Stránka 1 z 2

Prosím o kontrolu zahlceného NTB...

Napsal: 10 pro 2011 13:07
od Premda84
Ahoj,

projel jsem NTB programem CC Cleaner a MBAM - ale NTB je porad takovy "zdechly" - mozna to bude chtit reinstall Winů - přesto Vás poprosím o kontrolu - děkuji:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Veronika at 2011-12-09 13:07:51
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 19 GB (25%) free of 76 GB
Total RAM: 503 MB (27% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:08:48, on 9.12.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\vsnp2std.exe
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Eset\UpdateReminder.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Veronika\Dokumenty\Stažené soubory\RSIT.exe
C:\WINDOWS\system32\dumprep.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\trend micro\Veronika.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\System32\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UpdateReminder] C:\Program Files\Eset\UpdateReminder.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [Magnify] Magnify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [Magnify] Magnify.exe (User 'Default user')
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 9160 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Veronika\Data aplikací\Mozilla\Firefox\Profiles\87vv0fm2.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.google.cz/"
prefs.js - "extensions.enabledItems" - "toolbar@ask.com:3.6.6.99999, cs@dictionaries.addons.mozilla.org:1.0.1, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5, {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://websearch.ask.com/redirect?clien ... e=en_EU&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprjplug;version=1.0.3.46]
"Description"=RealJukebox Netscape Plugin
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46]
"Description"=6.0.12.46
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll

C:\Program Files\Mozilla Firefox\extensions\
{800b5000-a755-47e1-992b-48a1c1357f07}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{B13721C7-F507-4982-B2E5-502A71474FED}
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsIQTScriptablePlugin.xpt
nsJSRealPlayerPlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.dll
nppl3260.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprjplug.dll
nprpjplug.dll
QuickTimePlugin.class

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\Veronika\Data aplikací\Mozilla\Firefox\Profiles\87vv0fm2.default\extensions\
cs@dictionaries.addons.mozilla.org
toolbar@ask.com
{5359A5B3-9AFD-49ee-8C39-0A8F97A2A2D6}

C:\Documents and Settings\Veronika\Data aplikací\Mozilla\Firefox\Profiles\87vv0fm2.default\searchplugins\
askcom.xml
icqplugin-1.xml
icqplugin-10.xml
icqplugin-11.xml
icqplugin-12.xml
icqplugin-13.xml
icqplugin-14.xml
icqplugin-15.xml
icqplugin-16.xml
icqplugin-17.xml
icqplugin-18.xml
icqplugin-19.xml
icqplugin-2.xml
icqplugin-20.xml
icqplugin-21.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin-5.xml
icqplugin-6.xml
icqplugin-7.xml
icqplugin-8.xml
icqplugin-9.xml
icqplugin.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-15 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-08-04 1586472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll [2007-07-12 501136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-12-02 342192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll [2011-12-02 1003576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2009-06-01 962808]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-12-02 342192]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"=C:\Program Files\Eset\nod32kui.exe [2006-10-24 921600]
"igfxtray"=C:\WINDOWS\system32\igfxtray.exe [2005-08-24 94208]
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe [2005-08-24 77824]
"igfxpers"=C:\WINDOWS\system32\igfxpers.exe [2005-08-24 114688]
"Broadcom Wireless Manager UI"=C:\WINDOWS\system32\WLTRAY.exe [2005-12-14 1236992]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-01-19 185896]
"snp2std"=C:\WINDOWS\vsnp2std.exe [2006-09-15 675840]
"tsnpstd3"=C:\WINDOWS\tsnpstd3.exe [2005-12-20 94208]
"snpstd3"=C:\WINDOWS\vsnpstd3.exe [2005-09-05 339968]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2007-07-10 98304]
"UpdateReminder"=C:\Program Files\Eset\UpdateReminder.exe [2011-09-29 425984]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2010-11-15 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-12-19 39408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDElbyCDFL]
C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe [2002-11-02 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe [2002-12-02 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
C:\WINDOWS\FixCamera.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Veronika\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-04-24 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2007-07-10 98304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-12-19 39408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^DSLMON.lnk]
C:\PROGRA~1\SAGEM\SAGEMF~1\dslmon.exe [2003-07-08 962663]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2005-08-24 135168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableChangePassword"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoAddPrinter"=0
"NoDeletePrinter"=0
"NoCustomizeWebView"=0
"NoWinKeys"=0
"NoGoTo"=1
"NoInstrumentation"=0
"NoOptions"=1
"NoSMMyPictures"=1
"NoStartMenuMyMusic"=0
"NoSMMyDocs"=1
"NoFavoritesMenu"=1
"NoCommonGroups"=0
"NoStartMenuSubFolders"=0
"NoNtSecurity"=0
"NoFileUrl"=0
"NoBandCustomize"=1
"NoExpandedNewMenu"=0
"SpecifyDefaultButtons"=1
"Btn_Search"=2
"Btn_Folders"=2
"Btn_Favorites"=2
"Btn_Media"=2
"Btn_History"=2
"Btn_Fullscreen"=2
"Btn_Tools"=2
"Btn_MailNews"=2
"Btn_Size"=2
"Btn_Edit"=2
"Btn_Discussions"=2
"Btn_Cut"=2
"Btn_Copy"=2
"Btn_Paste"=2
"Btn_Encoding"=2
"Btn_PrintPreview"=2
"EnforceShellExtensionSecurity"=0
"NoLogOff"=0
"NoResolveSearch"=0
"ForceCopyAclwithFile"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\ESET\nod32.exe"="C:\Program Files\ESET\nod32.exe:*:Enabled:ENABLE"
"C:\Program Files\mozilla.org\Mozilla\mozilla.exe"="C:\Program Files\mozilla.org\Mozilla\mozilla.exe:*:Enabled:ENABLE"
"C:\WINDOWS\system32\igfxtray.exe"="C:\WINDOWS\system32\igfxtray.exe:*:Enabled:ENABLE"
"C:\WINDOWS\system32\hkcmd.exe"="C:\WINDOWS\system32\hkcmd.exe:*:Enabled:ENABLE"
"C:\WINDOWS\system32\igfxpers.exe"="C:\WINDOWS\system32\igfxpers.exe:*:Enabled:ENABLE"
"C:\WINDOWS\system32\WLTRAY.exe"="C:\WINDOWS\system32\WLTRAY.exe:*:Enabled:ENABLE"
"C:\Program Files\QuickTime\qttask.exe"="C:\Program Files\QuickTime\qttask.exe:*:Enabled:ENABLE"
"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe:*:Enabled:ENABLE"
"C:\Program Files\Winamp\winampa.exe"="C:\Program Files\Winamp\winampa.exe:*:Enabled:ENABLE"
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe:*:Enabled:ENABLE"
"C:\WINDOWS\SOUNDMAN.EXE"="C:\WINDOWS\SOUNDMAN.EXE:*:Enabled:ENABLE"
"C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe"="C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe:*:Enabled:ENABLE"
"C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe"="C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe:*:Enabled:ENABLE"
"C:\WINDOWS\system32\igfxsrvc.exe"="C:\WINDOWS\system32\igfxsrvc.exe:*:Enabled:ENABLE"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:ENABLE"
"C:\Program Files\Eset\nod32kui.exe"="C:\Program Files\Eset\nod32kui.exe:*:Enabled:ENABLE"
"C:\Documents and Settings\Veronika\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.dll"="C:\Documents and Settings\Veronika\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin"
"C:\Documents and Settings\Veronika\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe"="C:\Documents and Settings\Veronika\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Disabled:RealPlayer"
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe"="C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"VIDC.MPG4"=mpg4c32.dll
"VIDC.MP42"=mpg4c32.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.WMV3"=wmv9vcm.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv

======List of files/folders created in the last 1 month======

2011-12-09 12:55:51 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys

======List of files/folders modified in the last 1 month======

2011-12-09 13:08:48 ----D---- C:\WINDOWS\Prefetch
2011-12-09 13:08:41 ----D---- C:\Program Files\trend micro
2011-12-09 13:04:15 ----D---- C:\Program Files\Mozilla Firefox
2011-12-09 12:57:13 ----D---- C:\WINDOWS\temp
2011-12-09 12:55:51 ----D---- C:\WINDOWS\system32\drivers
2011-12-09 12:50:16 ----D---- C:\WINDOWS\Debug
2011-12-09 12:50:16 ----D---- C:\WINDOWS
2011-12-07 21:20:49 ----N---- C:\WINDOWS\SchedLgU.Txt
2011-12-07 17:08:19 ----D---- C:\Documents and Settings\Veronika\Data aplikací\Skype
2011-12-04 20:49:27 ----A---- C:\WINDOWS\NeroDigital.ini
2011-12-03 20:38:46 ----D---- C:\WINDOWS\security
2011-12-03 15:02:44 ----SHD---- C:\WINDOWS\Installer
2011-12-03 15:02:41 ----RD---- C:\Program Files\Skype
2011-12-03 15:02:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-12-03 15:02:25 ----D---- C:\Program Files\Common Files
2011-12-03 14:58:04 ----D---- C:\Documents and Settings\Veronika\Data aplikací\skypePM
2011-12-02 14:47:39 ----D---- C:\WINDOWS\system32\CatRoot2
2011-11-12 21:12:23 ----D---- C:\Program Files\Google

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ElbyVCD;ElbyVCD; C:\WINDOWS\system32\DRIVERS\ElbyVCD.sys [2002-11-28 22016]
R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2004-08-03 61056]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2010-12-18 21696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-17 39936]
R1 tidnet;TID NDIS Protocol Driver; C:\WINDOWS\system32\DRIVERS\tidnet.sys [2009-09-15 19200]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2002-02-19 12032]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.2.0.3; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2006-11-05 17801]
R2 AMON;AMON; \??\C:\WINDOWS\system32\drivers\amon.sys []
R2 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2002-11-29 16320]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2005-09-05 11354]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2008-09-24 4122368]
R3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2002-11-28 15360]
R3 EMSCR;EMSCR; C:\WINDOWS\system32\DRIVERS\EMS7SK.sys [2005-11-17 60928]
R3 ESDCR;ESDCR; C:\WINDOWS\system32\DRIVERS\ESD7SK.sys [2005-11-17 37888]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-08-24 1052732]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-09-13 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2004-08-03 67584]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 w29n51;Intel(R) PRO/Wireless 2915ABG Network Connection Driver for Windows XP; C:\WINDOWS\system32\DRIVERS\w29n51.sys [2005-09-12 3298432]
S2 ADILOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys [2003-07-17 46167]
S3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\system32\DRIVERS\adiusbaw.sys [2003-03-27 127145]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-17 60800]
S3 Bridge;Most MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2004-08-03 71552]
S3 BridgeMP;Miniport mostu MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2004-08-03 71552]
S3 catchme;catchme; \??\C:\DOCUME~1\Veronika\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys []
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\WINDOWS\system32\DRIVERS\ewdcsc.sys [2009-12-15 24448]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2009-12-15 102528]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\WINDOWS\system32\DRIVERS\ewusbdev.sys [2009-12-15 100736]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 SNP2STD;USB2.0 PC Camera (SNP2STD); C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2007-04-09 12039552]
S3 SNPSTD3;USB PC Camera (SNPSTD3); C:\WINDOWS\system32\DRIVERS\snpstd3.sys [2005-12-08 8718848]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2005-10-21 12800]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-09-02 717296]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 EvtEng;EvtEng; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2005-10-06 86016]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2009-06-01 222968]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2006-10-26 335872]
R2 NOD32krn;NOD32 Kernel Service; C:\Program Files\Eset\nod32krn.exe [2006-10-24 507904]
R2 RegSrvc;RegSrvc; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2005-10-06 139264]
R2 S24EventMonitor;Spectrum24 Event Monitor; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2005-10-06 372809]
R2 wltrysvc;Broadcom Wireless LAN Tray Service; C:\WINDOWS\System32\WLTRYSVC.EXE [2005-12-14 18944]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-10 135664]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-10 135664]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-19 182768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Re: Prosím o kontrolu zahlceného NTB...

Napsal: 10 pro 2011 13:20
od vyosek
Zdravim a pekny den preji :)

:arrow: Urcite radky v logu naznacuji, ze mate nelegalni NOD32, nemate na nej zakoupenou licenci, takze jak to je :???:

:arrow: Chybi tez Service Pack 3, ze by to bylo z duvodu, ze pro jeho instalaci je treba overeni pravosti (legality) systemu windows :???:

Re: Prosím o kontrolu zahlceného NTB...

Napsal: 10 pro 2011 13:23
od Premda84
Windows XP je legalni - SP3 tam neni z duvodu, ze to neni muj NTB - mam ho na "opravu" - od zname z rodiny - s NODEM netusim - vyskakuje jen, ze vyprsela platnost cili:

a) odstranim NOD
b) nainstaluju SP3

mam potom hodit novy log z RSIT?

díky

Re: Prosím o kontrolu zahlceného NTB...

Napsal: 10 pro 2011 13:26
od vyosek
Presne tak, jeste pridam dva kroky pred novym RSITem
  • Odinstalujte ICQ Toolbar - to mozna jako prvni krok ze vseho
  • Nainstalujte legalni zabezpeceni - Avast - NOD bez platne licence je neaktualni, nechrani

Re: Prosím o kontrolu zahlceného NTB...

Napsal: 10 pro 2011 13:28
od Premda84
Dobre dekuji...prosim o chvilku strpeni :) jinak provedu...

Re: Prosím o kontrolu zahlceného NTB...

Napsal: 10 pro 2011 13:29
od vyosek
Jasny, jedu ted na odpoledni, ale mel bych sem nakukovat...

Re: Prosím o kontrolu zahlceného NTB...

Napsal: 10 pro 2011 16:49
od Premda84
Omlouvam se, ale tento NTB je fakt srot!! Nekolikrat to pri instalaci SP3 spadlo a je to fakt brutalne pomale...budu rad za kazdou radu...dekuji :)

Logfile of random's system information tool 1.08 (written by random/random)
Run by Veronika at 2011-12-09 16:49:12
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 14 GB (19%) free of 76 GB
Total RAM: 503 MB (42% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:49:42, on 9.12.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\vsnp2std.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Documents and Settings\Veronika\Plocha\RSIT.exe
C:\Program Files\trend micro\Veronika.exe
C:\Program Files\AVAST Software\Avast\setup\avast.setup

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [Magnify] Magnify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [Magnify] Magnify.exe (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 7029 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-15 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-08-04 1586472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll [2007-07-12 501136]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"=C:\WINDOWS\system32\igfxtray.exe [2005-08-24 94208]
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe [2005-08-24 77824]
"igfxpers"=C:\WINDOWS\system32\igfxpers.exe [2005-08-24 114688]
"Broadcom Wireless Manager UI"=C:\WINDOWS\system32\WLTRAY.exe [2005-12-14 1236992]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-01-19 185896]
"snp2std"=C:\WINDOWS\vsnp2std.exe [2006-09-15 675840]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2007-07-10 98304]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2010-11-15 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-11-28 3744552]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDElbyCDFL]
C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe /L ElbyCDFL []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
C:\WINDOWS\FixCamera.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Veronika\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-04-24 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2007-07-10 98304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^DSLMON.lnk]
C:\PROGRA~1\SAGEM\SAGEMF~1\dslmon.exe [2003-07-08 962663]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2005-08-24 135168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableChangePassword"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoAddPrinter"=0
"NoDeletePrinter"=0
"NoCustomizeWebView"=0
"NoWinKeys"=0
"NoGoTo"=1
"NoInstrumentation"=0
"NoOptions"=1
"NoSMMyPictures"=1
"NoStartMenuMyMusic"=0
"NoSMMyDocs"=1
"NoFavoritesMenu"=1
"NoCommonGroups"=0
"NoStartMenuSubFolders"=0
"NoNtSecurity"=0
"NoFileUrl"=0
"NoBandCustomize"=1
"NoExpandedNewMenu"=0
"SpecifyDefaultButtons"=1
"Btn_Search"=2
"Btn_Folders"=2
"Btn_Favorites"=2
"Btn_Media"=2
"Btn_History"=2
"Btn_Fullscreen"=2
"Btn_Tools"=2
"Btn_MailNews"=2
"Btn_Size"=2
"Btn_Edit"=2
"Btn_Discussions"=2
"Btn_Cut"=2
"Btn_Copy"=2
"Btn_Paste"=2
"Btn_Encoding"=2
"Btn_PrintPreview"=2
"EnforceShellExtensionSecurity"=0
"NoLogOff"=0
"NoResolveSearch"=0
"ForceCopyAclwithFile"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\ESET\nod32.exe"="C:\Program Files\ESET\nod32.exe:*:Enabled:ENABLE"
"C:\Program Files\mozilla.org\Mozilla\mozilla.exe"="C:\Program Files\mozilla.org\Mozilla\mozilla.exe:*:Enabled:ENABLE"
"C:\WINDOWS\system32\igfxtray.exe"="C:\WINDOWS\system32\igfxtray.exe:*:Enabled:ENABLE"
"C:\WINDOWS\system32\hkcmd.exe"="C:\WINDOWS\system32\hkcmd.exe:*:Enabled:ENABLE"
"C:\WINDOWS\system32\igfxpers.exe"="C:\WINDOWS\system32\igfxpers.exe:*:Enabled:ENABLE"
"C:\WINDOWS\system32\WLTRAY.exe"="C:\WINDOWS\system32\WLTRAY.exe:*:Enabled:ENABLE"
"C:\Program Files\QuickTime\qttask.exe"="C:\Program Files\QuickTime\qttask.exe:*:Enabled:ENABLE"
"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe:*:Enabled:ENABLE"
"C:\Program Files\Winamp\winampa.exe"="C:\Program Files\Winamp\winampa.exe:*:Enabled:ENABLE"
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe:*:Enabled:ENABLE"
"C:\WINDOWS\SOUNDMAN.EXE"="C:\WINDOWS\SOUNDMAN.EXE:*:Enabled:ENABLE"
"C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe"="C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe:*:Enabled:ENABLE"
"C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe"="C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe:*:Enabled:ENABLE"
"C:\WINDOWS\system32\igfxsrvc.exe"="C:\WINDOWS\system32\igfxsrvc.exe:*:Enabled:ENABLE"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:ENABLE"
"C:\Program Files\Eset\nod32kui.exe"="C:\Program Files\Eset\nod32kui.exe:*:Enabled:ENABLE"
"C:\Documents and Settings\Veronika\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.dll"="C:\Documents and Settings\Veronika\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin"
"C:\Documents and Settings\Veronika\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe"="C:\Documents and Settings\Veronika\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Disabled:RealPlayer"
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe"="C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2011-12-09 16:41:37 ----D---- C:\WINDOWS\Prefetch
2011-12-09 16:35:00 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2011-12-09 16:33:13 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2011-12-09 16:31:31 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2011-12-09 16:29:52 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2011-12-09 16:28:14 ----HDC---- C:\WINDOWS\$NtUninstallKB969897$
2011-12-09 16:26:33 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2011-12-09 16:24:50 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2011-12-09 16:22:56 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2011-12-09 16:21:06 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2011-12-09 16:19:08 ----HDC---- C:\WINDOWS\$NtUninstallKB982381$
2011-12-09 16:17:12 ----HDC---- C:\WINDOWS\$NtUninstallKB963027$
2011-12-09 16:15:29 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2011-12-09 16:13:43 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2011-12-09 16:11:58 ----HDC---- C:\WINDOWS\$NtUninstallKB961371$
2011-12-09 16:10:16 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2011-12-09 16:08:32 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2011-12-09 16:06:23 ----HDC---- C:\WINDOWS\$NtUninstallKB960714$
2011-12-09 16:04:32 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2011-12-09 16:02:38 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2011-12-09 16:00:21 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2011-12-09 15:58:10 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2011-12-09 15:56:26 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2011-12-09 15:54:37 ----HDC---- C:\WINDOWS\$NtUninstallKB958215$
2011-12-09 15:52:51 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2011-12-09 15:51:04 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2011-12-09 15:49:18 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2011-12-09 15:47:28 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2011-12-09 15:45:46 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2011-12-09 15:43:41 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2011-12-09 15:41:50 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2011-12-09 15:40:01 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2011-12-09 15:38:04 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2011-12-09 15:32:44 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2011-12-09 15:30:07 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2011-12-09 15:28:36 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2011-12-09 15:26:58 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2011-12-09 15:25:20 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2011-12-09 15:23:45 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2011-12-09 15:22:17 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2011-12-09 15:20:00 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2011-12-09 15:18:20 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2011-12-09 15:16:37 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2011-12-09 15:14:59 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2011-12-09 15:13:14 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2011-12-09 15:11:30 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2011-12-09 15:09:34 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2011-12-09 15:07:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2011-12-09 15:07:12 ----D---- C:\WINDOWS\LastGood.Tmp
2011-12-09 15:02:17 ----N---- C:\WINDOWS\system32\msxml6r.dll
2011-12-09 15:02:16 ----N---- C:\WINDOWS\system32\msxml6.dll
2011-12-09 15:02:00 ----N---- C:\WINDOWS\system32\rwnh.dll
2011-12-09 15:02:00 ----N---- C:\WINDOWS\system32\drivers\irbus.sys
2011-12-09 15:02:00 ----N---- C:\WINDOWS\system32\comsdupd.exe
2011-12-09 15:01:59 ----N---- C:\WINDOWS\system32\smtpapi.dll
2011-12-09 15:01:54 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2011-12-09 15:01:54 ----N---- C:\WINDOWS\system32\ati2dvag.dll
2011-12-09 15:01:54 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2011-12-09 15:01:54 ----N---- C:\WINDOWS\system32\ati2cqag.dll
2011-12-09 15:01:54 ----N---- C:\WINDOWS\system32\aaclient.dll
2011-12-09 15:01:53 ----N---- C:\WINDOWS\system32\ativvaxx.dll
2011-12-09 15:01:53 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2011-12-09 15:01:53 ----N---- C:\WINDOWS\system32\ati3duag.dll
2011-12-09 15:01:52 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2011-12-09 15:01:52 ----N---- C:\WINDOWS\system32\azroles.dll
2011-12-09 15:01:51 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2011-12-09 15:01:51 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2011-12-09 15:01:51 ----N---- C:\WINDOWS\system32\credssp.dll
2011-12-09 15:01:50 ----N---- C:\WINDOWS\system32\dot3ui.dll
2011-12-09 15:01:50 ----N---- C:\WINDOWS\system32\dot3svc.dll
2011-12-09 15:01:50 ----N---- C:\WINDOWS\system32\dot3msm.dll
2011-12-09 15:01:50 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2011-12-09 15:01:50 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2011-12-09 15:01:50 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2011-12-09 15:01:50 ----N---- C:\WINDOWS\system32\dot3api.dll
2011-12-09 15:01:50 ----N---- C:\WINDOWS\system32\dimsroam.dll
2011-12-09 15:01:49 ----N---- C:\WINDOWS\system32\eapsvc.dll
2011-12-09 15:01:49 ----N---- C:\WINDOWS\system32\eapqec.dll
2011-12-09 15:01:49 ----N---- C:\WINDOWS\system32\eappprxy.dll
2011-12-09 15:01:49 ----N---- C:\WINDOWS\system32\eapphost.dll
2011-12-09 15:01:49 ----N---- C:\WINDOWS\system32\eappgnui.dll
2011-12-09 15:01:49 ----N---- C:\WINDOWS\system32\eappcfg.dll
2011-12-09 15:01:49 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2011-12-09 15:01:49 ----N---- C:\WINDOWS\system32\eapolqec.dll
2011-12-09 15:01:48 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2011-12-09 15:01:46 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2011-12-09 15:01:45 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2011-12-09 15:01:45 ----N---- C:\WINDOWS\system32\kmsvc.dll
2011-12-09 15:01:45 ----N---- C:\WINDOWS\system32\kbdpash.dll
2011-12-09 15:01:45 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2011-12-09 15:01:45 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2011-12-09 15:01:44 ----N---- C:\WINDOWS\system32\mmcex.dll
2011-12-09 15:01:44 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2011-12-09 15:01:44 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2011-12-09 15:01:43 ----N---- C:\WINDOWS\system32\mmcperf.exe
2011-12-09 15:01:43 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2011-12-09 15:01:42 ----N---- C:\WINDOWS\system32\napstat.exe
2011-12-09 15:01:42 ----N---- C:\WINDOWS\system32\napmontr.dll
2011-12-09 15:01:42 ----N---- C:\WINDOWS\system32\napipsec.dll
2011-12-09 15:01:42 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2011-12-09 15:01:42 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2011-12-09 15:01:42 ----N---- C:\WINDOWS\system32\mssha.dll
2011-12-09 15:01:41 ----N---- C:\WINDOWS\system32\nv4_disp.dll
2011-12-09 15:01:40 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2011-12-09 15:01:40 ----N---- C:\WINDOWS\system32\onex.dll
2011-12-09 15:01:39 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2011-12-09 15:01:39 ----N---- C:\WINDOWS\system32\rasqec.dll
2011-12-09 15:01:39 ----N---- C:\WINDOWS\system32\qutil.dll
2011-12-09 15:01:39 ----N---- C:\WINDOWS\system32\qcliprov.dll
2011-12-09 15:01:39 ----N---- C:\WINDOWS\system32\qagentrt.dll
2011-12-09 15:01:39 ----N---- C:\WINDOWS\system32\qagent.dll
2011-12-09 15:01:38 ----N---- C:\WINDOWS\system32\setupn.exe
2011-12-09 15:01:38 ----N---- C:\WINDOWS\system32\s3gnb.dll
2011-12-09 15:01:37 ----N---- C:\WINDOWS\system32\slserv.exe
2011-12-09 15:01:37 ----N---- C:\WINDOWS\system32\slrundll.exe
2011-12-09 15:01:37 ----N---- C:\WINDOWS\system32\slgen.dll
2011-12-09 15:01:37 ----N---- C:\WINDOWS\system32\slextspk.dll
2011-12-09 15:01:37 ----N---- C:\WINDOWS\system32\slcoinst.dll
2011-12-09 15:01:35 ----N---- C:\WINDOWS\system32\verclsid.exe
2011-12-09 15:01:35 ----N---- C:\WINDOWS\system32\tspkg.dll
2011-12-09 15:01:35 ----N---- C:\WINDOWS\system32\tsgqec.dll
2011-12-09 15:01:34 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2011-12-09 15:01:34 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2011-12-09 15:01:33 ----N---- C:\WINDOWS\system32\wmphoto.dll
2011-12-09 15:01:33 ----N---- C:\WINDOWS\system32\wlanapi.dll
2011-12-09 15:01:31 ----N---- C:\WINDOWS\system32\xmllite.dll
2011-12-09 15:01:31 ----N---- C:\WINDOWS\slrundll.exe
2011-12-09 15:01:30 ----D---- C:\WINDOWS\system32\cs-cz
2011-12-09 15:01:28 ----D---- C:\WINDOWS\l2schemas
2011-12-09 15:01:27 ----D---- C:\WINDOWS\system32\cs
2011-12-09 15:01:26 ----D---- C:\WINDOWS\system32\bits
2011-12-09 14:51:33 ----D---- C:\WINDOWS\network diagnostic
2011-12-09 14:51:31 ----N---- C:\WINDOWS\system32\drivers\alim1541.sys
2011-12-09 14:51:31 ----N---- C:\WINDOWS\system32\drivers\agpcpq.sys
2011-12-09 14:51:31 ----N---- C:\WINDOWS\system32\drivers\agp440.sys
2011-12-09 14:51:31 ----N---- C:\WINDOWS\system32\drivers\adv11nt5.dll
2011-12-09 14:51:31 ----N---- C:\WINDOWS\system32\drivers\adv09nt5.dll
2011-12-09 14:51:31 ----N---- C:\WINDOWS\system32\drivers\adv08nt5.dll
2011-12-09 14:51:31 ----N---- C:\WINDOWS\system32\drivers\adv07nt5.dll
2011-12-09 14:51:31 ----N---- C:\WINDOWS\system32\drivers\adv05nt5.dll
2011-12-09 14:51:31 ----N---- C:\WINDOWS\system32\drivers\adv02nt5.dll
2011-12-09 14:51:31 ----N---- C:\WINDOWS\system32\drivers\adv01nt5.dll
2011-12-09 14:51:30 ----N---- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2011-12-09 14:51:30 ----N---- C:\WINDOWS\system32\drivers\ati1raxx.sys
2011-12-09 14:51:30 ----N---- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2011-12-09 14:51:30 ----N---- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2011-12-09 14:51:30 ----N---- C:\WINDOWS\system32\drivers\ati1btxx.sys
2011-12-09 14:51:30 ----N---- C:\WINDOWS\system32\drivers\amdagp.sys
2011-12-09 14:51:29 ----N---- C:\WINDOWS\system32\drivers\atinbtxx.sys
2011-12-09 14:51:29 ----N---- C:\WINDOWS\system32\drivers\ati2mtag.sys
2011-12-09 14:51:29 ----N---- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2011-12-09 14:51:29 ----N---- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2011-12-09 14:51:29 ----N---- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2011-12-09 14:51:29 ----N---- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2011-12-09 14:51:29 ----N---- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2011-12-09 14:51:29 ----N---- C:\WINDOWS\system32\drivers\ati1snxx.sys
2011-12-09 14:51:28 ----N---- C:\WINDOWS\system32\drivers\atv04nt5.dll
2011-12-09 14:51:28 ----N---- C:\WINDOWS\system32\drivers\atv02nt5.dll
2011-12-09 14:51:28 ----N---- C:\WINDOWS\system32\drivers\atv01nt5.dll
2011-12-09 14:51:28 ----N---- C:\WINDOWS\system32\drivers\atinxsxx.sys
2011-12-09 14:51:28 ----N---- C:\WINDOWS\system32\drivers\atinxbxx.sys
2011-12-09 14:51:28 ----N---- C:\WINDOWS\system32\drivers\atintuxx.sys
2011-12-09 14:51:28 ----N---- C:\WINDOWS\system32\drivers\atinttxx.sys
2011-12-09 14:51:28 ----N---- C:\WINDOWS\system32\drivers\atinsnxx.sys
2011-12-09 14:51:28 ----N---- C:\WINDOWS\system32\drivers\atinrvxx.sys
2011-12-09 14:51:28 ----N---- C:\WINDOWS\system32\drivers\atinraxx.sys
2011-12-09 14:51:28 ----N---- C:\WINDOWS\system32\drivers\atinpdxx.sys
2011-12-09 14:51:28 ----N---- C:\WINDOWS\system32\drivers\atinmdxx.sys
2011-12-09 14:51:27 ----N---- C:\WINDOWS\system32\drivers\bthpan.sys
2011-12-09 14:51:27 ----N---- C:\WINDOWS\system32\drivers\bthmodem.sys
2011-12-09 14:51:27 ----N---- C:\WINDOWS\system32\drivers\bthenum.sys
2011-12-09 14:51:27 ----N---- C:\WINDOWS\system32\drivers\atv10nt5.dll
2011-12-09 14:51:27 ----N---- C:\WINDOWS\system32\drivers\atv06nt5.dll
2011-12-09 14:51:26 ----N---- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
2011-12-09 14:51:26 ----N---- C:\WINDOWS\system32\drivers\bthusb.sys
2011-12-09 14:51:26 ----N---- C:\WINDOWS\system32\drivers\bthprint.sys
2011-12-09 14:51:25 ----N---- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2011-12-09 14:51:25 ----N---- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2011-12-09 14:51:25 ----N---- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2011-12-09 14:51:25 ----N---- C:\WINDOWS\system32\drivers\hidir.sys
2011-12-09 14:51:25 ----N---- C:\WINDOWS\system32\drivers\hidbth.sys
2011-12-09 14:51:25 ----N---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2011-12-09 14:51:25 ----N---- C:\WINDOWS\system32\drivers\gagp30kx.sys
2011-12-09 14:51:23 ----N---- C:\WINDOWS\system32\drivers\mtxparhm.sys
2011-12-09 14:51:23 ----N---- C:\WINDOWS\system32\drivers\mtlstrm.sys
2011-12-09 14:51:23 ----N---- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2011-12-09 14:51:23 ----N---- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2011-12-09 14:51:22 ----N---- C:\WINDOWS\system32\drivers\s3gnbm.sys
2011-12-09 14:51:22 ----N---- C:\WINDOWS\system32\drivers\rfcomm.sys
2011-12-09 14:51:22 ----N---- C:\WINDOWS\system32\drivers\recagent.sys
2011-12-09 14:51:22 ----N---- C:\WINDOWS\system32\drivers\nv4_mini.sys
2011-12-09 14:51:22 ----N---- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2011-12-09 14:51:22 ----N---- C:\WINDOWS\system32\drivers\mutohpen.sys
2011-12-09 14:51:21 ----N---- C:\WINDOWS\system32\drivers\slntamr.sys
2011-12-09 14:51:21 ----N---- C:\WINDOWS\system32\drivers\slnt7554.sys
2011-12-09 14:51:21 ----N---- C:\WINDOWS\system32\drivers\sisagp.sys
2011-12-09 14:51:21 ----N---- C:\WINDOWS\system32\drivers\siint5.dll
2011-12-09 14:51:21 ----N---- C:\WINDOWS\system32\drivers\sffp_mmc.sys
2011-12-09 14:51:20 ----N---- C:\WINDOWS\system32\drivers\uagp35.sys
2011-12-09 14:51:20 ----N---- C:\WINDOWS\system32\drivers\smbali.sys
2011-12-09 14:51:20 ----N---- C:\WINDOWS\system32\drivers\slwdmsup.sys
2011-12-09 14:51:20 ----N---- C:\WINDOWS\system32\drivers\slnthal.sys
2011-12-09 14:51:19 ----N---- C:\WINDOWS\system32\drivers\watv10nt.sys
2011-12-09 14:51:19 ----N---- C:\WINDOWS\system32\drivers\watv06nt.sys
2011-12-09 14:51:19 ----N---- C:\WINDOWS\system32\drivers\wadv11nt.sys
2011-12-09 14:51:19 ----N---- C:\WINDOWS\system32\drivers\wadv09nt.sys
2011-12-09 14:51:19 ----N---- C:\WINDOWS\system32\drivers\wadv08nt.sys
2011-12-09 14:51:19 ----N---- C:\WINDOWS\system32\drivers\wadv07nt.sys
2011-12-09 14:51:19 ----N---- C:\WINDOWS\system32\drivers\wacompen.sys
2011-12-09 14:51:19 ----N---- C:\WINDOWS\system32\drivers\viaagp.sys
2011-12-09 14:51:19 ----N---- C:\WINDOWS\system32\drivers\vchnt5.dll
2011-12-09 14:51:19 ----N---- C:\WINDOWS\system32\drivers\usbvideo.sys
2011-12-09 14:48:58 ----A---- C:\WINDOWS\002822_.tmp
2011-12-09 14:40:22 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2011-12-09 14:30:24 ----D---- C:\0e81b2832616afe7a27dafdd78924b
2011-12-09 14:06:46 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011-12-09 14:06:45 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2011-12-09 14:06:43 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2011-12-09 14:06:42 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2011-12-09 14:06:41 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2011-12-09 14:06:40 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2011-12-09 14:06:39 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2011-12-09 14:06:38 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2011-12-09 14:05:16 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-12-09 14:04:41 ----D---- C:\Program Files\AVAST Software
2011-12-09 14:04:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2011-12-09 12:55:51 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys

======List of files/folders modified in the last 1 months======

2011-12-09 16:49:44 ----D---- C:\WINDOWS\temp
2011-12-09 16:49:15 ----D---- C:\Program Files\trend micro
2011-12-09 16:47:52 ----RD---- C:\Program Files
2011-12-09 16:47:45 ----SHD---- C:\WINDOWS\Installer
2011-12-09 16:47:05 ----D---- C:\Program Files\Vitware
2011-12-09 16:46:06 ----D---- C:\WINDOWS\Debug
2011-12-09 16:46:06 ----D---- C:\WINDOWS
2011-12-09 16:44:35 ----D---- C:\WINDOWS\system32
2011-12-09 16:44:34 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-12-09 16:42:27 ----D---- C:\WINDOWS\system32\CatRoot2
2011-12-09 16:38:10 ----D---- C:\WINDOWS\system32\Setup
2011-12-09 16:38:10 ----D---- C:\WINDOWS\AppPatch
2011-12-09 16:38:09 ----D---- C:\WINDOWS\system32\wbem
2011-12-09 16:38:08 ----RSD---- C:\WINDOWS\Fonts
2011-12-09 16:38:03 ----D---- C:\WINDOWS\system32\drivers
2011-12-09 16:36:29 ----HD---- C:\WINDOWS\inf
2011-12-09 16:35:49 ----D---- C:\WINDOWS\system32\CatRoot
2011-12-09 16:35:48 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-12-09 15:13:55 ----D---- C:\Program Files\Messenger
2011-12-09 15:12:57 ----D---- C:\WINDOWS\security
2011-12-09 15:12:08 ----D---- C:\WINDOWS\WinSxS
2011-12-09 15:02:19 ----D---- C:\WINDOWS\Help
2011-12-09 15:02:16 ----D---- C:\Program Files\Windows Media Player
2011-12-09 15:02:02 ----D---- C:\WINDOWS\ehome
2011-12-09 15:01:59 ----D---- C:\WINDOWS\system32\inetsrv
2011-12-09 15:01:58 ----D---- C:\WINDOWS\ime
2011-12-09 15:01:30 ----D---- C:\WINDOWS\system32\usmt
2011-12-09 15:01:28 ----D---- C:\Program Files\Internet Explorer
2011-12-09 15:01:26 ----D---- C:\WINDOWS\PeerNet
2011-12-09 15:01:25 ----D---- C:\Program Files\Movie Maker
2011-12-09 14:55:43 ----D---- C:\WINDOWS\ServicePackFiles
2011-12-09 14:55:25 ----D---- C:\WINDOWS\system32\Restore
2011-12-09 14:55:25 ----D---- C:\WINDOWS\system32\npp
2011-12-09 14:55:23 ----D---- C:\WINDOWS\msagent
2011-12-09 14:55:20 ----D---- C:\WINDOWS\srchasst
2011-12-09 14:55:17 ----D---- C:\Program Files\NetMeeting
2011-12-09 14:55:14 ----D---- C:\WINDOWS\system32\Com
2011-12-09 14:55:10 ----D---- C:\Program Files\Windows NT
2011-12-09 14:55:10 ----D---- C:\Program Files\Outlook Express
2011-12-09 14:55:04 ----D---- C:\Program Files\Common Files\System
2011-12-09 14:54:32 ----D---- C:\WINDOWS\system32\oobe
2011-12-09 14:54:29 ----D---- C:\WINDOWS\system
2011-12-09 14:48:48 ----D---- C:\WINDOWS\system32\ReinstallBackups
2011-12-09 14:22:39 ----D---- C:\Program Files\ESET
2011-12-09 14:06:12 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-12-09 13:44:24 ----D---- C:\Program Files\Common Files
2011-12-09 13:40:01 ----D---- C:\Program Files\Google
2011-12-09 13:40:00 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2011-12-09 13:38:01 ----D---- C:\Program Files\Elaborate Bytes
2011-12-09 13:36:21 ----D---- C:\Program Files\Cetis32
2011-12-09 13:33:02 ----D---- C:\Program Files\Microsoft ActiveSync
2011-12-09 13:32:30 ----D---- C:\Poker
2011-12-09 13:29:55 ----D---- C:\Program Files\rajce
2011-12-09 13:04:15 ----D---- C:\Program Files\Mozilla Firefox
2011-12-07 21:20:49 ----N---- C:\WINDOWS\SchedLgU.Txt
2011-12-07 17:08:19 ----D---- C:\Documents and Settings\Veronika\Data aplikací\Skype
2011-12-04 20:49:27 ----A---- C:\WINDOWS\NeroDigital.ini
2011-12-03 15:02:41 ----RD---- C:\Program Files\Skype
2011-12-03 15:02:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-12-03 14:58:04 ----D---- C:\Documents and Settings\Veronika\Data aplikací\skypePM

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2010-12-18 21696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-11-28 30808]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-11-28 34392]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-11-28 435032]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-11-28 314456]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-11-28 52952]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2002-02-19 12032]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.2.0.3; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2006-11-05 17801]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-11-28 20568]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-11-28 111320]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2005-09-05 11354]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2008-09-24 4122368]
R3 EMSCR;EMSCR; C:\WINDOWS\system32\DRIVERS\EMS7SK.sys [2005-11-17 60928]
R3 ESDCR;ESDCR; C:\WINDOWS\system32\DRIVERS\ESD7SK.sys [2005-11-17 37888]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-08-24 1052732]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-09-13 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-14 79232]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 w29n51;Intel(R) PRO/Wireless 2915ABG Network Connection Driver for Windows XP; C:\WINDOWS\system32\DRIVERS\w29n51.sys [2005-09-12 3298432]
S0 ElbyVCD;ElbyVCD; C:\WINDOWS\system32\DRIVERS\ElbyVCD.sys []
S2 ADILOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys [2003-07-17 46167]
S3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\system32\DRIVERS\adiusbaw.sys [2003-03-27 127145]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 Bridge;Most MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-14 71552]
S3 BridgeMP;Miniport mostu MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-14 71552]
S3 catchme;catchme; \??\C:\DOCUME~1\Veronika\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys []
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\WINDOWS\system32\DRIVERS\ewdcsc.sys []
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys []
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\WINDOWS\system32\DRIVERS\ewusbdev.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 SNP2STD;USB2.0 PC Camera (SNP2STD); C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2007-04-09 12039552]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2005-10-21 12800]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-09-02 717296]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-11-28 44768]
R2 EvtEng;EvtEng; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2005-10-06 86016]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2006-10-26 335872]
R2 RegSrvc;RegSrvc; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2005-10-06 139264]
R2 S24EventMonitor;Spectrum24 Event Monitor; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2005-10-06 372809]
R2 wltrysvc;Broadcom Wireless LAN Tray Service; C:\WINDOWS\System32\WLTRYSVC.EXE [2005-12-14 18944]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-10 135664]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-10 135664]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Re: Prosím o kontrolu zahlceného NTB...

Napsal: 10 pro 2011 17:03
od Premda84
Jeste jsem si dovolil log z DDS dle pokynu z fora...

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_02
Run by Veronika at 16:59:48 on 2011-12-09
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.503.71 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\vsnp2std.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Skype\Phone\Skype.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.seznam.cz/
uSearch Bar = hxxp://www.google.com/ie
mStart Page = about:blank
mSearch Bar = about:blank
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_02\bin\ssv.dll
TB: {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [snp2std] c:\windows\vsnp2std.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [Magnify] Magnify.exe
uPolicies-explorer: NoCustomizeWebView = 0 (0x0)
uPolicies-explorer: NoGoTo = 1 (0x1)
uPolicies-explorer: NoInstrumentation = 0 (0x0)
uPolicies-explorer: NoOptions = 1 (0x1)
uPolicies-explorer: NoSMMyPictures = 1 (0x1)
uPolicies-explorer: NoStartMenuMyMusic = 0 (0x0)
uPolicies-explorer: NoSMMyDocs = 1 (0x1)
uPolicies-explorer: NoFavoritesMenu = 1 (0x1)
uPolicies-explorer: NoCommonGroups = 0 (0x0)
uPolicies-explorer: NoStartMenuSubFolders = 0 (0x0)
uPolicies-explorer: NoNtSecurity = 0 (0x0)
uPolicies-explorer: NoFileUrl = 0 (0x0)
uPolicies-explorer: NoBandCustomize = 1 (0x1)
uPolicies-explorer: NoExpandedNewMenu = 0 (0x0)
uPolicies-explorer: SpecifyDefaultButtons = 1 (0x1)
uPolicies-explorer: Btn_Search = 2 (0x2)
uPolicies-explorer: Btn_Folders = 2 (0x2)
uPolicies-explorer: Btn_Favorites = 2 (0x2)
uPolicies-explorer: Btn_Media = 2 (0x2)
uPolicies-explorer: Btn_History = 2 (0x2)
uPolicies-explorer: Btn_Fullscreen = 2 (0x2)
uPolicies-explorer: Btn_Tools = 2 (0x2)
uPolicies-explorer: Btn_MailNews = 2 (0x2)
uPolicies-explorer: Btn_Size = 2 (0x2)
uPolicies-explorer: Btn_Edit = 2 (0x2)
uPolicies-explorer: Btn_Discussions = 2 (0x2)
uPolicies-explorer: Btn_Cut = 2 (0x2)
uPolicies-explorer: Btn_Copy = 2 (0x2)
uPolicies-explorer: Btn_Paste = 2 (0x2)
uPolicies-explorer: Btn_Encoding = 2 (0x2)
uPolicies-explorer: Btn_PrintPreview = 2 (0x2)
uPolicies-explorer: ForceCopyAclwithFile = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {B863453A-26C3-4e1f-A54D-A2CD196348E9} - c:\program files\icqlite\ICQLite.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {E59EB121-F339-4851-A3BA-FE49C35617C2} - c:\program files\icq6.5\ICQ.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_02\bin\ssv.dll
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: mojebanka.cz
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 94.229.92.40 94.229.92.30
TCP: Interfaces\{8B4989A1-0C17-4A71-8EB2-6E89FBCF2C62} : DhcpNameServer = 94.229.92.40 94.229.92.30
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\veronika\data aplikací\mozilla\firefox\profiles\87vv0fm2.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
FF - plugin: c:\documents and settings\veronika\data aplikacă­\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\veronika\local settings\data aplikacă­\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-12-9 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-12-9 314456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-12-9 20568]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-12-9 44768]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2004-8-3 69120]
S0 ElbyVCD;ElbyVCD;c:\windows\system32\drivers\elbyvcd.sys --> c:\windows\system32\drivers\ElbyVCD.sys [?]
S2 gupdate;Služba Google Update (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-10 135664]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-10 135664]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\drivers\ewdcsc.sys --> c:\windows\system32\drivers\ewdcsc.sys [?]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys --> c:\windows\system32\drivers\ewusbdev.sys [?]
.
=============== Created Last 30 ================
.
2011-12-09 14:07:12 -------- d-----w- c:\windows\LastGood.Tmp
2011-12-09 14:02:17 80896 -c----w- c:\windows\system32\dllcache\msxml6r.dll
2011-12-09 14:02:17 80896 ------w- c:\windows\system32\msxml6r.dll
2011-12-09 14:02:17 1372672 -c----w- c:\windows\system32\dllcache\msxml6.dll
2011-12-09 14:02:16 1372672 ------w- c:\windows\system32\msxml6.dll
2011-12-09 14:02:02 102912 -c----w- c:\windows\system32\dllcache\dpcdll.dll
2011-12-09 14:02:00 9728 ------w- c:\windows\system32\rwnh.dll
2011-12-09 14:02:00 9728 ------w- c:\windows\system32\comsdupd.exe
2011-12-09 14:02:00 46592 ------w- c:\windows\system32\drivers\irbus.sys
2011-12-09 13:55:12 294912 ------w- c:\program files\windows media player\dlimport.exe
2011-12-09 13:55:02 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe
2011-12-09 13:48:58 19569 ----a-w- c:\windows\002822_.tmp
2011-12-09 13:30:24 -------- d-----w- C:\0e81b2832616afe7a27dafdd78924b
2011-12-09 13:06:41 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-12-09 13:05:25 41184 ----a-w- c:\windows\avastSS.scr
2011-12-09 13:04:41 -------- d-----w- c:\program files\AVAST Software
2011-12-09 13:04:41 -------- d-----w- c:\documents and settings\all users\data aplikací\AVAST Software
2011-12-09 11:55:51 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
.
==================== Find3M ====================
.
2008-10-21 11:27:47 77738888 ----a-w- c:\program files\ExcelViewer.exe
.
============= FINISH: 17:05:05,60 ===============

Re: Prosím o kontrolu zahlceného NTB...

Napsal: 11 pro 2011 10:50
od Premda84
2 vyosek: je mi to trosku blbe, ale radeji se pripominam, protoze budu u NTB uz jen dnes do vecera - meril jsem nabeh NTB a je to cca 7minut nez se da neco zacit s NTB delat... Avast jsem nainstaloval.... projel - bez viru, MBAM hlasi taky 0 tak nevim...

Re: Prosím o kontrolu zahlceného NTB...

Napsal: 11 pro 2011 11:18
od vyosek
Zdravim :)

:arrow: Ja vim ze tu na me ceka Vas prispevek, ale nase forum funguje na bazi dobrovolnosti - radci jsou zde ve svem volnem case a zdarma. Je vikend, kazdy z radcu ma sve rodinne ci pracovni povinnosti. Pokud jste potreboval urgentni pomoc, mel jste se obratit na specializovane servisy\sluzby, kde jsou technici placeni a resi problemy ihned

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe ale nespoustejte

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    File::
    C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
    C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    
    Driver::
    gupdate
    gupdatem
    
    Folder::
    C:\Program Files\ESET
     C:\Program Files\ICQ6Toolbar
    
    DDS::
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mRun: [TkBellExe]
    mRun: [QuickTime Task]
    mRun: [Adobe Reader Speed Launcher]
    mRun: [Adobe ARM]
    Trusted Zone: mojebanka.cz
    
    Firefox::
    FF - ProfilePath - c:\documents and settings\veronika\data aplikací\mozilla\firefox\profiles\87vv0fm2.default\
    FF - prefs.js: browser.search.selectedEngine - ICQ Search
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "swg"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    
    ClearJavaCache::
    
    AtJob::
    
    Reboot::
    
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: Prosím o kontrolu zahlceného NTB...

Napsal: 11 pro 2011 11:23
od Premda84
Omlouvam se-nemyslel jsem to nejak zle - chapu Vase povinnosti a moc dekuji za rady a vazim si toho... provedu co je napsano...

Re: Prosím o kontrolu zahlceného NTB...

Napsal: 11 pro 2011 12:09
od Premda84
Uf....je to krapet vetsi.... http://www.uloz.to/11683826/combofix-txt

Re: Prosím o kontrolu zahlceného NTB...

Napsal: 11 pro 2011 13:08
od vyosek
Ja si sem log vlozim bez casti SnapShot

ComboFix 11-12-10.01 - Veronika 11.12.2011 11:36:48.6.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.503.131 [GMT 1:00]
Spuštěný z: c:\documents and settings\Veronika\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Veronika\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Veronika\WINDOWS
c:\program files\ESET
c:\program files\ESET\Install\advheur.nup
c:\program files\ESET\Install\archs.nup
c:\program files\ESET\Install\engine.nup
c:\program files\ESET\Install\charon.nup
c:\program files\ESET\Install\main.dll
c:\program files\ESET\Install\mainlang.dll
c:\program files\ESET\Install\mfc42.dll
c:\program files\ESET\Install\mfc42u.dll
c:\program files\ESET\Install\msvcrt.dll
c:\program files\ESET\Install\ntbasecz.nup
c:\program files\ESET\Install\ntinetcz.nup
c:\program files\ESET\Install\ntstdcz.nup
c:\program files\ESET\Install\pwscan.nup
c:\program files\ESET\Install\readme.txt
c:\program files\ESET\Install\setup.exe
c:\program files\ESET\Install\setup.xml
c:\program files\ESET\Install\utilmod.nup
c:\program files\ESET\nod32.007
c:\program files\ICQ6Toolbar
c:\program files\ICQ6Toolbar\Icons.bmp
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\program files\ICQ6Toolbar\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\ICQToolBar.dll
c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\logo_small.gif
c:\program files\ICQ6Toolbar\ServiceStarter.exe
c:\program files\ICQ6Toolbar\short.wav
c:\program files\ICQ6Toolbar\Version.txt
c:\windows\IsUn0407.exe
c:\windows\WindowsXP-KB822603-x86.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_GUPDATE
-------\Legacy_GUPDATEM
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-11 do 2011-12-11 )))))))))))))))))))))))))))))))
.
.
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-21 11:27 . 2008-10-21 11:23 77738888 ----a-w- c:\program files\ExcelViewer.exe
2011-09-24 07:30 . 2011-05-05 18:30 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-08-24 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-08-24 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-08-24 114688]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-14 1236992]
"snp2std"="c:\windows\vsnp2std.exe" [2006-09-15 675840]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Magnify"="Magnify.exe" [2008-04-14 72704]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoCustomizeWebView"= 0 (0x0)
"NoGoTo"= 1 (0x1)
"NoOptions"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoStartMenuMyMusic"= 0 (0x0)
"NoSMMyDocs"= 1 (0x1)
"NoFavoritesMenu"= 1 (0x1)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoBandCustomize"= 1 (0x1)
"NoExpandedNewMenu"= 0 (0x0)
"SpecifyDefaultButtons"= 1 (0x1)
"Btn_Search"= 2 (0x2)
"Btn_Folders"= 2 (0x2)
"Btn_Favorites"= 2 (0x2)
"Btn_Media"= 2 (0x2)
"Btn_History"= 2 (0x2)
"Btn_Fullscreen"= 2 (0x2)
"Btn_Tools"= 2 (0x2)
"Btn_MailNews"= 2 (0x2)
"Btn_Size"= 2 (0x2)
"Btn_Edit"= 2 (0x2)
"Btn_Discussions"= 2 (0x2)
"Btn_Cut"= 2 (0x2)
"Btn_Copy"= 2 (0x2)
"Btn_Paste"= 2 (0x2)
"Btn_Encoding"= 2 (0x2)
"Btn_PrintPreview"= 2 (0x2)
"ForceCopyAclwithFile"= 0 (0x0)
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^DSLMON.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\DSLMON.lnk
backup=c:\windows\pss\DSLMON.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2007-04-16 13:28 577536 ----a-w- c:\windows\soundman.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\mozilla.org\\Mozilla\\mozilla.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\WINDOWS\\system32\\igfxpers.exe"=
"c:\\WINDOWS\\system32\\WLTRAY.exe"=
"c:\\Program Files\\QuickTime\\qttask.exe"=
"c:\\Program Files\\Java\\jre1.6.0_02\\bin\\jusched.exe"=
"c:\\Program Files\\Winamp\\winampa.exe"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"c:\\WINDOWS\\SOUNDMAN.EXE"=
"c:\\Program Files\\SAGEM\\SAGEM F@st 800-840\\dslmon.exe"=
"c:\\Program Files\\Java\\jre1.6.0_02\\bin\\jucheck.exe"=
"c:\\WINDOWS\\system32\\igfxsrvc.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Veronika\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Veronika\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [9.12.2011 14:06 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [9.12.2011 14:06 314456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9.12.2011 14:06 20568]
S0 ElbyVCD;ElbyVCD;c:\windows\system32\DRIVERS\ElbyVCD.sys --> c:\windows\system32\DRIVERS\ElbyVCD.sys [?]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\DRIVERS\ewdcsc.sys --> c:\windows\system32\DRIVERS\ewdcsc.sys [?]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys --> c:\windows\system32\DRIVERS\ewusbdev.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [24.10.2006 21:55 717296]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-12-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-10 20:50]
.
2011-12-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-10 20:50]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
mStart Page = about:blank
mSearch Bar = about:blank
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 94.229.92.40 94.229.92.30
FF - ProfilePath - c:\documents and settings\Veronika\Data aplikací\Mozilla\Firefox\Profiles\87vv0fm2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
MSConfigStartUp-CloneCDElbyCDFL - c:\program files\Elaborate Bytes\CloneCD\ElbyCheck.exe
MSConfigStartUp-CloneCDTray - c:\program files\Elaborate Bytes\CloneCD\CloneCDTray.exe
MSConfigStartUp-FixCamera - c:\windows\FixCamera.EXE
AddRemove-Moorhuhn Winter-Edition - c:\windows\IsUn0407.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-11 11:53
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(680)
c:\windows\System32\BCMLogon.dll
.
- - - - - - - > 'explorer.exe'(3052)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
.
**************************************************************************
.
Celkový čas: 2011-12-11 12:09:28 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-12-11 11:09
ComboFix2.txt 2010-10-17 18:27
ComboFix3.txt 2010-05-16 12:33
ComboFix4.txt 2010-05-16 10:04
ComboFix5.txt 2011-12-11 10:32
.
Před spuštěním: Volných bajtů: 14 395 928 576
Po spuštění: Volných bajtů: 14 444 990 464
.
- - End Of File - - AF831B0B3AF34DA98F64740FB38D44C3

Re: Prosím o kontrolu zahlceného NTB...

Napsal: 11 pro 2011 13:10
od vyosek
:arrow: Jeste jeden skript pro CF, log pak sem

Kód: Vybrat vše

KillAll::

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000000

File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

Reboot::

Re: Prosím o kontrolu zahlceného NTB...

Napsal: 11 pro 2011 17:18
od Premda84
Ahoj, tentokrate ma jiz log jen "par" radku a subjektivne muzu rict, ze se zrychlil i start PC - predtim nez se dalo s PC pustit Mozilla tak od startu NTB to trvalo skoro 5minut...ted cca 2,5 min takze velky uspech muzu rict... :James008:

jinak od ted budu na NTB asi uz jen pul hodky - a potom asi az dalsi vikend takze kdyby bylo potreba tak bych s dovolenim to udelal az priste...moc Ti dekuji!! :D

ComboFix 11-12-10.01 - Veronika 11.12.2011 16:52:18.7.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.503.232 [GMT 1:00]
Spuštěný z: c:\documents and settings\Veronika\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Veronika\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-11 do 2011-12-11 )))))))))))))))))))))))))))))))
.
.
2011-12-09 14:02 . 2009-07-31 09:05 1372672 -c----w- c:\windows\system32\dllcache\msxml6.dll
2011-12-09 14:02 . 2008-04-14 07:00 80896 -c----w- c:\windows\system32\dllcache\msxml6r.dll
2011-12-09 14:02 . 2008-04-14 07:00 80896 ------w- c:\windows\system32\msxml6r.dll
2011-12-09 14:02 . 2009-07-31 09:05 1372672 ------w- c:\windows\system32\msxml6.dll
2011-12-09 14:02 . 2008-04-14 07:49 102912 -c----w- c:\windows\system32\dllcache\dpcdll.dll
2011-12-09 14:02 . 2008-04-14 07:51 9728 ------w- c:\windows\system32\rwnh.dll
2011-12-09 14:02 . 2008-04-13 23:15 46592 ------w- c:\windows\system32\drivers\irbus.sys
2011-12-09 14:02 . 2008-04-13 23:13 9728 ------w- c:\windows\system32\comsdupd.exe
2011-12-09 13:55 . 2008-04-14 07:52 294912 ------w- c:\program files\Windows Media Player\dlimport.exe
2011-12-09 13:55 . 2008-04-14 07:52 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe
2011-12-09 13:48 . 2006-12-28 23:31 19569 ----a-w- c:\windows\002822_.tmp
2011-12-09 13:30 . 2011-12-09 13:32 -------- d-----w- C:\0e81b2832616afe7a27dafdd78924b
2011-12-09 13:06 . 2011-11-28 17:51 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-12-09 13:06 . 2011-11-28 17:53 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-12-09 13:06 . 2011-11-28 17:52 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-12-09 13:06 . 2011-11-28 17:52 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-12-09 13:06 . 2011-11-28 17:53 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-12-09 13:06 . 2011-11-28 17:52 111320 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-12-09 13:06 . 2011-11-28 17:51 105176 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-12-09 13:06 . 2011-11-28 17:48 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-12-09 13:05 . 2011-11-28 18:01 41184 ----a-w- c:\windows\avastSS.scr
2011-12-09 13:05 . 2011-11-28 18:01 199816 ----a-w- c:\windows\system32\aswBoot.exe
2011-12-09 13:04 . 2011-12-09 13:04 -------- d-----w- c:\program files\AVAST Software
2011-12-09 13:04 . 2011-12-09 13:04 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2011-12-09 11:55 . 2011-12-09 11:55 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-12-06 20:13 . 2011-12-06 20:13 -------- d-----w- c:\documents and settings\val363\Local Settings\Data aplikací\Temp
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-21 11:27 . 2008-10-21 11:23 77738888 ----a-w- c:\program files\ExcelViewer.exe
2011-09-24 07:30 . 2011-05-05 18:30 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-08-24 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-08-24 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-08-24 114688]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-14 1236992]
"snp2std"="c:\windows\vsnp2std.exe" [2006-09-15 675840]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Magnify"="Magnify.exe" [2008-04-14 72704]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoCustomizeWebView"= 0 (0x0)
"NoGoTo"= 1 (0x1)
"NoOptions"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoStartMenuMyMusic"= 0 (0x0)
"NoSMMyDocs"= 1 (0x1)
"NoFavoritesMenu"= 1 (0x1)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoBandCustomize"= 1 (0x1)
"NoExpandedNewMenu"= 0 (0x0)
"SpecifyDefaultButtons"= 1 (0x1)
"Btn_Search"= 2 (0x2)
"Btn_Folders"= 2 (0x2)
"Btn_Favorites"= 2 (0x2)
"Btn_Media"= 2 (0x2)
"Btn_History"= 2 (0x2)
"Btn_Fullscreen"= 2 (0x2)
"Btn_Tools"= 2 (0x2)
"Btn_MailNews"= 2 (0x2)
"Btn_Size"= 2 (0x2)
"Btn_Edit"= 2 (0x2)
"Btn_Discussions"= 2 (0x2)
"Btn_Cut"= 2 (0x2)
"Btn_Copy"= 2 (0x2)
"Btn_Paste"= 2 (0x2)
"Btn_Encoding"= 2 (0x2)
"Btn_PrintPreview"= 2 (0x2)
"ForceCopyAclwithFile"= 0 (0x0)
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^DSLMON.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\DSLMON.lnk
backup=c:\windows\pss\DSLMON.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2007-04-16 13:28 577536 ----a-w- c:\windows\soundman.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\mozilla.org\\Mozilla\\mozilla.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\WINDOWS\\system32\\igfxpers.exe"=
"c:\\WINDOWS\\system32\\WLTRAY.exe"=
"c:\\Program Files\\QuickTime\\qttask.exe"=
"c:\\Program Files\\Java\\jre1.6.0_02\\bin\\jusched.exe"=
"c:\\Program Files\\Winamp\\winampa.exe"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"c:\\WINDOWS\\SOUNDMAN.EXE"=
"c:\\Program Files\\SAGEM\\SAGEM F@st 800-840\\dslmon.exe"=
"c:\\Program Files\\Java\\jre1.6.0_02\\bin\\jucheck.exe"=
"c:\\WINDOWS\\system32\\igfxsrvc.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Veronika\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Veronika\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [9.12.2011 14:06 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [9.12.2011 14:06 314456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9.12.2011 14:06 20568]
S0 ElbyVCD;ElbyVCD;c:\windows\system32\DRIVERS\ElbyVCD.sys --> c:\windows\system32\DRIVERS\ElbyVCD.sys [?]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\DRIVERS\ewdcsc.sys --> c:\windows\system32\DRIVERS\ewdcsc.sys [?]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys --> c:\windows\system32\DRIVERS\ewusbdev.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [24.10.2006 21:55 717296]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-12-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-10 20:50]
.
2011-12-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-10 20:50]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
mStart Page = about:blank
mSearch Bar = about:blank
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 94.229.92.40 94.229.92.30
FF - ProfilePath - c:\documents and settings\Veronika\Data aplikací\Mozilla\Firefox\Profiles\87vv0fm2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-11 17:07
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(688)
c:\windows\System32\BCMLogon.dll
.
- - - - - - - > 'explorer.exe'(2792)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-12-11 17:13:11 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-12-11 16:13
ComboFix2.txt 2011-12-11 11:09
ComboFix3.txt 2010-10-17 18:27
ComboFix4.txt 2010-05-16 12:33
ComboFix5.txt 2011-12-11 15:46
.
Před spuštěním: Volných bajtů: 14 326 435 840
Po spuštění: Volných bajtů: 14 313 299 968
.
- - End Of File - - 71476C20BBACFF7DCCE861CB3CA18168