC32}
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe"
{80BB2291-7389-4D8D-AF5D-10858F6CBE5F}
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\tosBtProc.exe"
"C:\Program Files\iPod\bin\iPodService.exe"
taskeng.exe {62934528-4557-4129-98FB-8E6A0528E159}
"C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
C:\Windows\system32\wbem\wmiprvse.exe
{68840A8C-DA16-4872-9C74-16A47C869E01}
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "D:\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe"
C:\Windows\system32\sppsvc.exe
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe"
"C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe"
"C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-e7013db2-9473-46e5-88fe-75039cda97f9 -SystemEventPortName:HostProcess-af64f1f5-702f-4fb2-8303-ccedd2949045 -IoCancelEventPortName:HostProcess-51f7e4ac-313d-4b78-a3ea-d5379a967e69 -NonStateChangingEventPortName:HostProcess-2da80fff-5c4b-4de5-980b-0993d094a0eb -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:dee2fd35-3a53-4234-8455-dbe0c35a1280
"C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
wmiadap.exe /R /T
"F:\RSITx64.exe"
"C:\Windows\system32\rundll32.exe" "C:\Windows\system32\WININET.dll",DispatchAPICall 1

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3960143003-3693527811-2526497408-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3960143003-3693527811-2526497408-1000UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\2mnr12le.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.centrum.cz/#utm_source=icq&u ... um=centrum"
prefs.js - "extensions.enabledItems" - "{AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906, bkmrksync@nokia.com:1.0.0.736, {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.51, {d9284e50-81fc-11da-a72b-0800200c9a66}:7.6.5, {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110323, wisestamp@wisestamp.com:2.2.1, {dc572301-7619-498c-a57d-39143191b318}:0.3.8.6, {75623d5d-4683-402a-b610-ac4bab767c86}:3.3.2, {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.9.4, {3112ca9c-de6d-4884-a869-9855de68056c}:7.1.20101113Wb1, toolbar@ask.com:3.11.3.15590, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://websearch.ask.com/redirect?clien ... YYYYYCZ&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon Easy-PhotoPrint EX
"Path"=C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{AB2CE124-6272-4b12-94A9-7303C7397BD1}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
NPOFF12.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
fcmdSrch.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\2mnr12le.default\extensions\
ffxtlbr@Facemoods.com
maps@ovi.com
staged
toolbar@ask.com
{3112ca9c-de6d-4884-a869-9855de68056c}
{75623d5d-4683-402a-b610-ac4bab767c86}
{800b5000-a755-47e1-992b-48a1c1357f07}
{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
{dc572301-7619-498c-a57d-39143191b318}

C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\2mnr12le.default\searchplugins\
facebook.xml
icqplugin.xml
surf-canyon.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]
Download Accelerator Plus Integration - C:\Program Files (x86)\DAP\DAPIELoader64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08 202144]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486b-A045-B233BD0DA8FC}]
CescrtHlpr Object - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.10\bh\facemoods.dll [2011-05-23 265944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-11-10 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2011-05-17 1490312]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2009-09-21 41368]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Lištička - C:\Program Files (x86)\Seznam.cz\listicka.dll [2011-03-15 2201600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08 1619352]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2011-05-17 1490312]
{1EA00BE1-6E54-4E2A-8099-680300BF23E1} - Nástroje Lištičky - C:\Program Files (x86)\Seznam.cz\toolbar\toolbar.dll [2011-03-10 183808]
{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - facemoods Toolbar - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.10\facemoodsTlbr.dll [2011-05-23 220888]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll [2010-11-21 1054520]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2009-08-03 709976]
"Toshiba TEMPRO"=C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [2009-08-06 1050000]
"TosNC"=C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [2009-08-06 596328]
"TosReelTimeMonitor"=C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [2009-08-06 35160]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-07-28 7982112]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-07-20 1815848]
"SmartFaceVWatcher"=C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [2009-07-29 238080]
"Teco"=C:\Program Files\TOSHIBA\TECO\Teco.exe [2009-09-03 1481568]
"TosWaitSrv"=C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [2009-08-04 711000]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2009-03-23 2184520]
"CanonSolutionMenu"=C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [2009-03-17 767312]
"pdfFactory Pro Dispatcher v3"=C:\Windows\system32\spool\DRIVERS\x64\3\fppdis3a.exe [2009-10-19 747008]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 1436224]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Pavel\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-17 136176]
"NokiaOviSuite2"=C:\Program Files (x86)\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe [2011-05-20 724536]
"InstallIQUpdater"=C:\Program Files (x86)\W3i\InstallIQUpdater\InstallIQUpdater.exe [2011-05-10 1205760]
""= []
"PC Suite Tray"=C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe [2010-12-21 1483264]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SVPWUTIL"=C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe [2009-08-12 352256]
"HWSetup"=C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [2009-06-02 423936]
"KeNotify"=C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [2009-01-13 34088]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-07-29 98304]
"ITSecMng"=C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START []
"TWebCamera"=C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe autorun []
"ToshibaServiceStation"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [2009-08-17 1294136]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"nmctxth"=C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe [2009-07-07 647216]
"nmapp"=C:\Program Files (x86)\Pure Networks\Network Magic\nmapp.exe [2009-07-08 472112]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
"IJNetworkScanUtility"=C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [2009-05-19 136544]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"AppleSyncNotifier"=C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [2011-04-20 58656]
""= []
"ApnUpdater"=C:\Program Files (x86)\Ask.com\Updater\Updater.exe [2011-05-17 395144]
"NokiaMServer"=C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-06-07 421160]
"facemoods"=C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.10\facemoodssrv.exe [2011-05-23 329432]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
HD Writer.lnk - C:\Program Files (x86)\Common Files\Panasonic\HD Writer AutoStart\HDWriterAutoStart.exe

C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
fliptoast.lnk - C:\Program Files (x86)\fliptoast\fliptoast.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 3 months======

2011-07-13 13:10:08 ----D---- C:\rsit
2011-07-13 13:10:08 ----D---- C:\Program Files\trend micro
2011-07-12 01:23:35 ----D---- C:\Program Files (x86)\ICQ7.5
2011-07-11 23:48:46 ----D---- C:\ProgramData\ICQ
2011-07-11 23:48:46 ----D---- C:\Program Files (x86)\ICQ6Toolbar
2011-07-11 23:48:27 ----D---- C:\Users\Pavel\AppData\Roaming\ICQ
2011-07-08 05:55:47 ----D---- C:\Users\Pavel\AppData\Roaming\FreeYoutubeToMP3TURBOConverter
2011-07-08 05:24:26 ----D---- C:\Program Files (x86)\FreeYouTubeToMP3TURBOConverter
2011-06-29 15:27:34 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-06-29 15:27:33 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2011-06-29 15:27:33 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2011-06-29 15:27:33 ----A---- C:\Windows\SYSWOW64\devobj.dll
2011-06-29 15:27:33 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2011-06-29 15:27:30 ----A---- C:\Windows\system32\tquery.dll
2011-06-29 15:27:29 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-06-29 15:27:29 ----A---- C:\Windows\system32\mssrch.dll
2011-06-29 15:27:28 ----A---- C:\Windows\SYSWOW64\tquery.dll
2011-06-29 15:27:28 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2011-06-29 15:27:28 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-06-29 15:27:27 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2011-06-29 15:27:27 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2011-06-29 15:27:26 ----A---- C:\Windows\SYSWOW64\mssph.dll
2011-06-29 15:27:25 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-06-29 15:27:25 ----A---- C:\Windows\system32\mssvp.dll
2011-06-29 15:27:25 ----A---- C:\Windows\system32\mssphtb.dll
2011-06-29 15:27:25 ----A---- C:\Windows\system32\mssph.dll
2011-06-29 15:27:24 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2011-06-29 15:27:24 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2011-06-29 15:27:24 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2011-06-29 15:27:24 ----A---- C:\Windows\system32\msscntrs.dll
2011-06-29 15:27:23 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2011-06-28 07:47:57 ----D---- C:\Program Files (x86)\facemoods.com
2011-06-28 07:42:12 ----D---- C:\Program Files (x86)\Free Offers from Freeze.com
2011-06-27 05:31:46 ----D---- C:\Windows\Minidump
2011-06-27 01:56:44 ----D---- C:\Users\Pavel\AppData\Roaming\Telefónica Móviles
2011-06-20 10:45:53 ----A---- C:\Windows\system32\mshtmled.dll
2011-06-20 10:45:52 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-06-20 10:45:49 ----A---- C:\Windows\system32\iertutil.dll
2011-06-20 10:45:48 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-06-20 10:45:48 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-06-20 10:45:48 ----A---- C:\Windows\system32\jscript9.dll
2011-06-20 10:45:48 ----A---- C:\Windows\system32\ieui.dll
2011-06-20 10:45:47 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-06-20 10:45:47 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-06-20 10:45:46 ----A---- C:\Windows\system32\jscript.dll
2011-06-20 10:45:45 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-06-20 10:45:45 ----A---- C:\Windows\system32\urlmon.dll
2011-06-20 10:45:44 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-06-20 10:45:42 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-06-20 10:45:42 ----A---- C:\Windows\system32\mshtml.dll
2011-06-20 10:45:41 ----A---- C:\Windows\system32\ieframe.dll
2011-06-19 19:57:03 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-19 19:57:03 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-19 19:57:00 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-19 19:56:59 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-19 19:56:59 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-19 19:56:57 ----A---- C:\Windows\system32\win32k.sys
2011-06-19 19:56:55 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-19 19:56:54 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-19 19:56:54 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-19 19:56:49 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-06-19 19:56:49 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-19 19:56:47 ----A---- C:\Windows\system32\inetcomm.dll
2011-06-19 19:56:46 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-06-15 01:59:21 ----D---- C:\Program Files (x86)\File Type Assistant
2011-06-15 01:58:22 ----D---- C:\Program Files (x86)\Zrychleni Pocitace
2011-06-15 01:58:11 ----SHD---- C:\Windows\SYSWOW64\AI_RecycleBin
2011-06-15 01:58:09 ----D---- C:\ProgramData\W3i
2011-06-15 01:58:09 ----D---- C:\Program Files (x86)\W3i
2011-06-15 01:52:34 ----D---- C:\ProgramData\OviInstallerCache
2011-06-13 17:46:23 ----D---- C:\Program Files\iPod
2011-06-13 17:46:22 ----D---- C:\Program Files (x86)\iTunes
2011-06-13 17:40:44 ----D---- C:\Program Files (x86)\Apple Software Update
2011-06-11 20:46:22 ----D---- C:\Users\Pavel\AppData\Roaming\go
2011-06-11 20:46:06 ----D---- C:\ProgramData\Easybits GO
2011-06-11 20:43:59 ----D---- C:\ProgramData\Skype Extras
2011-05-30 15:20:18 ----D---- C:\ProgramData\NokiaAccount
2011-05-30 04:16:29 ----D---- C:\Program Files (x86)\Fx MPEG Writer
2011-05-30 02:13:09 ----D---- C:\Program Files\CCleaner
2011-05-29 23:01:27 ----A---- C:\Windows\system32\drivers\pccsmcfdx64.sys
2011-05-29 23:01:10 ----D---- C:\Program Files (x86)\PC Connectivity Solution
2011-05-25 13:37:51 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2011-05-24 02:25:44 ----D---- C:\Program Files (x86)\Seznam.cz
2011-05-23 00:09:46 ----A---- C:\Windows\nsreg.dat
2011-05-22 23:18:54 ----D---- C:\Windows\SYSWOW64\BestPractices
2011-05-22 23:18:52 ----D---- C:\Windows\system32\msmq
2011-05-22 23:18:52 ----D---- C:\Windows\system32\BestPractices
2011-05-22 23:18:50 ----D---- C:\inetpub
2011-05-22 23:08:03 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-05-22 23:08:03 ----A---- C:\Windows\system32\d3d10_1.dll
2011-05-19 14:21:39 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2011-05-19 14:21:39 ----A---- C:\Windows\system32\poqexec.exe
2011-05-11 15:26:15 ----D---- C:\Program Files (x86)\RapidShareManager
2011-05-11 11:43:47 ----A---- C:\Windows\avisplitter.ini
2011-05-11 11:43:42 ----A---- C:\Windows\SYSWOW64\yv12vfw.dll
2011-05-11 11:43:41 ----A---- C:\Windows\SYSWOW64\xvidvfw.dll
2011-05-11 11:43:41 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2011-05-11 11:43:40 ----A---- C:\Windows\SYSWOW64\ff_vfw.dll
2011-05-11 11:13:05 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-05-11 11:13:03 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-05-11 11:13:03 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-05-11 11:13:01 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2011-05-11 11:13:01 ----A---- C:\Windows\system32\drivers\usbport.sys
2011-05-11 11:13:01 ----A---- C:\Windows\system32\drivers\usbhub.sys
2011-05-11 11:13:01 ----A---- C:\Windows\system32\drivers\usbehci.sys
2011-05-11 11:13:01 ----A---- C:\Windows\system32\drivers\usbd.sys
2011-05-11 11:13:01 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2011-05-10 08:06:08 ----A---- C:\Windows\system32\usbaaplrc.dll
2011-05-10 08:06:08 ----A---- C:\Windows\system32\drivers\usbaapl64.sys
2011-05-01 20:16:47 ----D---- C:\HDW30_TMP
2011-05-01 19:14:16 ----D---- C:\ProgramData\Panasonic
2011-05-01 19:09:02 ----N---- C:\Windows\system32\drivers\PxHlpa64.sys
2011-05-01 19:09:02 ----N---- C:\Windows\system32\drivers\cdralw2k.sys
2011-05-01 19:09:02 ----N---- C:\Windows\system32\drivers\cdr4_xp.sys
2011-05-01 19:07:06 ----D---- C:\Program Files (x86)\Panasonic
2011-05-01 19:07:00 ----D---- C:\Program Files\Microsoft Synchronization Services
2011-05-01 19:07:00 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2011-05-01 19:06:55 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services
2011-04-30 23:50:04 ----A---- C:\Windows\explorer.exe
2011-04-30 23:50:03 ----A---- C:\Windows\SYSWOW64\explorer.exe
2011-04-30 23:50:02 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-04-30 23:50:02 ----A---- C:\Windows\system32\XpsPrint.dll
2011-04-30 23:49:38 ----A---- C:\Windows\SYSWOW64\esent.dll
2011-04-30 23:49:38 ----A---- C:\Windows\system32\fsutil.exe
2011-04-30 23:49:38 ----A---- C:\Windows\system32\esent.dll
2011-04-30 23:49:37 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2011-04-30 23:49:37 ----A---- C:\Windows\system32\drivers\storport.sys
2011-04-30 23:49:37 ----A---- C:\Windows\system32\drivers\nvstor.sys
2011-04-30 23:49:37 ----A---- C:\Windows\system32\drivers\nvraid.sys
2011-04-30 23:49:37 ----A---- C:\Windows\system32\drivers\ntfs.sys
2011-04-30 23:49:37 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2011-04-30 23:49:37 ----A---- C:\Windows\system32\drivers\amdxata.sys
2011-04-30 23:49:37 ----A---- C:\Windows\system32\drivers\amdsata.sys
2011-04-30 23:49:36 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2011-04-30 23:49:27 ----A---- C:\Windows\system32\prevhost.exe
2011-04-30 23:49:26 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2011-04-19 10:52:07 ----D---- C:\Program Files\Bonjour
2011-04-19 10:52:07 ----D---- C:\Program Files (x86)\Bonjour
2011-04-15 20:06:36 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-04-15 20:06:34 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-04-14 00:40:16 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2011-04-14 00:40:16 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2011-04-14 00:40:14 ----A---- C:\Windows\system32\mfc42u.dll
2011-04-14 00:40:14 ----A---- C:\Windows\system32\mfc42.dll
2011-04-14 00:39:56 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-04-14 00:39:56 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-04-14 00:39:55 ----A---- C:\Windows\system32\atmlib.dll
2011-04-14 00:39:55 ----A---- C:\Windows\system32\atmfd.dll
2011-04-14 00:39:50 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2011-04-14 00:39:50 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2011-04-14 00:39:49 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-04-14 00:39:49 ----A---- C:\Windows\system32\dnscacheugc.exe
2011-04-14 00:39:49 ----A---- C:\Windows\system32\dnsapi.dll
2011-04-14 00:39:22 ----A---- C:\Windows\system32\winresume.exe
2011-04-14 00:39:22 ----A---- C:\Windows\system32\winload.exe
2011-04-14 00:39:21 ----A---- C:\Windows\system32\kdusb.dll
2011-04-14 00:39:21 ----A---- C:\Windows\system32\kdcom.dll
2011-04-14 00:39:21 ----A---- C:\Windows\system32\kd1394.dll
2011-04-14 00:38:55 ----A---- C:\Windows\system32\FXSCOVER.exe
2011-04-14 00:38:49 ----A---- C:\Windows\system32\drivers\bowser.sys

======List of files/folders modified in the last 3 months======

2011-07-13 13:10:09 ----D---- C:\Windows\Prefetch
2011-07-13 13:10:08 ----RD---- C:\Program Files
2011-07-13 13:09:59 ----D---- C:\Windows\Temp
2011-07-13 13:08:52 ----D---- C:\Windows\inf
2011-07-13 13:06:51 ----D---- C:\Windows\tracing
2011-07-12 14:18:53 ----D---- C:\Windows\system32\config
2011-07-12 13:16:01 ----D---- C:\ProgramData\CanonIJPLM
2011-07-12 12:44:36 ----SHD---- C:\Windows\Installer
2011-07-12 12:44:35 ----D---- C:\Program Files (x86)\Microsoft Office
2011-07-12 12:44:20 ----SHD---- C:\System Volume Information
2011-07-12 01:23:35 ----RD---- C:\Program Files (x86)
2011-07-11 23:48:46 ----HD---- C:\ProgramData
2011-07-11 23:48:41 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-07-11 22:38:25 ----D---- C:\Windows\system32\drivers
2011-07-11 21:54:11 ----D---- C:\Windows\system32\catroot
2011-07-11 21:53:48 ----D---- C:\Users\Pavel\AppData\Roaming\Skype
2011-07-11 08:33:17 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-07-08 06:32:35 ----D---- C:\Windows\Microsoft.NET
2011-07-08 06:32:34 ----RSD---- C:\Windows\assembly
2011-07-08 05:26:26 ----D---- C:\Windows\system32\DriverStore
2011-07-08 04:01:39 ----D---- C:\Users\Pavel\AppData\Roaming\Apple Computer
2011-07-07 18:06:46 ----A---- C:\Windows\red_dialer.ini
2011-07-07 17:36:49 ----D---- C:\Windows\System32
2011-07-07 17:36:49 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-07 17:30:57 ----D---- C:\Windows\Tasks
2011-07-07 17:30:57 ----D---- C:\Windows\system32\wfp
2011-07-07 17:30:57 ----D---- C:\Windows\system32\Tasks
2011-07-07 17:30:57 ----D---- C:\Windows\system32\catroot2
2011-07-07 17:30:57 ----D---- C:\Windows
2011-07-07 17:30:56 ----D---- C:\Windows\system32\CodeIntegrity
2011-07-07 17:30:49 ----D---- C:\Windows\AppCompat
2011-07-07 17:30:34 ----D---- C:\Windows\system32\wbem
2011-07-07 17:30:33 ----D---- C:\Windows\registration
2011-07-06 09:15:28 ----D---- C:\Windows\winsxs
2011-06-29 16:01:05 ----D---- C:\Windows\SysWOW64
2011-06-29 16:01:04 ----RSD---- C:\Windows\Fonts
2011-06-27 07:56:36 ----D---- C:\Windows\system32\NDF
2011-06-27 06:15:53 ----D---- C:\Windows\ModemLogs
2011-06-24 20:51:54 ----D---- C:\Program Files (x86)\K-Lite Codec Pack
2011-06-22 12:27:02 ----RD---- C:\Program Files (x86)\Skype
2011-06-22 12:26:53 ----D---- C:\Program Files (x86)\Common Files
2011-06-22 12:26:33 ----D---- C:\ProgramData\Skype
2011-06-21 23:16:34 ----D---- C:\Users\Pavel\AppData\Roaming\skypePM
2011-06-20 11:11:34 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-06-20 11:10:18 ----D---- C:\Program Files\Internet Explorer
2011-06-20 11:10:18 ----D---- C:\Program Files (x86)\Internet Explorer
2011-06-20 10:50:44 ----D---- C:\Windows\debug
2011-06-20 10:50:43 ----A---- C:\Windows\system32\MRT.exe
2011-06-20 10:50:16 ----D---- C:\ProgramData\Microsoft Help
2011-06-20 10:47:16 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-06-15 01:14:59 ----D---- C:\Users\Pavel\AppData\Roaming\PC Suite
2011-06-13 17:47:16 ----D---- C:\Program Files\iTunes
2011-06-13 16:01:28 ----D---- C:\ProgramData\CanonIJ
2011-06-13 16:00:51 ----SD---- C:\Users\Pavel\AppData\Roaming\Microsoft
2011-06-13 16:00:30 ----D---- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-06-13 15:57:15 ----D---- C:\Windows\system32\LogFiles
2011-06-01 15:05:13 ----D---- C:\Program Files (x86)\Ask.com
2011-05-30 05:03:55 ----D---- C:\Users\Pavel\AppData\Roaming\Media Player Classic
2011-05-30 04:48:27 ----D---- C:\Program Files (x86)\Adobe
2011-05-30 02:17:16 ----D---- C:\Windows\Logs
2011-05-30 00:06:24 ----D---- C:\Windows\system32\drivers\UMDF
2011-05-29 23:01:27 ----DC---- C:\Windows\system32\DRVSTORE
2011-05-29 23:00:03 ----D---- C:\Program Files (x86)\Nokia
2011-05-29 22:20:25 ----RD---- C:\Users
2011-05-24 09:50:34 ----D---- C:\Windows\rescache
2011-05-24 02:26:00 ----HD---- C:\Windows\msdownld.tmp
2011-05-22 23:18:54 ----D---- C:\Windows\SYSWOW64\migration
2011-05-22 23:18:54 ----D---- C:\Windows\SYSWOW64\inetsrv
2011-05-22 23:18:53 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-05-22 23:18:52 ----D---- C:\Windows\system32\migration
2011-05-22 23:18:52 ----D---- C:\Windows\system32\inetsrv
2011-05-22 23:18:52 ----D---- C:\Windows\system32\drivers\etc
2011-05-22 23:18:52 ----D---- C:\Windows\PolicyDefinitions
2011-05-22 23:18:51 ----D---- C:\Windows\system32\cs-CZ
2011-05-01 19:06:54 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2011-05-01 03:42:08 ----D---- C:\Windows\AppPatch
2011-04-19 10:56:47 ----D---- C:\Program Files (x86)\Safari
2011-04-14 01:49:59 ----D---- C:\Windows\system32\Boot

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-04 408600]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 tos_sps64;TOSHIBA tos_sps64 Service; C:\Windows\system32\DRIVERS\tos_sps64.sys [2009-07-24 482384]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-10-24 188928]
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2009-07-28 81768]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 pnarp;Pure Networks Device Discovery Driver; C:\Windows\system32\DRIVERS\pnarp.sys [2009-07-07 33328]
R2 purendis;Pure Networks Wireless Driver; C:\Windows\system32\DRIVERS\purendis.sys [2009-07-07 35376]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\Windows\system32\DRIVERS\TVALZFL.sys [2009-06-19 14472]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-30 6037504]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-07-28 1966624]
R3 LPCFilter;LPC Lower Filter Driver; C:\Windows\system32\DRIVERS\LPCFilter.sys [2009-07-30 44912]
R3 MQAC;@mqutil.dll,-6101; C:\Windows\system32\drivers\mqac.sys [2009-07-14 189440]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 72064]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2009-07-14 11264]
R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2009-05-20 202016]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-05-22 215040]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\RTL8187B.sys [2010-03-31 450048]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-07-20 274480]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2009-07-30 27784]
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2009-06-17 54664]
R3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2009-07-07 211432]
R3 tosrfec;Bluetooth ACPI; C:\Windows\system32\DRIVERS\tosrfec.sys [2009-07-13 19824]
R3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2009-06-19 94336]
R3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2009-08-05 58744]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 adusbser;AnyDATA USB Device for Legacy Serial Communication; C:\Windows\system32\DRIVERS\adusbser.sys [2006-12-20 140160]
S3 athr;Atheros – ovladač pro zařízení pro rozšiřitelnou bezdrátovou síť LAN; C:\Windows\system32\DRIVERS\athrx.sys [2009-06-20 1394688]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys []
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys []
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys []
S3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 40832]
S3 Netaapl;Apple Mobile Device Ethernet Service; C:\Windows\system32\DRIVERS\netaapl64.sys [2010-04-19 22528]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2010-12-02 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2010-12-02 27136]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2010-12-02 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2009-07-30 222208]
S3 RtsUIR;Realtek IR Driver; C:\Windows\system32\DRIVERS\Rts516xIR.sys []
S3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2009-06-19 50664]
S3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2009-07-24 26472]
S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys [2009-08-05 63856]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2010-12-02 9216]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2011-05-10 51712]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\Windows\system32\DRIVERS\RtsUCcid.sys []
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2010-12-02 9216]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-07-30 203264]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-02-18 37664]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2011-04-06 349472]
R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2009-08-10 248688]
R2 CISVC;@%systemroot%\system32\CISVC.EXE,-1; C:\Windows\system32\CISVC.EXE [2009-07-14 19456]
R2 ConfigFree Gadget Service;ConfigFree Gadget Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe [2009-07-14 42368]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2009-02-10 116104]
R2 iprip;@%Systemroot%\system32\iprip.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 12784]
R2 MSMQ;@mqutil.dll,-6102; C:\Windows\system32\mqsvc.exe [2009-07-14 9216]
R2 nmservice;Pure Networks Platform Service; C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [2009-07-07 647216]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-02-25 249648]
R2 simptcp;@%SystemRoot%\system32\simptcp.dll,-200; C:\Windows\System32\tcpsvcs.exe [2009-07-14 10240]
R2 SNMP;@%SystemRoot%\system32\snmp.exe,-3; C:\Windows\System32\snmp.exe [2010-11-20 49664]
R2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO); C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2009-08-06 116104]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2009-07-28 140632]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [2009-09-03 251760]
R2 W3SVC;@%windir%\system32\inetsrv\iisres.dll,-30003; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-06-07 934176]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
R3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2011-03-21 632832]
R3 TMachInfo;TMachInfo; C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-08-17 51512]
R3 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2009-07-30 192368]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-03 137560]
R3 TPCHSrv;TPCH Service; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2009-08-04 826224]
R3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 Installer Service;Installer Service; C:\ProgramData\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{6339663B-F26F-4FE3-B813-0E1DEC4ED976}\Installer\InstallerService.exe [2011-05-29 119296]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-01-14 1255736]
S4 TlntSvr;@%SystemRoot%\system32\tlntsvr.exe,-119; C:\Windows\System32\tlntsvr.exe [2009-07-14 81920]

-----------------EOF-----------------

Re: Problém s PC - vypíná se, chodí spamové emaily

Napsal: 13 črc 2011 14:16
od vyosek
Zdravim a pekny den preji :)

:arrow: Zkontrolujte vetraky ci nejsou ucpany prachem, pripadne opatrne vycistete - napr pumpickou

:arrow: Stahnete OTL (viz muj podpis) a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
  • Zaskrtnete okenko Pro vsechny uzivatele
  • Zaskrtnete okenko Kontrola na havet "LOP"
  • Zaskrtnete okenko Kontrola na havet "Purity"
  • Stari souboru zmente z 30 dnu na 7 dnu
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    netsvcs
    drivers32
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    c:\windows\*.* /U
    %SYSTEMDRIVE%\*.exe
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    /md5start
    adp3132.sys
    AGP440.sys
    ahcix86.sys
    ahcix86s.sys
    atapi.sys
    autochk.exe
    cdrom.sys
    cngaudit.dll
    cryptsvc.dll
    eNetHook.dll
    eventlog.dll
    explorer.exe
    hal.dll
    Changer.sys
    iaStor.sys
    iastorv.sys
    IdeChnDr.sys
    isapnp.sys
    JakNDis.sys
    KR10N.sys
    logevent.dll
    lsass.exe
    mv61xx.sys
    ndis.sys
    netlogon.dll
    ntelogon.dll
    nvata.sys
    nvatabus.sys
    nvgts.sys
    nvraid.sys
    nvrd32.sys
    nvstor.sys
    nvstor32.sys
    scecli.dll
    sceclt.dll
    smss.exe
    svchost.exe
    symmpi.sys
    tcpip.sys
    userinit.exe
    vaxscsi.sys
    viamraid.sys
    viasraid.sys
    ViPrt.sys
    winlogon.exe
    ws2_32.dll
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\drivers\*.sys /3
    %systemroot%\system32\*.* /3
    CREATERESTOREPOINT
  • Kliknete na tlacitko Prohledat
  • Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte