Stránka 1 z 1

FB vir

Napsal: 24 črc 2011 16:56
od B1zKiT
ahojte, bohuzel sem si taky stahl z FB tenhle hnusnej vir. prikladam LOG

Logfile of random's system information tool 1.09 (written by random/random)
Run by comp at 2011-07-24 17:51:39
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 9 GB (46%) free of 20 GB
Total RAM: 1151 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:51:42, on 24.7.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe
C:\WINDOWS\update.tray-7-0\svchost.exe
C:\WINDOWS\update.tray-5-0\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\l1rezerv.exe
C:\WINDOWS\systemup.exe
C:\WINDOWS\update.5.0\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Documents and Settings\comp\Local Settings\Data aplikací\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
C:\WINDOWS\update.2\svchost.exe
C:\WINDOWS\update.5.0\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\sysdriver32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\update.1\svchost.exe
C:\WINDOWS\update.2\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Documents and Settings\comp\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\comp\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\comp\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\comp\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\comp\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\WINDOWS\TEMP\385673202_ati.exe
C:\Documents and Settings\comp\Dokumenty\Downloads\RSIT (1).exe
C:\Program Files\trend micro\comp.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylon.com/?babsrc=SP_ss ... ffID=19404
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\bh\BabylonToolbar.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarTlbr.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Hard Disk Sentinel] "C:\Program Files\Hard Disk Sentinel\HDSentinel.exe" /AUTORUN
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE -startup
O4 - HKLM\..\Run: [BabylonToolbar] "C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe" /md I
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [wxpdrv] C:\WINDOWS\services32.exe
O4 - HKLM\..\Run: [tray_ico0] C:\WINDOWS\update.tray-7-0\svchost.exe
O4 - HKLM\..\Run: [tray_ico1] C:\WINDOWS\update.tray-5-0\svchost.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [1364781.exe] "C:\DOCUME~1\comp\LOCALS~1\Temp\1364781.exe"
O4 - HKLM\..\Run: [sysdriver32.exe] "C:\WINDOWS\sysdriver32.exe" rezerv
O4 - HKLM\..\Run: [sysdriver32_.exe] "C:\WINDOWS\sysdriver32_.exe" rezerv
O4 - HKLM\..\Run: [7495578.exe] "C:\DOCUME~1\comp\LOCALS~1\Temp\7495578.exe"
O4 - HKLM\..\Run: [2779253.exe] "C:\WINDOWS\TEMP\2779253.exe"
O4 - HKLM\..\Run: [3363267.exe] "C:\WINDOWS\TEMP\3363267.exe"
O4 - HKLM\..\Run: [2930257.exe] "C:\WINDOWS\TEMP\2930257.exe"
O4 - HKLM\..\Run: [55634712-loader2.exe] "C:\WINDOWS\TEMP\55634712-loader2.exe"
O4 - HKLM\..\Run: [l1rezerv.exe] "C:\WINDOWS\l1rezerv.exe"
O4 - HKLM\..\Run: [systemup] "C:\WINDOWS\systemup.exe" stand
O4 - HKLM\..\Run: [6637100.exe] "C:\DOCUME~1\comp\LOCALS~1\Temp\6637100.exe"
O4 - HKLM\..\Run: [3862158.exe] "C:\DOCUME~1\comp\LOCALS~1\Temp\3862158.exe"
O4 - HKLM\..\Run: [7549623.exe] "C:\WINDOWS\TEMP\7549623.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\comp\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe (User 'Default user')
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Chytrý výběr - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs:
O20 - Winlogon Notify: RailNotification - Invalid registry found
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: srvbtcclient - Unknown owner - C:\WINDOWS\update.5.0\svchost.exe
O23 - Service: srviecheck - Unknown owner - C:\WINDOWS\update.2\svchost.exe
O23 - Service: srvsysdriver32 - Unknown owner - C:\WINDOWS\sysdriver32.exe
O23 - Service: wxpdrivers - Unknown owner - C:\WINDOWS\update.1\svchost.exe

--
End of file - 10167 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-527237240-706699826-842925246-1004Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-527237240-706699826-842925246-1004UA.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{F918A1B7-FFDF-4442-832D-EC4969D5B797}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2007-11-06 322880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}]
CescrtHlpr Object - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\bh\BabylonToolbar.dll [2010-11-07 225720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
uTorrentBar Toolbar - C:\Program Files\uTorrentBar\tbuTor.dll [2010-12-09 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-06-17 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-06-17 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06 542016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - uTorrentBar Toolbar - C:\Program Files\uTorrentBar\tbuTor.dll [2010-12-09 3911776]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]
{98889811-442D-49dd-99D7-DC866BE87DBC} - Babylon Toolbar - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarTlbr.dll [2010-11-07 184760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TaskTray"= []
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-02-10 61440]
"Hard Disk Sentinel"=C:\Program Files\Hard Disk Sentinel\HDSentinel.exe [2011-05-09 4007936]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui []
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-10-14 49152]
"hpqSRMon"=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2007-08-22 80896]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2011-06-15 307200]
"BabylonToolbar"=C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe [2010-11-07 286720]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2008-03-27 36352]
"wxpdrv"=C:\WINDOWS\services32.exe [2011-07-23 1185792]
"tray_ico"= []
"tray_ico0"=C:\WINDOWS\update.tray-7-0\svchost.exe [2011-07-23 1185792]
"tray_ico1"=C:\WINDOWS\update.tray-5-0\svchost.exe [2011-07-23 1185792]
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"1364781.exe"=C:\DOCUME~1\comp\LOCALS~1\Temp\1364781.exe [2011-07-24 247296]
"sysdriver32.exe"=C:\WINDOWS\sysdriver32.exe [2011-07-24 247296]
"sysdriver32_.exe"=C:\WINDOWS\sysdriver32_.exe [2011-07-24 247296]
"7495578.exe"=C:\DOCUME~1\comp\LOCALS~1\Temp\7495578.exe [2011-07-24 247296]
"2779253.exe"=C:\WINDOWS\TEMP\2779253.exe [2011-07-24 247296]
"3363267.exe"=C:\WINDOWS\TEMP\3363267.exe [2011-07-24 247296]
"2930257.exe"=C:\WINDOWS\TEMP\2930257.exe [2011-07-24 495616]
"55634712-loader2.exe"=C:\WINDOWS\TEMP\55634712-loader2.exe [2011-07-24 247296]
"l1rezerv.exe"=C:\WINDOWS\l1rezerv.exe [2011-07-24 232960]
"systemup"=C:\WINDOWS\systemup.exe [2011-07-24 114176]
"6637100.exe"=C:\DOCUME~1\comp\LOCALS~1\Temp\6637100.exe [2011-07-24 247296]
"3862158.exe"=C:\DOCUME~1\comp\LOCALS~1\Temp\3862158.exe [2011-07-24 247296]
"7549623.exe"=C:\WINDOWS\TEMP\7549623.exe [2011-07-24 247296]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Google Update"=C:\Documents and Settings\comp\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-06-07 136176]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe

C:\Documents and Settings\comp\Nabídka Start\Programy\Po spuštění
Y'z Shadow.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-02-11 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RailNotification]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2010-01-14 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2010-01-14 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2010-01-14 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0
"EnableSecureUIAPaths"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Xfire\Xfire.exe"="C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire"
"D:\Program Files\Call of Duty\CoDMP.exe"="D:\Program Files\Call of Duty\CoDMP.exe:*:Enabled:CoDMP"
"D:\Program Files\Valve\hl.exe"="D:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"D:\Program Files\EA GAMES\Need For Speed Underground\Speed.exe"="D:\Program Files\EA GAMES\Need For Speed Underground\Speed.exe:*:Enabled:Speed"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\TeamViewer\Version6\TeamViewer.exe"="C:\Program Files\TeamViewer\Version6\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe"="C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service"
"C:\codserver\server.exe"="C:\codserver\server.exe:*:Enabled:server"
"D:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe"="D:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"D:\Nový priečinok\Nová složka\CoDMP.exe"="D:\Nový priečinok\Nová složka\CoDMP.exe:*:Enabled:CoDMP"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"D:\Stronghold Crusader\Stronghold Crusader\Stronghold Crusader.exe"="D:\Stronghold Crusader\Stronghold Crusader\Stronghold Crusader.exe:*:Enabled:Stronghold Crusader"
"C:\Program Files\Call of Duty\CoDMP.exe"="C:\Program Files\Call of Duty\CoDMP.exe:*:Enabled:CoDMP"
"C:\Program Files\Call of Duty\CoDUOMP.exe"="C:\Program Files\Call of Duty\CoDUOMP.exe:*:Enabled:CoDUOMP"
"D:\Call of Duty\CoDUOMP.exe"="D:\Call of Duty\CoDUOMP.exe:*:Enabled:CoDUOMP"
"D:\Call of Duty\CoDMP.exe"="D:\Call of Duty\CoDMP.exe:*:Enabled:CoDMP"
"C:\WINDOWS\services32.exe"="C:\WINDOWS\services32.exe:*:Enabled:C:\WINDOWS\services32.exe"
"C:\WINDOWS\update.1\svchost.exe"="C:\WINDOWS\update.1\svchost.exe:*:Enabled:C:\WINDOWS\update.1\svchost.exe"
"C:\WINDOWS\update.tray-5-0\svchost.exe"="C:\WINDOWS\update.tray-5-0\svchost.exe:*:Enabled:C:\WINDOWS\update.tray-5-0\svchost.exe"
"C:\WINDOWS\update.tray-7-0\svchost.exe"="C:\WINDOWS\update.tray-7-0\svchost.exe:*:Enabled:C:\WINDOWS\update.tray-7-0\svchost.exe"
"C:\WINDOWS\update.tray-7-0-lnk\svchost.exe"="C:\WINDOWS\update.tray-7-0-lnk\svchost.exe:*:Enabled:C:\WINDOWS\update.tray-7-0-lnk\svchost.exe"
"C:\WINDOWS\update.tray-5-0-lnk\svchost.exe"="C:\WINDOWS\update.tray-5-0-lnk\svchost.exe:*:Enabled:C:\WINDOWS\update.tray-5-0-lnk\svchost.exe"
"C:\WINDOWS\update.2\svchost.exe"="C:\WINDOWS\update.2\svchost.exe:*:Enabled:C:\WINDOWS\update.2\svchost.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"VIDC.XFR1"=xfcodec.dll
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll

======List of files/folders created in the last 1 month======

2011-07-24 17:50:30 ----D---- C:\rsit
2011-07-24 17:50:30 ----D---- C:\Program Files\trend micro
2011-07-24 17:44:57 ----ASH---- C:\hiberfil.sys
2011-07-24 17:37:06 ----A---- C:\WINDOWS\system32\avastSS.scr
2011-07-24 17:36:42 ----D---- C:\WINDOWS\ufa
2011-07-24 17:36:42 ----D---- C:\WINDOWS\rpcminer
2011-07-24 17:36:42 ----D---- C:\WINDOWS\phoenix
2011-07-24 17:35:38 ----A---- C:\WINDOWS\ddh_iplist.txt
2011-07-24 17:35:12 ----A---- C:\WINDOWS\systemup.exe
2011-07-24 17:34:37 ----A---- C:\WINDOWS\btc_client_iplist.txt
2011-07-24 17:34:06 ----HD---- C:\WINDOWS\update.5.0
2011-07-24 17:33:37 ----A---- C:\WINDOWS\l1rezerv.exe
2011-07-24 17:32:35 ----A---- C:\WINDOWS\iecheck_iplist.txt
2011-07-24 17:32:18 ----A---- C:\WINDOWS\unrar.exe
2011-07-24 17:31:47 ----HD---- C:\WINDOWS\update.2
2011-07-24 17:29:45 ----A---- C:\WINDOWS\iplist.txt
2011-07-24 17:22:31 ----A---- C:\WINDOWS\sysdriver32_.exe
2011-07-24 17:22:16 ----A---- C:\WINDOWS\sysdriver32.exe
2011-07-24 17:21:56 ----A---- C:\WINDOWS\front_ip_list.txt
2011-07-24 17:19:22 ----D---- C:\WINDOWS\system32\appmgmt
2011-07-24 11:21:52 ----D---- C:\Program Files\Common Files\Adobe
2011-07-24 11:21:52 ----D---- C:\Program Files\Adobe
2011-07-24 11:08:00 ----D---- C:\WINDOWS\av_ico
2011-07-24 11:05:55 ----HD---- C:\WINDOWS\update.1
2011-07-24 11:05:38 ----HD---- C:\WINDOWS\update.tray-5-0-lnk
2011-07-24 11:05:38 ----HD---- C:\WINDOWS\update.tray-5-0
2011-07-24 11:05:37 ----HD---- C:\WINDOWS\update.tray-7-0-lnk
2011-07-24 11:05:37 ----HD---- C:\WINDOWS\update.tray-7-0
2011-07-23 16:36:35 ----A---- C:\WINDOWS\services32.exe
2011-07-23 16:36:29 ----A---- C:\WINDOWS\winlog-ids.txt
2011-07-23 16:36:29 ----A---- C:\WINDOWS\winlog-dirs.txt
2011-07-20 17:21:42 ----A---- C:\WINDOWS\system32\sstunst2.exe
2011-07-20 17:21:38 ----A---- C:\WINDOWS\system32\BMW.scr
2011-07-17 19:22:16 ----A---- C:\WINDOWS\CoDUO.INI
2011-07-17 19:14:17 ----A---- C:\WINDOWS\CoD.INI
2011-07-11 16:09:09 ----N---- C:\WINDOWS\system32\drivers\PxHelp20.sys
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\vxblock.dll
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\pxsfs.dll
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\pxdrv.dll
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\pxafs.dll
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\drivers\cdralw2k.sys
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2011-07-11 16:09:07 ----N---- C:\WINDOWS\system32\pxwave.dll
2011-07-11 16:09:07 ----N---- C:\WINDOWS\system32\pxmas.dll
2011-07-11 16:09:07 ----N---- C:\WINDOWS\system32\px.dll
2011-07-11 16:08:56 ----D---- C:\Program Files\Winamp
2011-07-11 16:08:56 ----D---- C:\Documents and Settings\comp\Data aplikací\Winamp
2011-07-09 12:43:51 ----D---- C:\Program Files\GIMP-2.0
2011-06-30 14:51:58 ----D---- C:\Program Files\SystemRequirementsLab
2011-06-30 14:51:20 ----D---- C:\WINDOWS\Sun
2011-06-28 17:30:41 ----D---- C:\Program Files\Blip Blop
2011-06-28 17:17:21 ----A---- C:\WINDOWS\system32\d3d9caps.dat
2011-06-28 17:05:12 ----D---- C:\DRIVERS
2011-06-28 17:04:06 ----D---- C:\Program Files\VIA
2011-06-28 17:02:46 ----A---- C:\WINDOWS\system32\RtNicProp32.dll
2011-06-28 17:02:46 ----A---- C:\WINDOWS\system32\drivers\Rtnicxp.sys
2011-06-28 17:02:45 ----D---- C:\Program Files\Realtek
2011-06-28 15:22:01 ----RA---- C:\WINDOWS\system32\vp6vfw.dll
2011-06-26 19:56:44 ----D---- C:\Program Files\Common Files\PCSuite
2011-06-26 19:56:43 ----D---- C:\Program Files\Nokia
2011-06-26 19:56:43 ----D---- C:\Program Files\Common Files\Nokia
2011-06-26 17:56:52 ----D---- C:\Documents and Settings\comp\Data aplikací\BabylonToolbar
2011-06-26 17:47:22 ----D---- C:\Program Files\BabylonToolbar
2011-06-26 17:46:25 ----D---- C:\Program Files\Total Video Converter

======List of files/folders modified in the last 1 month======

2011-07-24 17:50:30 ----RD---- C:\Program Files
2011-07-24 17:49:30 ----D---- C:\WINDOWS\Temp
2011-07-24 17:46:26 ----D---- C:\WINDOWS
2011-07-24 17:43:28 ----A---- C:\boot.ini
2011-07-24 17:38:34 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-07-24 17:37:33 ----HD---- C:\Config.Msi
2011-07-24 17:37:32 ----D---- C:\WINDOWS\WinSxS
2011-07-24 17:37:24 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-07-24 17:37:23 ----SHD---- C:\WINDOWS\Installer
2011-07-24 17:37:06 ----D---- C:\WINDOWS\system32
2011-07-24 17:35:27 ----SHD---- C:\System Volume Information
2011-07-24 17:35:27 ----D---- C:\WINDOWS\system32\Restore
2011-07-24 17:33:48 ----D---- C:\WINDOWS\Prefetch
2011-07-24 17:32:11 ----D---- C:\WINDOWS\system32\drivers\etc
2011-07-24 17:19:14 ----D---- C:\WINDOWS\system32\drivers
2011-07-24 11:22:02 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-07-24 11:21:52 ----D---- C:\Program Files\Common Files
2011-07-23 21:27:06 ----D---- C:\WINDOWS\system32\CatRoot2
2011-07-23 14:31:24 ----D---- C:\Program Files\Xfire
2011-07-23 14:22:19 ----D---- C:\WINDOWS\Minidump
2011-07-21 16:33:34 ----D---- C:\Documents and Settings\comp\Data aplikací\Xfire
2011-07-18 16:03:35 ----SD---- C:\Documents and Settings\comp\Data aplikací\Microsoft
2011-07-18 16:03:35 ----D---- C:\Documents and Settings\comp\Data aplikací\Adobe
2011-07-17 19:33:28 ----HD---- C:\Program Files\InstallShield Installation Information
2011-07-14 23:51:42 ----D---- C:\Documents and Settings\comp\Data aplikací\uTorrent
2011-07-13 12:14:39 ----D---- C:\codserver
2011-07-09 20:29:16 ----HD---- C:\WINDOWS\inf
2011-07-01 15:06:19 ----D---- C:\Documents and Settings\comp\Data aplikací\TeamViewer
2011-07-01 12:13:01 ----D---- C:\Program Files\Internet Explorer
2011-06-28 17:08:51 ----D---- C:\WINDOWS\system32\ReinstallBackups
2011-06-27 16:54:58 ----D---- C:\Documents and Settings
2011-06-26 18:15:05 ----D---- C:\Program Files\Hard Disk Sentinel
2011-06-26 17:47:27 ----D---- C:\Program Files\Mozilla Firefox
2011-06-26 17:46:49 ----RSD---- C:\WINDOWS\Fonts
2011-06-26 09:35:02 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 viaagp;Filtr VIA sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-14 42240]
R0 viaagp1;VIA AGP Filter; C:\WINDOWS\system32\DRIVERS\viaagp1.sys [2003-07-02 27904]
R0 videX32;videX32; C:\WINDOWS\system32\DRIVERS\videX32.sys [2009-05-05 13976]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-06-11 218688]
R1 P3;Ovladač procesoru Intel PentiumIII; C:\WINDOWS\system32\DRIVERS\p3.sys [2010-01-14 46592]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2011-06-15 60156]
R2 rspndr;Odpovídající zařízení zjišťování topologie linkové vrstvy; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2010-01-14 62848]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-02-11 3565056]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2009-03-25 130432]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 VIAudio;Zvukový řadič VIA AC'97 (WDM); C:\WINDOWS\system32\drivers\ac97via.sys [2008-04-13 84480]
S1 DumpDrv;Crash Dump Driver; C:\WINDOWS\system32\drivers\DumpDrv.sys [2010-01-14 9472]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-11-01 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-11-01 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-11-01 21568]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-22 32384]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2010-01-14 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2010-01-14 82944]
S4 exFat;exFat; C:\WINDOWS\system32\drivers\exFat.sys [2010-01-14 133632]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-02-11 602112]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-06-17 153376]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2010-01-14 14848]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2010-01-14 14848]
R2 srvbtcclient;srvbtcclient; C:\WINDOWS\update.5.0\svchost.exe [2011-07-24 340992]
R2 srviecheck;srviecheck; C:\WINDOWS\update.2\svchost.exe [2011-07-24 495616]
R2 srvsysdriver32;srvsysdriver32; C:\WINDOWS\sysdriver32.exe [2011-07-24 247296]
R2 wxpdrivers;wxpdrivers; C:\WINDOWS\update.1\svchost.exe [2011-07-23 1185792]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2010-02-10 593920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2010-01-14 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: FB vir

Napsal: 24 črc 2011 17:26
od Rudy
Zdravím!
Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.

Re: FB vir

Napsal: 24 črc 2011 18:42
od B1zKiT
log z MBAM

Malwarebytes' Anti-Malware
www.malwarebytes.org

Verze databáze:

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

24.7.2011 19:41:27
mbam-log-2011-07-24 (19-41-23).txt

Typ: Úplná kontrola (C:\|D:\|)
Kontrolované objekty: 323461
Uplynulý čas: 41 minut, 34 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 20

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
c:\documents and settings\comp\local settings\data aplikací\Google\Chrome\user data\Default\Cache\f_000834 (Trojan.Dropper) -> No action taken.
c:\documents and settings\comp\Plocha\Blbosti\stronghold crusader (warchest v1.1) trainer.exe (PUP.HackTool.HotKeysHook) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\services32.exe.vir (Trojan.Dropper) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\systemup.exe.vir (Trojan.Agent) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\update.1\svchost.exe.vir (Trojan.Dropper) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\update.tray-5-0\svchost.exe.vir (Trojan.Dropper) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\update.tray-7-0\svchost.exe.vir (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{94486993-38d9-4411-beb4-38c71e3b6d19}\RP57\A0033566.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{94486993-38d9-4411-beb4-38c71e3b6d19}\RP57\A0033567.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{94486993-38d9-4411-beb4-38c71e3b6d19}\RP57\A0033568.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{94486993-38d9-4411-beb4-38c71e3b6d19}\RP57\A0033569.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{94486993-38d9-4411-beb4-38c71e3b6d19}\RP57\A0033696.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{94486993-38d9-4411-beb4-38c71e3b6d19}\RP57\A0033699.exe (Trojan.Agent) -> No action taken.
c:\system volume information\_restore{94486993-38d9-4411-beb4-38c71e3b6d19}\RP57\A0033700.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{94486993-38d9-4411-beb4-38c71e3b6d19}\RP57\A0033703.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{94486993-38d9-4411-beb4-38c71e3b6d19}\RP57\A0033704.exe (Trojan.Dropper) -> No action taken.
c:\WINDOWS\update.tray-5-0-lnk\svchost.exe (Trojan.Dropper) -> No action taken.
c:\WINDOWS\update.tray-7-0-lnk\svchost.exe (Trojan.Dropper) -> No action taken.
d:\system volume information\_restore{368ecc31-0819-45a3-85f9-21d643a8dd49}\RP207\A0135539.exe (RiskWare.Tool.CK) -> No action taken.
d:\nový priečinok\call of duty\dev-cod.exe (RiskWare.Tool.CK) -> No action taken.

Re: FB vir

Napsal: 24 črc 2011 19:28
od Rudy
Vše, co MBAM nalezl, smažte a pak dejte nový log RSIT.

Re: FB vir

Napsal: 24 črc 2011 19:31
od B1zKiT
Logfile of random's system information tool 1.09 (written by random/random)
Run by comp at 2011-07-24 20:30:47
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 9 GB (47%) free of 20 GB
Total RAM: 1151 MB (47% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:30:56, on 24.7.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\comp\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\comp\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\comp\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\comp\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\comp\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\comp\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\comp\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\comp\Dokumenty\Downloads\RSIT.exe
C:\Program Files\trend micro\comp.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\bh\BabylonToolbar.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarTlbr.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE -startup
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe (User 'Default user')
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Chytrý výběr - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 7595 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\User_Feed_Synchronization-{F918A1B7-FFDF-4442-832D-EC4969D5B797}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2007-11-06 322880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}]
CescrtHlpr Object - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\bh\BabylonToolbar.dll [2010-11-07 225720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
uTorrentBar Toolbar - C:\Program Files\uTorrentBar\tbuTor.dll [2010-12-09 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-06-17 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-06-17 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06 542016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - uTorrentBar Toolbar - C:\Program Files\uTorrentBar\tbuTor.dll [2010-12-09 3911776]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]
{98889811-442D-49dd-99D7-DC866BE87DBC} - Babylon Toolbar - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarTlbr.dll [2010-11-07 184760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-02-10 61440]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-10-14 49152]
"hpqSRMon"=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2007-08-22 80896]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2011-06-15 307200]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"MSConfig"=C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE [2008-04-14 171008]
"Malwarebytes' Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2011-07-06 1047656]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2011-07-06 449584]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BabylonToolbar]
C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe [2010-11-07 286720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hard Disk Sentinel]
C:\Program Files\Hard Disk Sentinel\HDSentinel.exe [2011-05-09 4007936]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2008-03-27 36352]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe

C:\Documents and Settings\comp\Nabídka Start\Programy\Po spuštění
Y'z Shadow.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-02-11 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2010-01-14 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2010-01-14 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2010-01-14 304128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableSecureUIAPaths"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Xfire\Xfire.exe"="C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire"
"D:\Program Files\Call of Duty\CoDMP.exe"="D:\Program Files\Call of Duty\CoDMP.exe:*:Enabled:CoDMP"
"D:\Program Files\Valve\hl.exe"="D:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"D:\Program Files\EA GAMES\Need For Speed Underground\Speed.exe"="D:\Program Files\EA GAMES\Need For Speed Underground\Speed.exe:*:Enabled:Speed"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\TeamViewer\Version6\TeamViewer.exe"="C:\Program Files\TeamViewer\Version6\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe"="C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service"
"C:\codserver\server.exe"="C:\codserver\server.exe:*:Enabled:server"
"D:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe"="D:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"D:\Nový priečinok\Nová složka\CoDMP.exe"="D:\Nový priečinok\Nová složka\CoDMP.exe:*:Enabled:CoDMP"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"D:\Stronghold Crusader\Stronghold Crusader\Stronghold Crusader.exe"="D:\Stronghold Crusader\Stronghold Crusader\Stronghold Crusader.exe:*:Enabled:Stronghold Crusader"
"D:\Call of Duty\CoDUOMP.exe"="D:\Call of Duty\CoDUOMP.exe:*:Enabled:CoDUOMP"
"D:\Call of Duty\CoDMP.exe"="D:\Call of Duty\CoDMP.exe:*:Enabled:CoDMP"
"C:\WINDOWS\update.tray-7-0-lnk\svchost.exe"="C:\WINDOWS\update.tray-7-0-lnk\svchost.exe:*:Enabled:C:\WINDOWS\update.tray-7-0-lnk\svchost.exe"
"C:\WINDOWS\update.tray-5-0-lnk\svchost.exe"="C:\WINDOWS\update.tray-5-0-lnk\svchost.exe:*:Enabled:C:\WINDOWS\update.tray-5-0-lnk\svchost.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"VIDC.XFR1"=xfcodec.dll
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll

======List of files/folders created in the last 1 month======

2011-07-24 20:30:24 ----A---- C:\WINDOWS\system32\drivers\ohalme.sys
2011-07-24 19:35:12 ----D---- C:\WINDOWS\pss
2011-07-24 18:56:35 ----D---- C:\Documents and Settings\comp\Data aplikací\Malwarebytes
2011-07-24 18:56:25 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-07-24 18:56:24 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-07-24 18:56:21 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-07-24 18:56:21 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-07-24 18:47:42 ----A---- C:\ComboFix.txt
2011-07-24 18:43:16 ----SH---- C:\WINDOWS\system32\mqad.dll
2011-07-24 18:41:44 ----D---- C:\found.000
2011-07-24 18:13:06 ----A---- C:\Boot.bak
2011-07-24 18:13:00 ----RASHD---- C:\cmdcons
2011-07-24 18:10:43 ----A---- C:\WINDOWS\zip.exe
2011-07-24 18:10:43 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-07-24 18:10:43 ----A---- C:\WINDOWS\SWSC.exe
2011-07-24 18:10:43 ----A---- C:\WINDOWS\SWREG.exe
2011-07-24 18:10:43 ----A---- C:\WINDOWS\sed.exe
2011-07-24 18:10:43 ----A---- C:\WINDOWS\PEV.exe
2011-07-24 18:10:43 ----A---- C:\WINDOWS\NIRCMD.exe
2011-07-24 18:10:43 ----A---- C:\WINDOWS\MBR.exe
2011-07-24 18:10:43 ----A---- C:\WINDOWS\grep.exe
2011-07-24 18:10:26 ----D---- C:\WINDOWS\ERDNT
2011-07-24 18:10:19 ----D---- C:\Qoobox
2011-07-24 18:03:40 ----D---- C:\Program Files\AMD APP
2011-07-24 18:03:34 ----D---- C:\Program Files\ATI
2011-07-24 17:50:30 ----D---- C:\rsit
2011-07-24 17:50:30 ----D---- C:\Program Files\trend micro
2011-07-24 17:44:57 ----ASH---- C:\hiberfil.sys
2011-07-24 17:37:06 ----A---- C:\WINDOWS\system32\avastSS.scr
2011-07-24 17:36:42 ----D---- C:\WINDOWS\ufa
2011-07-24 17:36:42 ----D---- C:\WINDOWS\rpcminer
2011-07-24 17:36:42 ----D---- C:\WINDOWS\phoenix
2011-07-24 17:32:18 ----A---- C:\WINDOWS\unrar.exe
2011-07-24 17:19:22 ----D---- C:\WINDOWS\system32\appmgmt
2011-07-24 11:21:52 ----D---- C:\Program Files\Common Files\Adobe
2011-07-24 11:21:52 ----D---- C:\Program Files\Adobe
2011-07-24 11:08:00 ----D---- C:\WINDOWS\av_ico
2011-07-24 11:05:38 ----HD---- C:\WINDOWS\update.tray-5-0-lnk
2011-07-24 11:05:38 ----HD---- C:\WINDOWS\update.tray-5-0
2011-07-24 11:05:37 ----HD---- C:\WINDOWS\update.tray-7-0-lnk
2011-07-24 11:05:37 ----HD---- C:\WINDOWS\update.tray-7-0
2011-07-20 17:21:42 ----A---- C:\WINDOWS\system32\sstunst2.exe
2011-07-20 17:21:38 ----A---- C:\WINDOWS\system32\BMW.scr
2011-07-17 19:22:16 ----A---- C:\WINDOWS\CoDUO.INI
2011-07-17 19:14:17 ----A---- C:\WINDOWS\CoD.INI
2011-07-11 16:09:09 ----N---- C:\WINDOWS\system32\drivers\PxHelp20.sys
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\vxblock.dll
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\pxsfs.dll
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\pxdrv.dll
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\pxafs.dll
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\drivers\cdralw2k.sys
2011-07-11 16:09:08 ----N---- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2011-07-11 16:09:07 ----N---- C:\WINDOWS\system32\pxwave.dll
2011-07-11 16:09:07 ----N---- C:\WINDOWS\system32\pxmas.dll
2011-07-11 16:09:07 ----N---- C:\WINDOWS\system32\px.dll
2011-07-11 16:08:56 ----D---- C:\Program Files\Winamp
2011-07-11 16:08:56 ----D---- C:\Documents and Settings\comp\Data aplikací\Winamp
2011-07-09 12:43:51 ----D---- C:\Program Files\GIMP-2.0
2011-06-30 14:51:58 ----D---- C:\Program Files\SystemRequirementsLab
2011-06-30 14:51:20 ----D---- C:\WINDOWS\Sun
2011-06-28 17:30:41 ----D---- C:\Program Files\Blip Blop
2011-06-28 17:17:21 ----A---- C:\WINDOWS\system32\d3d9caps.dat
2011-06-28 17:05:12 ----D---- C:\DRIVERS
2011-06-28 17:04:06 ----D---- C:\Program Files\VIA
2011-06-28 17:02:46 ----A---- C:\WINDOWS\system32\RtNicProp32.dll
2011-06-28 17:02:46 ----A---- C:\WINDOWS\system32\drivers\Rtnicxp.sys
2011-06-28 17:02:45 ----D---- C:\Program Files\Realtek
2011-06-28 15:22:01 ----RA---- C:\WINDOWS\system32\vp6vfw.dll
2011-06-26 19:56:44 ----D---- C:\Program Files\Common Files\PCSuite
2011-06-26 19:56:43 ----D---- C:\Program Files\Nokia
2011-06-26 19:56:43 ----D---- C:\Program Files\Common Files\Nokia
2011-06-26 17:56:52 ----D---- C:\Documents and Settings\comp\Data aplikací\BabylonToolbar
2011-06-26 17:47:22 ----D---- C:\Program Files\BabylonToolbar
2011-06-26 17:46:25 ----D---- C:\Program Files\Total Video Converter

======List of files/folders modified in the last 1 month======

2011-07-24 20:30:24 ----D---- C:\WINDOWS\AppPatch
2011-07-24 19:36:40 ----RASH---- C:\boot.ini
2011-07-24 19:36:40 ----A---- C:\WINDOWS\win.ini
2011-07-24 19:36:40 ----A---- C:\WINDOWS\system.ini
2011-07-24 19:35:12 ----D---- C:\WINDOWS
2011-07-24 18:56:25 ----D---- C:\WINDOWS\system32\drivers
2011-07-24 18:56:21 ----RD---- C:\Program Files
2011-07-24 18:49:10 ----D---- C:\WINDOWS\Temp
2011-07-24 18:46:42 ----SD---- C:\WINDOWS\Tasks
2011-07-24 18:45:43 ----D---- C:\WINDOWS\system32\CatRoot2
2011-07-24 18:43:23 ----D---- C:\WINDOWS\system32\drivers\etc
2011-07-24 18:36:48 ----D---- C:\WINDOWS\system32\config
2011-07-24 18:31:06 ----D---- C:\WINDOWS\system32
2011-07-24 18:31:02 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-07-24 18:26:24 ----D---- C:\Program Files\Common Files
2011-07-24 18:11:14 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-07-24 18:03:42 ----SHD---- C:\WINDOWS\Installer
2011-07-24 18:03:42 ----D---- C:\Config.Msi
2011-07-24 18:03:38 ----D---- C:\Program Files\ATI Technologies
2011-07-24 17:37:32 ----D---- C:\WINDOWS\WinSxS
2011-07-24 17:37:24 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-07-24 17:35:27 ----SHD---- C:\System Volume Information
2011-07-24 17:35:27 ----D---- C:\WINDOWS\system32\Restore
2011-07-24 17:33:48 ----D---- C:\WINDOWS\Prefetch
2011-07-24 11:22:02 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-07-23 14:31:24 ----D---- C:\Program Files\Xfire
2011-07-23 14:22:19 ----D---- C:\WINDOWS\Minidump
2011-07-21 16:33:34 ----D---- C:\Documents and Settings\comp\Data aplikací\Xfire
2011-07-18 16:03:35 ----SD---- C:\Documents and Settings\comp\Data aplikací\Microsoft
2011-07-18 16:03:35 ----D---- C:\Documents and Settings\comp\Data aplikací\Adobe
2011-07-17 19:33:28 ----HD---- C:\Program Files\InstallShield Installation Information
2011-07-14 23:51:42 ----D---- C:\Documents and Settings\comp\Data aplikací\uTorrent
2011-07-13 12:14:39 ----D---- C:\codserver
2011-07-09 20:29:16 ----HD---- C:\WINDOWS\inf
2011-07-01 15:06:19 ----D---- C:\Documents and Settings\comp\Data aplikací\TeamViewer
2011-07-01 12:13:01 ----D---- C:\Program Files\Internet Explorer
2011-06-28 17:08:51 ----D---- C:\WINDOWS\system32\ReinstallBackups
2011-06-27 16:54:58 ----D---- C:\Documents and Settings
2011-06-26 18:15:05 ----D---- C:\Program Files\Hard Disk Sentinel
2011-06-26 17:47:27 ----D---- C:\Program Files\Mozilla Firefox
2011-06-26 17:46:49 ----RSD---- C:\WINDOWS\Fonts
2011-06-26 09:35:02 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 viaagp;Filtr VIA sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-14 42240]
R0 viaagp1;VIA AGP Filter; C:\WINDOWS\system32\DRIVERS\viaagp1.sys [2003-07-02 27904]
R0 videX32;videX32; C:\WINDOWS\system32\DRIVERS\videX32.sys [2009-05-05 13976]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-06-11 218688]
R1 P3;Ovladač procesoru Intel PentiumIII; C:\WINDOWS\system32\DRIVERS\p3.sys [2010-01-14 46592]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2011-06-15 60156]
R2 rspndr;Odpovídající zařízení zjišťování topologie linkové vrstvy; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2010-01-14 62848]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-02-11 3565056]
R3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2009-03-25 130432]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 VIAudio;Zvukový řadič VIA AC'97 (WDM); C:\WINDOWS\system32\drivers\ac97via.sys [2008-04-13 84480]
S0 ywjtvrs;ywjtvrs; C:\WINDOWS\System32\drivers\ohalme.sys [2011-07-24 54016]
S1 DumpDrv;Crash Dump Driver; C:\WINDOWS\system32\drivers\DumpDrv.sys [2010-01-14 9472]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-11-01 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-11-01 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-11-01 21568]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
S3 mbr;mbr; \??\C:\DOCUME~1\comp\LOCALS~1\Temp\mbr.sys []
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-22 32384]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2010-01-14 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2010-01-14 82944]
S4 exFat;exFat; C:\WINDOWS\system32\drivers\exFat.sys [2010-01-14 133632]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-02-11 602112]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-06-17 153376]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2010-01-14 14848]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2010-01-14 14848]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2010-02-10 593920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2010-01-14 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: FB vir

Napsal: 24 črc 2011 19:48
od Rudy
Můžete mi vysvětlit, proč jste se nedržel rad a aplikoval ComboFix, o který jsem vás nežádal?

Re: FB vir

Napsal: 24 črc 2011 19:50
od B1zKiT
ja sem to nejprve neresil. nejprve to resil muj syn, ktery cetl prispevky tady na foru a musel to na 100% spustit prede mnou :oops:

Re: FB vir

Napsal: 24 črc 2011 19:51
od B1zKiT
ted se to uz neda vyresit?

Re: FB vir

Napsal: 24 črc 2011 19:55
od Rudy
B1zKiT píše:ted se to uz neda vyresit?
No, log již vypadá čistý a naštěstí se nic nestalo. Jen nedoporučujeme laikům spouštět CF bez konzultace s rádcem. Mohl by se poškodit systém. CF byl spuštěn dnes v 18:10. Jak se nyní PC tváří?

Re: FB vir

Napsal: 24 črc 2011 19:58
od B1zKiT
tvari se uplne normalne, akorat comodo firewall a placeny avast internet security je pryc :baby:

Re: FB vir

Napsal: 24 črc 2011 20:04
od Rudy
Pak je to OK. Uvedené programy reinstalujte.