Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Preventivka - prosím

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Mufff
Návštěvník
Návštěvník
Příspěvky: 92
Registrován: 14 dub 2009 15:12

Preventivka - prosím

#1 Příspěvek od Mufff »

Zdravím. Můžu požádat o preventivku logu:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Maca at 2012-08-03 21:44:42
Systém Microsoft Windows XP Professional Service Pack 2
System drive D: has 21 GB (55%) free of 38 GB
Total RAM: 1014 MB (23% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:44:50, on 3.8.2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\AVAST Software\Avast\AvastSvc.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\acs.exe
D:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\CyberLink\Shared Files\RichVideo.exe
D:\WINDOWS\system32\spool\drivers\w32x86\3\NetFaxServer.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\igfxtray.exe
D:\WINDOWS\system32\hkcmd.exe
D:\WINDOWS\system32\igfxsrvc.exe
D:\WINDOWS\system32\igfxpers.exe
D:\WINDOWS\RTHDCPL.EXE
D:\WINDOWS\AGRSMMSG.exe
D:\Program Files\Synaptics\SynTP\SynTPEnh.exe
D:\Program Files\BenQ\BenQ Surround\BenQSurround.exe
D:\Program Files\BenQ\Q-HotkeyMgr\HotkeySensor.exe
D:\Program Files\Ekahau\Ekahau Wireless Utility\ACU.exe
D:\Program Files\Notebook Hardware Control\nhc.exe
D:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
D:\WINDOWS\Twain_32\Samsung\SCX4623\Scan2pc.exe
D:\Program Files\Real\RealPlayer\update\realsched.exe
D:\Program Files\AVAST Software\Avast\avastUI.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
D:\WINDOWS\system32\wbem\wmiapsrv.exe
D:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
D:\Program Files\internet explorer\iexplore.exe
D:\Program Files\internet explorer\iexplore.exe
D:\Documents and Settings\Maca\Local Settings\Temporary Internet Files\Content.IE5\X550LQ03\RSIT[1].exe
D:\Program Files\trend micro\Maca.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - D:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - D:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - D:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IgfxTray] D:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] D:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] D:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPEnh] D:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BenQSurround] D:\Program Files\BenQ\BenQ Surround\BenQSurround.exe
O4 - HKLM\..\Run: [Q-HotkeyMgr] "D:\Program Files\BenQ\Q-HotkeyMgr\HotkeySensor.exe"
O4 - HKLM\..\Run: [ACU] "D:\Program Files\Ekahau\Ekahau Wireless Utility\ACU.exe" -nogui
O4 - HKLM\..\Run: [NotebookHardwareControl] "D:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [Samsung PanelMgr] D:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
O4 - HKLM\..\Run: [4623 Scan2PC] "D:\WINDOWS\Twain_32\Samsung\SCX4623\Scan2pc.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [avast] "D:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 7934784652
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: Ekahau Configuration Service (ACS) - Unknown owner - D:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - D:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - D:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Služba Google Update (gupdate1c996bee849d438) (gupdate1c996bee849d438) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - D:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Samsung Network Fax Server - Unknown owner - D:\WINDOWS\system32\spool\drivers\w32x86\3\NetFaxServer.exe

--
End of file - 10225 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\avast! Emergency Update.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
D:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1801674531-1336601894-839522115-1003.job
D:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1801674531-1336601894-839522115-1003.job

=========Mozilla firefox=========

ProfilePath - D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "extensions.enabledItems" - "wrc@avast.com:7.0.1456, {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11, jqs@sun.com:1.0, {ABDE892B-13A8-4d1b-88E6-365A6E755758}:15.0.1, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.19"

"jqs@sun.com"=D:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"=D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
"wrc@avast.com"=D:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=D:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=D:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pack.google.com/Google Updater;version=13]
"Description"=Google Updater
"Path"=D:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=D:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13]
"Description"=RealJukebox Netscape Plugin
"Path"=D:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13]
"Description"=RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In
"Path"=D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13]
"Description"=15.0.1.13
"Path"=D:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=D:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=D:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll

D:\Program Files\Mozilla Firefox\extensions\
{800b5000-a755-47e1-992b-48a1c1357f07}
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

D:\Program Files\Mozilla Firefox\components\
aboutRights.js
aboutRobots.js
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
jsconsole-clhandler.js
nppl3260.xpt
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsHandlerService.js
nsHelperAppDlg.js
nsIQTScriptablePlugin.xpt
nsjsrealplayerplugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesTransactionsService.js
nsPostUpdateWin.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
txEXSLTRegExFunctions.js
WebContentConverter.js

D:\Program Files\Mozilla Firefox\plugins\
npdeploytk.dll
npnul32.dll
nppl3260.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprjplug.dll
nprpjplug.dll
QuickTimePlugin.class

D:\Program Files\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\
icqplugin-1.xml
icqplugin-10.xml
icqplugin-11.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin-5.xml
icqplugin-6.xml
icqplugin-7.xml
icqplugin-8.xml
icqplugin-9.xml
icqplugin.xml
web-search.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - D:\PROGRA~1\ICQTOO~1\toolbaru.dll [2006-12-25 701952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2012-01-15 425680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - D:\Program Files\Java\jre6\bin\ssv.dll [2008-12-12 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-07-03 1160792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - D:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2012-04-05 192112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10 3834016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - D:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll [2012-01-23 1003576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-12 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-12 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-07-03 1160792]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - D:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2012-04-05 192112]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=D:\WINDOWS\system32\igfxtray.exe [2008-04-05 138008]
"HotKeysCmds"=D:\WINDOWS\system32\hkcmd.exe [2008-04-05 162584]
"Persistence"=D:\WINDOWS\system32\igfxpers.exe [2008-04-05 138008]
"RTHDCPL"=D:\WINDOWS\RTHDCPL.EXE [2007-07-05 16380416]
"AGRSMMSG"=D:\WINDOWS\AGRSMMSG.exe [2008-04-05 88363]
"SynTPEnh"=D:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-04-19 861744]
"BenQSurround"=D:\Program Files\BenQ\BenQ Surround\BenQSurround.exe [2007-04-20 1187840]
"Q-HotkeyMgr"=D:\Program Files\BenQ\Q-HotkeyMgr\HotkeySensor.exe [2007-03-22 237673]
"ACU"=D:\Program Files\Ekahau\Ekahau Wireless Utility\ACU.exe [2006-05-09 303104]
"NotebookHardwareControl"=D:\Program Files\Notebook Hardware Control\nhc.exe [2007-05-04 2629632]
"Samsung PanelMgr"=D:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe [2009-08-14 614400]
"4623 Scan2PC"=D:\WINDOWS\Twain_32\Samsung\SCX4623\Scan2pc.exe [2009-09-10 1968640]
"QuickTime Task"=D:\Program Files\QuickTime\qttask.exe [2008-03-28 413696]
"TkBellExe"=D:\Program Files\Real\RealPlayer\update\realsched.exe [2012-01-15 296056]
"avast"=D:\Program Files\AVAST Software\Avast\avastUI.exe [2012-07-03 4273976]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
"swg"=D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-02-24 39408]

D:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - D:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

D:\Documents and Settings\Maca\Nabídka Start\Programy\Po spuštění
Adobe Gamma.lnk - D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
D:\WINDOWS\system32\igfxdev.dll [2008-04-05 204800]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe"="D:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup"
"D:\Program Files\WIP Miranda IM 1.7\miranda32.exe"="D:\Program Files\WIP Miranda IM 1.7\miranda32.exe:*:Enabled:Miranda IM"
"D:\Program Files\WIP Miranda IM 1.7.3\miranda32.exe"="D:\Program Files\WIP Miranda IM 1.7.3\miranda32.exe:*:Enabled:Miranda IM"
"D:\Program Files\Skype\Plugin Manager\skypePM.exe"="D:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"D:\WINDOWS\twain_32\Samsung\ScanMgr.exe"="D:\WINDOWS\twain_32\Samsung\ScanMgr.exe:*:Enabled:Scan Manger"
"D:\WINDOWS\twain_32\Samsung\SCX4623\Scan2Pc.exe"="D:\WINDOWS\twain_32\Samsung\SCX4623\Scan2Pc.exe:*:Enabled:ScanToPC"
"D:\WINDOWS\twain_32\Samsung\SCX4623\Sscan2io.exe"="D:\WINDOWS\twain_32\Samsung\SCX4623\Sscan2io.exe:*:Enabled:SScanToIO"
"D:\Program Files\ICQ7.4\ICQ.exe"="D:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"
"D:\Program Files\BitLord2\BitLord.exe"="D:\Program Files\BitLord2\BitLord.exe:*:Enabled:Bitlord2"
"D:\Program Files\Skype\Phone\Skype.exe"="D:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
"D:\Program Files\Google\Google Earth\plugin\geplugin.exe"="D:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\ICQ7.4\ICQ.exe"="D:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=D:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=D:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-09-12 23:06:29 ----A---- D:\WINDOWS\system32\drivers\aswFsBlk.sys
2012-09-12 23:06:28 ----A---- D:\WINDOWS\system32\drivers\aswSP.sys
2012-09-12 23:06:26 ----A---- D:\WINDOWS\system32\drivers\aswTdi.sys
2012-09-12 23:06:26 ----A---- D:\WINDOWS\system32\drivers\aswRdr.sys
2012-09-12 23:06:25 ----A---- D:\WINDOWS\system32\drivers\aswSnx.sys
2012-09-12 23:06:25 ----A---- D:\WINDOWS\system32\drivers\aswmon2.sys
2012-09-12 23:06:25 ----A---- D:\WINDOWS\system32\drivers\aswmon.sys
2012-09-12 23:06:24 ----A---- D:\WINDOWS\system32\drivers\aavmker4.sys
2012-09-12 23:06:17 ----SHD---- D:\Config.Msi
2012-09-12 23:05:51 ----A---- D:\WINDOWS\avastSS.scr
2012-09-12 23:05:50 ----A---- D:\WINDOWS\system32\aswBoot.exe
2012-09-12 23:05:32 ----D---- D:\Program Files\AVAST Software
2012-08-23 21:10:45 ----A---- D:\WINDOWS\system32\systeminfo.dll
2012-08-23 21:10:35 ----D---- D:\Documents and Settings\All Users\Data aplikací\BlazeVideo
2012-08-23 21:10:32 ----A---- D:\WINDOWS\system32\psisdecd.dll
2012-08-23 21:10:18 ----D---- D:\Program Files\BlazeVideo
2012-08-03 21:44:42 ----D---- D:\rsit
2012-07-20 21:10:30 ----D---- D:\D2VAVS
2012-07-20 21:10:08 ----D---- D:\Ripp
2012-07-20 21:09:00 ----A---- D:\Rebuilder.ini
2012-07-20 21:09:00 ----A---- D:\Installer.txt
2012-07-20 21:08:10 ----A---- D:\info.txt
2012-07-20 21:08:07 ----D---- D:\Program Files\DVD-RB
2012-07-20 21:07:16 ----D---- D:\Program Files\AviSynth 2.5

======List of files/folders modified in the last 1 month======

2012-09-12 23:06:29 ----D---- D:\WINDOWS\system32\drivers
2012-09-12 23:06:19 ----D---- D:\WINDOWS\WinSxS
2012-09-12 23:05:32 ----D---- D:\Documents and Settings\All Users\Data aplikací\AVAST Software
2012-08-23 21:10:49 ----RSHDC---- D:\WINDOWS\system32\dllcache
2012-08-03 21:44:50 ----D---- D:\WINDOWS\Prefetch
2012-08-03 21:44:50 ----D---- D:\Program Files\Trend Micro
2012-08-03 20:37:44 ----D---- D:\Program Files\Mozilla Firefox
2012-08-03 20:26:11 ----D---- D:\WINDOWS\Temp
2012-08-03 09:54:31 ----D---- D:\WINDOWS\Microsoft.NET
2012-08-03 09:47:49 ----D---- D:\WINDOWS
2012-08-03 09:46:41 ----A---- D:\WINDOWS\SchedLgU.Txt
2012-08-03 09:45:56 ----SD---- D:\WINDOWS\Tasks
2012-08-03 09:45:54 ----D---- D:\WINDOWS\system32
2012-08-03 09:41:51 ----D---- D:\WINDOWS\Minidump
2012-07-29 18:06:23 ----D---- D:\WINDOWS\Help
2012-07-27 21:50:39 ----A---- D:\WINDOWS\NeroDigital.ini
2012-07-26 13:11:51 ----D---- D:\Documents and Settings\Maca\Data aplikací\Skype
2012-07-25 20:09:00 ----D---- D:\Documents and Settings\Maca\Data aplikací\ICQ
2012-07-20 21:08:07 ----RD---- D:\Program Files
2012-07-20 21:02:43 ----D---- D:\Program Files\DVD Shrink
2012-07-19 16:29:11 ----SHD---- D:\WINDOWS\Installer
2012-07-18 14:21:57 ----D---- D:\WINDOWS\system32\CatRoot2
2012-07-10 05:47:55 ----HD---- D:\WINDOWS\inf

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI; D:\WINDOWS\system32\DRIVERS\ohci1394.sys [2004-08-03 61056]
R0 PxHelp20;PxHelp20; D:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R1 Aavmker4;avast! Asynchronous Virus Monitor; D:\WINDOWS\system32\drivers\Aavmker4.sys [2012-07-03 25256]
R1 AswRdr;aswRdr; D:\WINDOWS\system32\drivers\AswRdr.sys [2012-07-03 35928]
R1 aswSnx;aswSnx; D:\WINDOWS\system32\drivers\aswSnx.sys [2012-07-03 721000]
R1 aswSP;aswSP; D:\WINDOWS\system32\drivers\aswSP.sys [2012-07-03 353688]
R1 aswTdi;avast! Network Shield Support; D:\WINDOWS\system32\drivers\aswTdi.sys [2012-07-03 54232]
R1 intelppm;Řadič procesoru Intel; D:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-17 39936]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.10.0; D:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-04-11 21275]
R2 aswFsBlk;aswFsBlk; D:\WINDOWS\system32\drivers\aswFsBlk.sys [2012-07-03 21256]
R2 aswMon2;avast! Standard Shield Support; D:\WINDOWS\system32\drivers\aswMon2.sys [2012-07-03 97608]
R2 QBIOSIo;QBIOSIo.dll; D:\WINDOWS\system32\QBIOSIo.dll [2007-01-20 11520]
R3 AgereSoftModem;Agere Systems Soft Modem; D:\WINDOWS\system32\DRIVERS\AGRSM.sys [2008-04-05 1270540]
R3 AR5211;Atheros Wireless Network Adapter Service; D:\WINDOWS\system32\DRIVERS\ar5211.sys [2006-10-20 478432]
R3 Arp1394;Protokol 1394 ARP Client; D:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-17 60800]
R3 btaudio;Bluetooth Audio Device; D:\WINDOWS\system32\drivers\btaudio.sys [2006-06-07 329901]
R3 btkrnl;Bluetooth Bus Enumerator; D:\WINDOWS\system32\DRIVERS\btkrnl.sys [2006-06-07 855018]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 ialm;ialm; D:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-04-05 5700096]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); D:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-07-10 4449280]
R3 nhcDriverDevice;Notebook Hardware Control Driver; \??\D:\WINDOWS\system32\drivers\nhcDriver.sys []
R3 NIC1394;1394 Net Driver; D:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
R3 rimmptsk;rimmptsk; D:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2005-11-16 28928]
R3 rimsptsk;rimsptsk; D:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2006-09-08 51328]
R3 rismxdp;Ricoh xD-Picture Card Driver; D:\WINDOWS\system32\DRIVERS\rixdptsk.sys [2005-11-01 308992]
R3 sdbus;sdbus; D:\WINDOWS\system32\DRIVERS\sdbus.sys [2004-08-03 67584]
R3 SynTP;Synaptics TouchPad Driver; D:\WINDOWS\system32\DRIVERS\SynTP.sys [2007-04-19 186552]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; D:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 usbvideo;Zobrazovací zařízení USB (WDM); D:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-04 78464]
R3 Wdf01000;Wdf01000; D:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; D:\WINDOWS\system32\DRIVERS\yk51x86.sys [2006-11-22 250496]
S1 kbdhid;Ovladač klávesnice standardu HID; D:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
S2 DgiVecp;DgiVecp; \??\D:\WINDOWS\system32\Drivers\DgiVecp.sys []
S2 SSPORT;SSPORT; \??\D:\WINDOWS\system32\Drivers\SSPORT.sys []
S3 BTDriver;Bluetooth Virtual Communications Driver; D:\WINDOWS\system32\DRIVERS\btport.sys [2006-06-07 30459]
S3 BTWDNDIS;Bluetooth LAN Access Server; D:\WINDOWS\system32\DRIVERS\btwdndis.sys [2006-06-07 149028]
S3 btwhid;btwhid; D:\WINDOWS\system32\DRIVERS\btwhid.sys [2006-06-07 47811]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; D:\WINDOWS\System32\Drivers\btwusb.sys [2006-06-07 67384]
S3 CCDECODE;Dekodér Closed Caption; D:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 HidUsb;Ovladač třídy standardu HID; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 ipw_bus;IPWireless; D:\WINDOWS\system32\DRIVERS\ipw_bus.sys []
S3 ipw_mdfl;Wireless Broadband Modem Filter; D:\WINDOWS\system32\DRIVERS\ipw_mdfl.sys []
S3 ipw_mdm;Wireless Broadband Modem (WDM); D:\WINDOWS\system32\DRIVERS\ipw_mdm.sys []
S3 IpwP;IPWireless 3G Network Adapter; D:\WINDOWS\system32\DRIVERS\ipw3gnet.sys [2008-10-10 51040]
S3 mouhid;Ovladač myši standardu HID; D:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; D:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-04 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; D:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 nmwcd;Nokia USB Phone Parent; D:\WINDOWS\system32\drivers\ccdcmb.sys [2008-05-02 17536]
S3 sffdisk;Ovladač třídy úložiště SFF; D:\WINDOWS\system32\DRIVERS\sffdisk.sys [2004-08-03 11136]
S3 sffp_sd;Ovladač protokolu úložiště SFF pro paměť sběrnici SDBus; D:\WINDOWS\system32\DRIVERS\sffp_sd.sys [2004-08-03 10240]
S3 SkLaggProtocol;Marvell Link Aggregation Protocol (LAGG) Support; D:\WINDOWS\system32\DRIVERS\yk51lagg.sys []
S3 SkVlanProtocol;Marvell Virtual LAN (VLAN) Support; D:\WINDOWS\system32\DRIVERS\skvlan.sys [2006-05-17 19328]
S3 SLIP;BDA Slip De-Framer; D:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); D:\WINDOWS\system32\DRIVERS\snp2uvc.sys []
S3 streamip;BDA IPSink; D:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 usbprint;Třída USB Printer; D:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; D:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; D:\WINDOWS\System32\Drivers\wpdusb.sys [2004-08-11 18944]
S3 WSTCODEC;Dálnopisný kodek světového standardu; D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACS;Ekahau Configuration Service; D:\WINDOWS\system32\acs.exe [2006-04-19 36864]
R2 avast! Antivirus;avast! Antivirus; D:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-07-03 44808]
R2 btwdins;Bluetooth Service; D:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2006-06-07 266295]
R2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre6\bin\jqs.exe [2008-12-12 152984]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); D:\Program Files\CyberLink\Shared Files\RichVideo.exe [2005-08-08 167936]
R2 Samsung Network Fax Server;Samsung Network Fax Server; D:\WINDOWS\system32\spool\drivers\w32x86\3\NetFaxServer.exe [2009-09-11 162304]
R2 UMWdf;Windows User Mode Driver Framework; D:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S2 gupdate1c996bee849d438;Služba Google Update (gupdate1c996bee849d438); D:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-24 133104]
S3 Adobe LM Service;Adobe LM Service; D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-02-08 72704]
S3 aspnet_state;ASP.NET State Service; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 gupdatem;Služba Google Update (gupdatem); D:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-24 133104]
S3 gusvc;Google Software Updater; D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-12-12 182768]
S3 NMIndexingService;NMIndexingService; D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2006-12-20 262144]
S3 ose;Office Source Engine; D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

-----------------EOF-----------------

Díky!!!

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Preventivka - prosím

#2 Příspěvek od Márty84 »

Zdravim :)

Na logu se pracuje, bude to nejakou dobu trvat.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Preventivka - prosím

#3 Příspěvek od Márty84 »

:!: Delejte to v tomhle poradi.



:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Najdete tento soubor D:\Program Files\trend micro\Maca.exe a spustte ho.
Kliknete na Main menu a na Do a system scan only
U techto radku dejte vlevo zatrzitko

Kód: Vybrat vše

R3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O4 - Startup: Adobe Gamma.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O18 - Protocol: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - (no file)
Kliknete na nápis Fix checked a potvrdte





:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Stahnete OTM http://oldtimer.geekstogo.com/OTM.exe , ulozte nejlepe na plochu a spustte.
Do leveho okna zkopirujte tento skript (vcetne te dvojtecky pred slovem commands)

Kód: Vybrat vše

:commands
[EMPTYTEMP]
[EMPTYFLASH]
[RESETHOSTS]
[Purity]

:services
JavaQuickStarterService
gupdate1c996bee849d438
Adobe LM Service
gupdatem
gusvc
NMIndexingService

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
D:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1801674531-1336601894-839522115-1003.job
D:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1801674531-1336601894-839522115-1003.job
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-1.xml
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-10.xml
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-11.xml
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-2.xml
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-3.xml
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-4.xml
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-5.xml
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-6.xml
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-7.xml
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-8.xml
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-9.xml
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin.xml
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\web-search.xml
D:\Documents and Settings\Maca\Nabídka Start\Programy\Po spuštění\Adobe Gamma.lnk

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{855F3B16-6D32-4fe6-8A56-BBB695989046}"=-
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=-
"QuickTime Task"=-
"TkBellExe"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=-
Kliknete na MoveIt a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu sem dejte log, ktery na vas vyskoci, nebo bude zde C:\_OTM\MovedFiles\xxxxxxxx_xxxxxx (misto tech x budou cisla, predstavujici datum a cas spusteni)





:arrow: Udelejte !!!uplnou!!! kontrolu s MBAM http://forum.viry.cz/viewtopic.php?f=29&t=115222 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Mufff
Návštěvník
Návštěvník
Příspěvky: 92
Registrován: 14 dub 2009 15:12

Re: Preventivka - prosím

#4 Příspěvek od Mufff »

Zdravím - omlouvám se za dvojí log. Nebyl v tom žádný úmysl, jen jsem si myslel, že jsem log vložil do špatné sekce. Tady je lot z OTM:

All processes killed
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Maca
->Temp folder emptied: 167919471 bytes
->Temporary Internet Files folder emptied: 56213277 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 43634991 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 642 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 27437 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 12095706 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 267,00 mb


[EMPTYFLASH]

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: LocalService

User: Maca
->Flash cache emptied: 0 bytes

User: NetworkService

Total Flash Files Cleaned = 0,00 mb

D:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
========== SERVICES/DRIVERS ==========
Service JavaQuickStarterService stopped successfully!
Service JavaQuickStarterService deleted successfully!
Service gupdate1c996bee849d438 stopped successfully!
Service gupdate1c996bee849d438 deleted successfully!
Service Adobe LM Service stopped successfully!
Service Adobe LM Service deleted successfully!
Service gupdatem stopped successfully!
Service gupdatem deleted successfully!
Service gusvc stopped successfully!
Service gusvc deleted successfully!
Service NMIndexingService stopped successfully!
Service NMIndexingService deleted successfully!
========== FILES ==========
File/Folder D:\WINDOWS\system32\*.tmp.dll not found.
File/Folder D:\WINDOWS\system32\SET*.tmp not found.
File/Folder D:\WINDOWS\*.tmp not found.
D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
D:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1801674531-1336601894-839522115-1003.job moved successfully.
D:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1801674531-1336601894-839522115-1003.job moved successfully.
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-1.xml moved successfully.
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-10.xml moved successfully.
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-11.xml moved successfully.
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-2.xml moved successfully.
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-3.xml moved successfully.
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-4.xml moved successfully.
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-5.xml moved successfully.
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-6.xml moved successfully.
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-7.xml moved successfully.
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-8.xml moved successfully.
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin-9.xml moved successfully.
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\icqplugin.xml moved successfully.
D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default\searchplugins\web-search.xml moved successfully.
File/Folder D:\Documents and Settings\Maca\Nabídka Start\Programy\Po spuštění\Adobe Gamma.lnk not found.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{055FD26D-3A88-4e15-963D-DC8493744B1D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{2318C2B1-4965-11d4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\IgfxTray deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\TkBellExe deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\swg deleted successfully.

OTM by OldTimer - Version 3.1.21.0 log created on 08052012_220800

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Preventivka - prosím

#5 Příspěvek od Márty84 »

V poradku :)

OTM provedlo co melo, jeste pockam na MBAM.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Mufff
Návštěvník
Návštěvník
Příspěvky: 92
Registrován: 14 dub 2009 15:12

Re: Preventivka - prosím

#6 Příspěvek od Mufff »

Zdravím!!! MBAM:

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.62.0.1300
www.malwarebytes.org

Verze databáze: v2012.08.05.08

Windows XP Service Pack 2 x86 NTFS
Internet Explorer 7.0.5730.13
Maca :: MARCELA [administrátor]

Ochrana: Povolena

5.8.2012 22:21:06
mbam-log-2012-08-05 (23-26-22).txt

Typ: Úplná kontrola (C:\|D:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 233501
Uplynulý čas: 1 hodin, 18 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 4
HKCR\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (PUP.MyWebSearch) -> Žádná instrukce nebyla provedena.
HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (PUP.MyWebSearch) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Fun Web Products (PUP.MyWebSearch) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (PUP.MyWebSearch) -> Žádná instrukce nebyla provedena.

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Mufff
Návštěvník
Návštěvník
Příspěvky: 92
Registrován: 14 dub 2009 15:12

Re: Preventivka - prosím

#7 Příspěvek od Mufff »

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.62.0.1300
www.malwarebytes.org

Verze databáze: v2012.08.05.08

Windows XP Service Pack 2 x86 NTFS
Internet Explorer 7.0.5730.13
Maca :: MARCELA [administrátor]

Ochrana: Povolena

5.8.2012 22:21:06
mbam-log-2012-08-05 (22-21-06).txt

Typ: Úplná kontrola (C:\|D:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 233501
Uplynulý čas: 1 hodin, 18 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 4
HKCR\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (PUP.MyWebSearch) -> Umístnění do karantény a smazání se zdařilo.
HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (PUP.MyWebSearch) -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Fun Web Products (PUP.MyWebSearch) -> Umístnění do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (PUP.MyWebSearch) -> Umístnění do karantény a smazání se zdařilo.

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Preventivka - prosím

#8 Příspěvek od Márty84 »

:arrow: Polozky nechte odstranit.
:arrow: Pak MBAM odinstalujte.
:arrow: Dejte novy log z RSIT.
:arrow: Napiste jak je na tom pc. Byla to ciste jen prevence, nebo je s pc nejaky problem?
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Mufff
Návštěvník
Návštěvník
Příspěvky: 92
Registrován: 14 dub 2009 15:12

Re: Preventivka - prosím

#9 Příspěvek od Mufff »

Zdravím - PC se tváří fajn. Šlo spíše o preventivku, ale komp je celkově dost zasekanej - všechno začalo dost trvat za poslední měsíc, takže proto moje žádost o pomoc. Níže posílám finální log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Maca at 2012-08-05 23:42:39
Systém Microsoft Windows XP Professional Service Pack 2
System drive D: has 21 GB (56%) free of 38 GB
Total RAM: 1014 MB (41% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:42:46, on 5.8.2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\AVAST Software\Avast\AvastSvc.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\acs.exe
D:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
D:\WINDOWS\system32\hkcmd.exe
D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
D:\WINDOWS\system32\igfxpers.exe
D:\WINDOWS\RTHDCPL.EXE
D:\WINDOWS\AGRSMMSG.exe
D:\Program Files\Synaptics\SynTP\SynTPEnh.exe
D:\Program Files\BenQ\BenQ Surround\BenQSurround.exe
D:\Program Files\BenQ\Q-HotkeyMgr\HotkeySensor.exe
D:\Program Files\Ekahau\Ekahau Wireless Utility\ACU.exe
D:\Program Files\Notebook Hardware Control\nhc.exe
D:\WINDOWS\system32\igfxsrvc.exe
D:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
D:\WINDOWS\Twain_32\Samsung\SCX4623\Scan2pc.exe
D:\Program Files\AVAST Software\Avast\avastUI.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
D:\Program Files\CyberLink\Shared Files\RichVideo.exe
D:\WINDOWS\system32\spool\drivers\w32x86\3\NetFaxServer.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\internet explorer\iexplore.exe
D:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
D:\Documents and Settings\Maca\Local Settings\Temporary Internet Files\Content.IE5\IKQA320H\RSIT[1].exe
D:\Program Files\Trend Micro\Maca.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [HotKeysCmds] D:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] D:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPEnh] D:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BenQSurround] D:\Program Files\BenQ\BenQ Surround\BenQSurround.exe
O4 - HKLM\..\Run: [Q-HotkeyMgr] "D:\Program Files\BenQ\Q-HotkeyMgr\HotkeySensor.exe"
O4 - HKLM\..\Run: [ACU] "D:\Program Files\Ekahau\Ekahau Wireless Utility\ACU.exe" -nogui
O4 - HKLM\..\Run: [NotebookHardwareControl] "D:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [Samsung PanelMgr] D:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
O4 - HKLM\..\Run: [4623 Scan2PC] "D:\WINDOWS\Twain_32\Samsung\SCX4623\Scan2pc.exe"
O4 - HKLM\..\Run: [avast] "D:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 7934784652
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: Ekahau Configuration Service (ACS) - Unknown owner - D:\WINDOWS\system32\acs.exe
O23 - Service: avast! Antivirus - AVAST Software - D:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - D:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - D:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Samsung Network Fax Server - Unknown owner - D:\WINDOWS\system32\spool\drivers\w32x86\3\NetFaxServer.exe

--
End of file - 7984 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\avast! Emergency Update.job

=========Mozilla firefox=========

ProfilePath - D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "extensions.enabledItems" - "wrc@avast.com:7.0.1456, {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11, jqs@sun.com:1.0, {ABDE892B-13A8-4d1b-88E6-365A6E755758}:15.0.1, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.19"

"jqs@sun.com"=D:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"=D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
"wrc@avast.com"=D:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=D:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=D:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pack.google.com/Google Updater;version=13]
"Description"=Google Updater
"Path"=D:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=D:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13]
"Description"=RealJukebox Netscape Plugin
"Path"=D:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13]
"Description"=RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In
"Path"=D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13]
"Description"=15.0.1.13
"Path"=D:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

D:\Program Files\Mozilla Firefox\extensions\
{800b5000-a755-47e1-992b-48a1c1357f07}
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

D:\Program Files\Mozilla Firefox\components\
aboutRights.js
aboutRobots.js
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
jsconsole-clhandler.js
nppl3260.xpt
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsHandlerService.js
nsHelperAppDlg.js
nsIQTScriptablePlugin.xpt
nsjsrealplayerplugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesTransactionsService.js
nsPostUpdateWin.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
txEXSLTRegExFunctions.js
WebContentConverter.js

D:\Program Files\Mozilla Firefox\plugins\
npdeploytk.dll
npnul32.dll
nppl3260.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprjplug.dll
nprpjplug.dll
QuickTimePlugin.class

D:\Program Files\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2012-01-15 425680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - D:\Program Files\Java\jre6\bin\ssv.dll [2008-12-12 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-07-03 1160792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-12 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-12 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-07-03 1160792]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"=D:\WINDOWS\system32\hkcmd.exe [2008-04-05 162584]
"Persistence"=D:\WINDOWS\system32\igfxpers.exe [2008-04-05 138008]
"RTHDCPL"=D:\WINDOWS\RTHDCPL.EXE [2007-07-05 16380416]
"AGRSMMSG"=D:\WINDOWS\AGRSMMSG.exe [2008-04-05 88363]
"SynTPEnh"=D:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-04-19 861744]
"BenQSurround"=D:\Program Files\BenQ\BenQ Surround\BenQSurround.exe [2007-04-20 1187840]
"Q-HotkeyMgr"=D:\Program Files\BenQ\Q-HotkeyMgr\HotkeySensor.exe [2007-03-22 237673]
"ACU"=D:\Program Files\Ekahau\Ekahau Wireless Utility\ACU.exe [2006-05-09 303104]
"NotebookHardwareControl"=D:\Program Files\Notebook Hardware Control\nhc.exe [2007-05-04 2629632]
"Samsung PanelMgr"=D:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe [2009-08-14 614400]
"4623 Scan2PC"=D:\WINDOWS\Twain_32\Samsung\SCX4623\Scan2pc.exe [2009-09-10 1968640]
"avast"=D:\Program Files\AVAST Software\Avast\avastUI.exe [2012-07-03 4273976]
"QuickTime Task"=D:\Program Files\QuickTime\qttask.exe [2008-03-28 413696]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

D:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - D:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
D:\WINDOWS\system32\igfxdev.dll [2008-04-05 204800]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe"="D:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup"
"D:\Program Files\WIP Miranda IM 1.7\miranda32.exe"="D:\Program Files\WIP Miranda IM 1.7\miranda32.exe:*:Enabled:Miranda IM"
"D:\Program Files\WIP Miranda IM 1.7.3\miranda32.exe"="D:\Program Files\WIP Miranda IM 1.7.3\miranda32.exe:*:Enabled:Miranda IM"
"D:\Program Files\Skype\Plugin Manager\skypePM.exe"="D:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"D:\WINDOWS\twain_32\Samsung\ScanMgr.exe"="D:\WINDOWS\twain_32\Samsung\ScanMgr.exe:*:Enabled:Scan Manger"
"D:\WINDOWS\twain_32\Samsung\SCX4623\Scan2Pc.exe"="D:\WINDOWS\twain_32\Samsung\SCX4623\Scan2Pc.exe:*:Enabled:ScanToPC"
"D:\WINDOWS\twain_32\Samsung\SCX4623\Sscan2io.exe"="D:\WINDOWS\twain_32\Samsung\SCX4623\Sscan2io.exe:*:Enabled:SScanToIO"
"D:\Program Files\ICQ7.4\ICQ.exe"="D:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"
"D:\Program Files\BitLord2\BitLord.exe"="D:\Program Files\BitLord2\BitLord.exe:*:Enabled:Bitlord2"
"D:\Program Files\Skype\Phone\Skype.exe"="D:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
"D:\Program Files\Google\Google Earth\plugin\geplugin.exe"="D:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\ICQ7.4\ICQ.exe"="D:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=D:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=D:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-09-12 23:06:29 ----A---- D:\WINDOWS\system32\drivers\aswFsBlk.sys
2012-09-12 23:06:28 ----A---- D:\WINDOWS\system32\drivers\aswSP.sys
2012-09-12 23:06:26 ----A---- D:\WINDOWS\system32\drivers\aswTdi.sys
2012-09-12 23:06:26 ----A---- D:\WINDOWS\system32\drivers\aswRdr.sys
2012-09-12 23:06:25 ----A---- D:\WINDOWS\system32\drivers\aswSnx.sys
2012-09-12 23:06:25 ----A---- D:\WINDOWS\system32\drivers\aswmon2.sys
2012-09-12 23:06:25 ----A---- D:\WINDOWS\system32\drivers\aswmon.sys
2012-09-12 23:06:24 ----A---- D:\WINDOWS\system32\drivers\aavmker4.sys
2012-09-12 23:06:17 ----SHD---- D:\Config.Msi
2012-09-12 23:05:51 ----A---- D:\WINDOWS\avastSS.scr
2012-09-12 23:05:50 ----A---- D:\WINDOWS\system32\aswBoot.exe
2012-09-12 23:05:32 ----D---- D:\Program Files\AVAST Software
2012-08-23 21:10:45 ----A---- D:\WINDOWS\system32\systeminfo.dll
2012-08-23 21:10:35 ----D---- D:\Documents and Settings\All Users\Data aplikací\BlazeVideo
2012-08-23 21:10:32 ----A---- D:\WINDOWS\system32\psisdecd.dll
2012-08-23 21:10:18 ----D---- D:\Program Files\BlazeVideo
2012-08-05 22:19:40 ----D---- D:\Documents and Settings\Maca\Data aplikací\Malwarebytes
2012-08-05 22:19:25 ----D---- D:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2012-08-05 22:08:00 ----D---- D:\_OTM
2012-08-03 21:44:42 ----D---- D:\rsit
2012-07-20 21:10:30 ----D---- D:\D2VAVS
2012-07-20 21:10:08 ----D---- D:\Ripp
2012-07-20 21:09:00 ----A---- D:\Rebuilder.ini
2012-07-20 21:09:00 ----A---- D:\Installer.txt
2012-07-20 21:08:10 ----A---- D:\info.txt
2012-07-20 21:08:07 ----D---- D:\Program Files\DVD-RB
2012-07-20 21:07:16 ----D---- D:\Program Files\AviSynth 2.5

======List of files/folders modified in the last 1 month======

2012-09-12 23:06:19 ----D---- D:\WINDOWS\WinSxS
2012-09-12 23:05:32 ----D---- D:\Documents and Settings\All Users\Data aplikací\AVAST Software
2012-08-23 21:10:49 ----RSHDC---- D:\WINDOWS\system32\dllcache
2012-08-05 23:42:42 ----D---- D:\Program Files\Trend Micro
2012-08-05 23:40:40 ----D---- D:\WINDOWS\Temp
2012-08-05 23:39:43 ----RD---- D:\Program Files
2012-08-05 23:38:28 ----A---- D:\WINDOWS\SchedLgU.Txt
2012-08-05 23:37:22 ----D---- D:\WINDOWS\system32\drivers
2012-08-05 23:37:22 ----D---- D:\WINDOWS\Prefetch
2012-08-05 22:27:48 ----D---- D:\WINDOWS\Microsoft.NET
2012-08-05 22:09:29 ----D---- D:\WINDOWS\system32\CatRoot2
2012-08-05 22:08:49 ----SD---- D:\WINDOWS\Tasks
2012-08-05 22:08:45 ----D---- D:\WINDOWS\system32\drivers\etc
2012-08-04 08:41:27 ----D---- D:\WINDOWS
2012-08-03 20:37:44 ----D---- D:\Program Files\Mozilla Firefox
2012-08-03 09:45:54 ----D---- D:\WINDOWS\system32
2012-08-03 09:41:51 ----D---- D:\WINDOWS\Minidump
2012-07-29 18:06:23 ----D---- D:\WINDOWS\Help
2012-07-27 21:50:39 ----A---- D:\WINDOWS\NeroDigital.ini
2012-07-26 13:11:51 ----D---- D:\Documents and Settings\Maca\Data aplikací\Skype
2012-07-25 20:09:00 ----D---- D:\Documents and Settings\Maca\Data aplikací\ICQ
2012-07-20 21:02:43 ----D---- D:\Program Files\DVD Shrink
2012-07-19 16:29:11 ----SHD---- D:\WINDOWS\Installer
2012-07-10 05:47:55 ----HD---- D:\WINDOWS\inf

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI; D:\WINDOWS\system32\DRIVERS\ohci1394.sys [2004-08-03 61056]
R0 PxHelp20;PxHelp20; D:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R1 Aavmker4;avast! Asynchronous Virus Monitor; D:\WINDOWS\system32\drivers\Aavmker4.sys [2012-07-03 25256]
R1 AswRdr;aswRdr; D:\WINDOWS\system32\drivers\AswRdr.sys [2012-07-03 35928]
R1 aswSnx;aswSnx; D:\WINDOWS\system32\drivers\aswSnx.sys [2012-07-03 721000]
R1 aswSP;aswSP; D:\WINDOWS\system32\drivers\aswSP.sys [2012-07-03 353688]
R1 aswTdi;avast! Network Shield Support; D:\WINDOWS\system32\drivers\aswTdi.sys [2012-07-03 54232]
R1 intelppm;Řadič procesoru Intel; D:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-17 39936]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.10.0; D:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-04-11 21275]
R2 aswFsBlk;aswFsBlk; D:\WINDOWS\system32\drivers\aswFsBlk.sys [2012-07-03 21256]
R2 aswMon2;avast! Standard Shield Support; D:\WINDOWS\system32\drivers\aswMon2.sys [2012-07-03 97608]
R2 QBIOSIo;QBIOSIo.dll; D:\WINDOWS\system32\QBIOSIo.dll [2007-01-20 11520]
R3 AgereSoftModem;Agere Systems Soft Modem; D:\WINDOWS\system32\DRIVERS\AGRSM.sys [2008-04-05 1270540]
R3 AR5211;Atheros Wireless Network Adapter Service; D:\WINDOWS\system32\DRIVERS\ar5211.sys [2006-10-20 478432]
R3 Arp1394;Protokol 1394 ARP Client; D:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-17 60800]
R3 btaudio;Bluetooth Audio Device; D:\WINDOWS\system32\drivers\btaudio.sys [2006-06-07 329901]
R3 btkrnl;Bluetooth Bus Enumerator; D:\WINDOWS\system32\DRIVERS\btkrnl.sys [2006-06-07 855018]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 ialm;ialm; D:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-04-05 5700096]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); D:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-07-10 4449280]
R3 nhcDriverDevice;Notebook Hardware Control Driver; \??\D:\WINDOWS\system32\drivers\nhcDriver.sys []
R3 NIC1394;1394 Net Driver; D:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
R3 rimmptsk;rimmptsk; D:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2005-11-16 28928]
R3 rimsptsk;rimsptsk; D:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2006-09-08 51328]
R3 rismxdp;Ricoh xD-Picture Card Driver; D:\WINDOWS\system32\DRIVERS\rixdptsk.sys [2005-11-01 308992]
R3 sdbus;sdbus; D:\WINDOWS\system32\DRIVERS\sdbus.sys [2004-08-03 67584]
R3 SynTP;Synaptics TouchPad Driver; D:\WINDOWS\system32\DRIVERS\SynTP.sys [2007-04-19 186552]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; D:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 usbvideo;Zobrazovací zařízení USB (WDM); D:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-04 78464]
R3 Wdf01000;Wdf01000; D:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; D:\WINDOWS\system32\DRIVERS\yk51x86.sys [2006-11-22 250496]
S1 kbdhid;Ovladač klávesnice standardu HID; D:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
S2 DgiVecp;DgiVecp; \??\D:\WINDOWS\system32\Drivers\DgiVecp.sys []
S2 SSPORT;SSPORT; \??\D:\WINDOWS\system32\Drivers\SSPORT.sys []
S3 BTDriver;Bluetooth Virtual Communications Driver; D:\WINDOWS\system32\DRIVERS\btport.sys [2006-06-07 30459]
S3 BTWDNDIS;Bluetooth LAN Access Server; D:\WINDOWS\system32\DRIVERS\btwdndis.sys [2006-06-07 149028]
S3 btwhid;btwhid; D:\WINDOWS\system32\DRIVERS\btwhid.sys [2006-06-07 47811]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; D:\WINDOWS\System32\Drivers\btwusb.sys [2006-06-07 67384]
S3 CCDECODE;Dekodér Closed Caption; D:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 HidUsb;Ovladač třídy standardu HID; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 ipw_bus;IPWireless; D:\WINDOWS\system32\DRIVERS\ipw_bus.sys []
S3 ipw_mdfl;Wireless Broadband Modem Filter; D:\WINDOWS\system32\DRIVERS\ipw_mdfl.sys []
S3 ipw_mdm;Wireless Broadband Modem (WDM); D:\WINDOWS\system32\DRIVERS\ipw_mdm.sys []
S3 IpwP;IPWireless 3G Network Adapter; D:\WINDOWS\system32\DRIVERS\ipw3gnet.sys [2008-10-10 51040]
S3 mouhid;Ovladač myši standardu HID; D:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; D:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-04 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; D:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 nmwcd;Nokia USB Phone Parent; D:\WINDOWS\system32\drivers\ccdcmb.sys [2008-05-02 17536]
S3 sffdisk;Ovladač třídy úložiště SFF; D:\WINDOWS\system32\DRIVERS\sffdisk.sys [2004-08-03 11136]
S3 sffp_sd;Ovladač protokolu úložiště SFF pro paměť sběrnici SDBus; D:\WINDOWS\system32\DRIVERS\sffp_sd.sys [2004-08-03 10240]
S3 SkLaggProtocol;Marvell Link Aggregation Protocol (LAGG) Support; D:\WINDOWS\system32\DRIVERS\yk51lagg.sys []
S3 SkVlanProtocol;Marvell Virtual LAN (VLAN) Support; D:\WINDOWS\system32\DRIVERS\skvlan.sys [2006-05-17 19328]
S3 SLIP;BDA Slip De-Framer; D:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); D:\WINDOWS\system32\DRIVERS\snp2uvc.sys []
S3 streamip;BDA IPSink; D:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 usbprint;Třída USB Printer; D:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; D:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; D:\WINDOWS\System32\Drivers\wpdusb.sys [2004-08-11 18944]
S3 WSTCODEC;Dálnopisný kodek světového standardu; D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACS;Ekahau Configuration Service; D:\WINDOWS\system32\acs.exe [2006-04-19 36864]
R2 avast! Antivirus;avast! Antivirus; D:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-07-03 44808]
R2 btwdins;Bluetooth Service; D:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2006-06-07 266295]
R2 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); D:\Program Files\CyberLink\Shared Files\RichVideo.exe [2005-08-08 167936]
R2 Samsung Network Fax Server;Samsung Network Fax Server; D:\WINDOWS\system32\spool\drivers\w32x86\3\NetFaxServer.exe [2009-09-11 162304]
R2 UMWdf;Windows User Mode Driver Framework; D:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S3 aspnet_state;ASP.NET State Service; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 ose;Office Source Engine; D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Preventivka - prosím

#10 Příspěvek od Márty84 »

:arrow: Nainstalujte Service Pack 3 a aktualizujte Internet Explorer na verzi 8



:arrow: Stahnete OTC http://oldtimer.geekstogo.com/OTC.exe , ulozte a spustte.
Kliknete na napis CleanUp a pote OK - Po uklidu dojde k restartu pc.

:arrow: Stahnete TFC http://oldtimer.geekstogo.com/TFC.exe , ulozte a spustte
Kliknete na START a pote OK - Po uklidu dojde k restartu pc.
Po pouziti muzete programek smazat

:arrow: Stahnete Ccleaner http://www.stahuj.centrum.cz/utility_a_ ... /ccleaner/ a spustte.
Pri instalaci pozor na toolbar, jestli vam nabidne jeho instalaci, tak zruste zatrzitko.
Po spusteni se ocitnete ve funkci Cistic. Vlevo je spousta zatrzitek. Pozor dejte hlavne na kos, pokud nechate zatrzene, vzdy ho vysype.
Dale, podle toho jak je nastaven, smaze vsechna hesla ulozena na netu!!! Takze jestli mate nastavene, at si pocitac hesla pamatuje (coz neni pro bezpecnost dobre), budete je muset pak napsat znova rucne (napr mail, facebook, ruzna fora atd.)
Kliknete na Analyzovat a az dokonci analyzu, kliknete na Spustit Cleaner.
Potom kliknete vlevo na funkci Registry
Kliknete na Hledej problemy, kdyz najde, kliknete na Opravit problemy. Nabidne Vam zalohu, tu udelejte a ulozte ji tak, at ji v pripade potreby najdete :)
Funkce Nastroje umoznuje odinstalovani programu. Je dukladnejsi nez samotny windows!

:arrow: Defragmentujte disk
Stahnete napriklad program Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
Pri instalaci opet pozor na toolbar
Po nainstalovani program spustte a kliknete na Analyzovat, po analyze kliknete na Defragmentovat a programek odvede svou praci :)



Az vse provedete, napiste, zda se to zlepsilo
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Mufff
Návštěvník
Návštěvník
Příspěvky: 92
Registrován: 14 dub 2009 15:12

Re: Preventivka - prosím

#11 Příspěvek od Mufff »

Zdravím. Omlouvám se, ale chvíli to trvalo, než jsem to zvládl... Komp vypadá daleko lépe. Věřím, že to snad vydrží. Moc díky. Pro jistotu přikládám ještě RSIT log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Maca at 2012-08-07 08:28:22
Systém Microsoft Windows XP Professional Service Pack 3
System drive D: has 20 GB (53%) free of 38 GB
Total RAM: 1014 MB (39% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:28:36, on 7.8.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\AVAST Software\Avast\AvastSvc.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\acs.exe
D:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\CyberLink\Shared Files\RichVideo.exe
D:\WINDOWS\system32\spool\drivers\w32x86\3\NetFaxServer.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\hkcmd.exe
D:\WINDOWS\system32\igfxpers.exe
D:\WINDOWS\system32\igfxsrvc.exe
D:\WINDOWS\RTHDCPL.EXE
D:\WINDOWS\AGRSMMSG.exe
D:\Program Files\Synaptics\SynTP\SynTPEnh.exe
D:\Program Files\BenQ\BenQ Surround\BenQSurround.exe
D:\Program Files\BenQ\Q-HotkeyMgr\HotkeySensor.exe
D:\Program Files\Ekahau\Ekahau Wireless Utility\ACU.exe
D:\Program Files\Notebook Hardware Control\nhc.exe
D:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
D:\WINDOWS\Twain_32\Samsung\SCX4623\Scan2pc.exe
D:\Program Files\AVAST Software\Avast\avastUI.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
D:\Program Files\internet explorer\iexplore.exe
D:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
D:\Documents and Settings\Maca\Local Settings\Temporary Internet Files\Content.IE5\D08W5112\RSIT[1].exe
D:\Program Files\Trend Micro\Maca.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [HotKeysCmds] D:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] D:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPEnh] D:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BenQSurround] D:\Program Files\BenQ\BenQ Surround\BenQSurround.exe
O4 - HKLM\..\Run: [Q-HotkeyMgr] "D:\Program Files\BenQ\Q-HotkeyMgr\HotkeySensor.exe"
O4 - HKLM\..\Run: [ACU] "D:\Program Files\Ekahau\Ekahau Wireless Utility\ACU.exe" -nogui
O4 - HKLM\..\Run: [NotebookHardwareControl] "D:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [Samsung PanelMgr] D:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
O4 - HKLM\..\Run: [4623 Scan2PC] "D:\WINDOWS\Twain_32\Samsung\SCX4623\Scan2pc.exe"
O4 - HKLM\..\Run: [avast] "D:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 7934784652
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: Ekahau Configuration Service (ACS) - Unknown owner - D:\WINDOWS\system32\acs.exe
O23 - Service: avast! Antivirus - AVAST Software - D:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - D:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - D:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Samsung Network Fax Server - Unknown owner - D:\WINDOWS\system32\spool\drivers\w32x86\3\NetFaxServer.exe

--
End of file - 7923 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\avast! Emergency Update.job

=========Mozilla firefox=========

ProfilePath - D:\Documents and Settings\Maca\Data aplikací\Mozilla\Firefox\Profiles\wi28r37z.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "extensions.enabledItems" - "wrc@avast.com:7.0.1456, {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11, jqs@sun.com:1.0, {ABDE892B-13A8-4d1b-88E6-365A6E755758}:15.0.1, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.19"

"jqs@sun.com"=D:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"=D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
"wrc@avast.com"=D:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=D:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=D:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pack.google.com/Google Updater;version=13]
"Description"=Google Updater
"Path"=D:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=D:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13]
"Description"=RealJukebox Netscape Plugin
"Path"=D:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13]
"Description"=RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In
"Path"=D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13]
"Description"=15.0.1.13
"Path"=D:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

D:\Program Files\Mozilla Firefox\extensions\
{800b5000-a755-47e1-992b-48a1c1357f07}
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

D:\Program Files\Mozilla Firefox\components\
aboutRights.js
aboutRobots.js
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
jsconsole-clhandler.js
nppl3260.xpt
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsHandlerService.js
nsHelperAppDlg.js
nsIQTScriptablePlugin.xpt
nsjsrealplayerplugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesTransactionsService.js
nsPostUpdateWin.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
txEXSLTRegExFunctions.js
WebContentConverter.js

D:\Program Files\Mozilla Firefox\plugins\
npdeploytk.dll
npnul32.dll
nppl3260.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprjplug.dll
nprpjplug.dll
QuickTimePlugin.class

D:\Program Files\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2012-01-15 425680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - D:\Program Files\Java\jre6\bin\ssv.dll [2008-12-12 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-07-03 1160792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-12 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-12 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-07-03 1160792]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"=D:\WINDOWS\system32\hkcmd.exe [2008-04-05 162584]
"Persistence"=D:\WINDOWS\system32\igfxpers.exe [2008-04-05 138008]
"RTHDCPL"=D:\WINDOWS\RTHDCPL.EXE [2007-07-05 16380416]
"AGRSMMSG"=D:\WINDOWS\AGRSMMSG.exe [2008-04-05 88363]
"SynTPEnh"=D:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-04-19 861744]
"BenQSurround"=D:\Program Files\BenQ\BenQ Surround\BenQSurround.exe [2007-04-20 1187840]
"Q-HotkeyMgr"=D:\Program Files\BenQ\Q-HotkeyMgr\HotkeySensor.exe [2007-03-22 237673]
"ACU"=D:\Program Files\Ekahau\Ekahau Wireless Utility\ACU.exe [2006-05-09 303104]
"NotebookHardwareControl"=D:\Program Files\Notebook Hardware Control\nhc.exe [2007-05-04 2629632]
"Samsung PanelMgr"=D:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe [2009-08-14 614400]
"4623 Scan2PC"=D:\WINDOWS\Twain_32\Samsung\SCX4623\Scan2pc.exe [2009-09-10 1968640]
"avast"=D:\Program Files\AVAST Software\Avast\avastUI.exe [2012-07-03 4273976]
"QuickTime Task"=D:\Program Files\QuickTime\qttask.exe [2008-03-28 413696]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

D:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - D:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
D:\WINDOWS\system32\igfxdev.dll [2008-04-05 204800]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe"="D:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup"
"D:\Program Files\WIP Miranda IM 1.7\miranda32.exe"="D:\Program Files\WIP Miranda IM 1.7\miranda32.exe:*:Enabled:Miranda IM"
"D:\Program Files\WIP Miranda IM 1.7.3\miranda32.exe"="D:\Program Files\WIP Miranda IM 1.7.3\miranda32.exe:*:Enabled:Miranda IM"
"D:\Program Files\Skype\Plugin Manager\skypePM.exe"="D:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"D:\WINDOWS\twain_32\Samsung\ScanMgr.exe"="D:\WINDOWS\twain_32\Samsung\ScanMgr.exe:*:Enabled:Scan Manger"
"D:\WINDOWS\twain_32\Samsung\SCX4623\Scan2Pc.exe"="D:\WINDOWS\twain_32\Samsung\SCX4623\Scan2Pc.exe:*:Enabled:ScanToPC"
"D:\WINDOWS\twain_32\Samsung\SCX4623\Sscan2io.exe"="D:\WINDOWS\twain_32\Samsung\SCX4623\Sscan2io.exe:*:Enabled:SScanToIO"
"D:\Program Files\ICQ7.4\ICQ.exe"="D:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"
"D:\Program Files\BitLord2\BitLord.exe"="D:\Program Files\BitLord2\BitLord.exe:*:Enabled:Bitlord2"
"D:\Program Files\Skype\Phone\Skype.exe"="D:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
"D:\Program Files\Google\Google Earth\plugin\geplugin.exe"="D:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\ICQ7.4\ICQ.exe"="D:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=D:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=D:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-09-12 23:06:29 ----A---- D:\WINDOWS\system32\drivers\aswFsBlk.sys
2012-09-12 23:06:28 ----A---- D:\WINDOWS\system32\drivers\aswSP.sys
2012-09-12 23:06:26 ----A---- D:\WINDOWS\system32\drivers\aswTdi.sys
2012-09-12 23:06:26 ----A---- D:\WINDOWS\system32\drivers\aswRdr.sys
2012-09-12 23:06:25 ----A---- D:\WINDOWS\system32\drivers\aswSnx.sys
2012-09-12 23:06:25 ----A---- D:\WINDOWS\system32\drivers\aswmon2.sys
2012-09-12 23:06:25 ----A---- D:\WINDOWS\system32\drivers\aswmon.sys
2012-09-12 23:06:24 ----A---- D:\WINDOWS\system32\drivers\aavmker4.sys
2012-09-12 23:06:17 ----SHD---- D:\Config.Msi
2012-09-12 23:05:51 ----A---- D:\WINDOWS\avastSS.scr
2012-09-12 23:05:50 ----A---- D:\WINDOWS\system32\aswBoot.exe
2012-09-12 23:05:32 ----D---- D:\Program Files\AVAST Software
2012-08-23 21:10:45 ----A---- D:\WINDOWS\system32\systeminfo.dll
2012-08-23 21:10:35 ----D---- D:\Documents and Settings\All Users\Data aplikací\BlazeVideo
2012-08-23 21:10:32 ----A---- D:\WINDOWS\system32\psisdecd.dll
2012-08-23 21:10:18 ----D---- D:\Program Files\BlazeVideo
2012-08-07 08:28:22 ----D---- D:\rsit
2012-08-06 22:01:01 ----D---- D:\Program Files\Defraggler
2012-08-06 21:51:31 ----A---- D:\WINDOWS\system32\wmpns.dll
2012-08-06 21:50:44 ----D---- D:\WINDOWS\Prefetch
2012-08-06 21:43:13 ----HDC---- D:\WINDOWS\$NtUninstallKB967715$
2012-08-06 21:43:05 ----HDC---- D:\WINDOWS\$NtUninstallKB960225$
2012-08-06 21:42:58 ----HDC---- D:\WINDOWS\$NtUninstallKB958690$
2012-08-06 21:42:51 ----HDC---- D:\WINDOWS\$NtUninstallKB958687$
2012-08-06 21:42:44 ----HDC---- D:\WINDOWS\$NtUninstallKB958644$
2012-08-06 21:42:37 ----HDC---- D:\WINDOWS\$NtUninstallKB957097$
2012-08-06 21:42:31 ----HDC---- D:\WINDOWS\$NtUninstallKB957095$
2012-08-06 21:42:22 ----HDC---- D:\WINDOWS\$NtUninstallKB956841$
2012-08-06 21:42:14 ----HDC---- D:\WINDOWS\$NtUninstallKB956803$
2012-08-06 21:42:08 ----HDC---- D:\WINDOWS\$NtUninstallKB956802$
2012-08-06 21:41:58 ----HDC---- D:\WINDOWS\$NtUninstallKB955069$
2012-08-06 21:41:51 ----HDC---- D:\WINDOWS\$NtUninstallKB954600$
2012-08-06 21:41:44 ----HDC---- D:\WINDOWS\$NtUninstallKB954211$
2012-08-06 21:41:35 ----HDC---- D:\WINDOWS\$NtUninstallKB952954$
2012-08-06 21:41:27 ----HDC---- D:\WINDOWS\$NtUninstallKB952287$
2012-08-06 21:41:20 ----HDC---- D:\WINDOWS\$NtUninstallKB951748$
2012-08-06 21:41:12 ----HDC---- D:\WINDOWS\$NtUninstallKB951698$
2012-08-06 21:41:06 ----HDC---- D:\WINDOWS\$NtUninstallKB951376-v2$
2012-08-06 21:40:59 ----HDC---- D:\WINDOWS\$NtUninstallKB951376$
2012-08-06 21:40:50 ----HDC---- D:\WINDOWS\$NtUninstallKB951066$
2012-08-06 21:40:43 ----HDC---- D:\WINDOWS\$NtUninstallKB950974$
2012-08-06 21:40:36 ----HDC---- D:\WINDOWS\$NtUninstallKB950762$
2012-08-06 21:40:29 ----HDC---- D:\WINDOWS\$NtUninstallKB946648$
2012-08-06 21:40:18 ----HDC---- D:\WINDOWS\$NtUninstallKB938464$
2012-08-06 21:36:09 ----N---- D:\WINDOWS\system32\smtpapi.dll
2012-08-06 21:36:09 ----N---- D:\WINDOWS\system32\rwnh.dll
2012-08-06 21:36:09 ----N---- D:\WINDOWS\system32\drivers\irbus.sys
2012-08-06 21:36:09 ----N---- D:\WINDOWS\system32\comsdupd.exe
2012-08-06 21:36:06 ----N---- D:\WINDOWS\system32\ati3d1ag.dll
2012-08-06 21:36:06 ----N---- D:\WINDOWS\system32\ati2dvag.dll
2012-08-06 21:36:06 ----N---- D:\WINDOWS\system32\ati2dvaa.dll
2012-08-06 21:36:06 ----N---- D:\WINDOWS\system32\ati2cqag.dll
2012-08-06 21:36:06 ----N---- D:\WINDOWS\system32\aaclient.dll
2012-08-06 21:36:05 ----N---- D:\WINDOWS\system32\bitsprx4.dll
2012-08-06 21:36:05 ----N---- D:\WINDOWS\system32\azroles.dll
2012-08-06 21:36:05 ----N---- D:\WINDOWS\system32\ativvaxx.dll
2012-08-06 21:36:05 ----N---- D:\WINDOWS\system32\ativtmxx.dll
2012-08-06 21:36:05 ----N---- D:\WINDOWS\system32\ati3duag.dll
2012-08-06 21:36:04 ----N---- D:\WINDOWS\system32\eapp3hst.dll
2012-08-06 21:36:04 ----N---- D:\WINDOWS\system32\eapolqec.dll
2012-08-06 21:36:04 ----N---- D:\WINDOWS\system32\dot3ui.dll
2012-08-06 21:36:04 ----N---- D:\WINDOWS\system32\dot3svc.dll
2012-08-06 21:36:04 ----N---- D:\WINDOWS\system32\dot3msm.dll
2012-08-06 21:36:04 ----N---- D:\WINDOWS\system32\dot3gpclnt.dll
2012-08-06 21:36:04 ----N---- D:\WINDOWS\system32\dot3dlg.dll
2012-08-06 21:36:04 ----N---- D:\WINDOWS\system32\dot3cfg.dll
2012-08-06 21:36:04 ----N---- D:\WINDOWS\system32\dot3api.dll
2012-08-06 21:36:04 ----N---- D:\WINDOWS\system32\dimsroam.dll
2012-08-06 21:36:04 ----N---- D:\WINDOWS\system32\dimsntfy.dll
2012-08-06 21:36:04 ----N---- D:\WINDOWS\system32\dhcpqec.dll
2012-08-06 21:36:04 ----N---- D:\WINDOWS\system32\credssp.dll
2012-08-06 21:36:03 ----N---- D:\WINDOWS\system32\eapsvc.dll
2012-08-06 21:36:03 ----N---- D:\WINDOWS\system32\eapqec.dll
2012-08-06 21:36:03 ----N---- D:\WINDOWS\system32\eappprxy.dll
2012-08-06 21:36:03 ----N---- D:\WINDOWS\system32\eapphost.dll
2012-08-06 21:36:03 ----N---- D:\WINDOWS\system32\eappgnui.dll
2012-08-06 21:36:03 ----N---- D:\WINDOWS\system32\eappcfg.dll
2012-08-06 21:36:02 ----N---- D:\WINDOWS\system32\hsfcisp2.dll
2012-08-06 21:36:01 ----N---- D:\WINDOWS\system32\l2gpstore.dll
2012-08-06 21:36:01 ----N---- D:\WINDOWS\system32\kmsvc.dll
2012-08-06 21:36:01 ----N---- D:\WINDOWS\system32\kbdpash.dll
2012-08-06 21:36:01 ----N---- D:\WINDOWS\system32\kbdnepr.dll
2012-08-06 21:36:01 ----N---- D:\WINDOWS\system32\kbdiultn.dll
2012-08-06 21:36:01 ----N---- D:\WINDOWS\system32\kbdbhc.dll
2012-08-06 21:36:00 ----N---- D:\WINDOWS\system32\mmcperf.exe
2012-08-06 21:36:00 ----N---- D:\WINDOWS\system32\mmcfxcommon.dll
2012-08-06 21:36:00 ----N---- D:\WINDOWS\system32\mmcex.dll
2012-08-06 21:36:00 ----N---- D:\WINDOWS\system32\microsoft.managementconsole.dll
2012-08-06 21:36:00 ----N---- D:\WINDOWS\system32\mdmxsdk.dll
2012-08-06 21:35:59 ----N---- D:\WINDOWS\system32\onex.dll
2012-08-06 21:35:59 ----N---- D:\WINDOWS\system32\nv4_disp.dll
2012-08-06 21:35:59 ----N---- D:\WINDOWS\system32\napstat.exe
2012-08-06 21:35:59 ----N---- D:\WINDOWS\system32\napmontr.dll
2012-08-06 21:35:59 ----N---- D:\WINDOWS\system32\napipsec.dll
2012-08-06 21:35:59 ----N---- D:\WINDOWS\system32\mtxparhd.dll
2012-08-06 21:35:59 ----N---- D:\WINDOWS\system32\msshavmsg.dll
2012-08-06 21:35:59 ----N---- D:\WINDOWS\system32\mssha.dll
2012-08-06 21:35:58 ----N---- D:\WINDOWS\system32\s3gnb.dll
2012-08-06 21:35:58 ----N---- D:\WINDOWS\system32\rhttpaa.dll
2012-08-06 21:35:58 ----N---- D:\WINDOWS\system32\rasqec.dll
2012-08-06 21:35:58 ----N---- D:\WINDOWS\system32\qutil.dll
2012-08-06 21:35:58 ----N---- D:\WINDOWS\system32\qcliprov.dll
2012-08-06 21:35:58 ----N---- D:\WINDOWS\system32\qagentrt.dll
2012-08-06 21:35:58 ----N---- D:\WINDOWS\system32\qagent.dll
2012-08-06 21:35:58 ----N---- D:\WINDOWS\system32\photometadatahandler.dll
2012-08-06 21:35:57 ----N---- D:\WINDOWS\system32\slserv.exe
2012-08-06 21:35:57 ----N---- D:\WINDOWS\system32\slrundll.exe
2012-08-06 21:35:57 ----N---- D:\WINDOWS\system32\slgen.dll
2012-08-06 21:35:57 ----N---- D:\WINDOWS\system32\slextspk.dll
2012-08-06 21:35:57 ----N---- D:\WINDOWS\system32\slcoinst.dll
2012-08-06 21:35:57 ----N---- D:\WINDOWS\system32\setupn.exe
2012-08-06 21:35:56 ----N---- D:\WINDOWS\system32\windowscodecsext.dll
2012-08-06 21:35:56 ----N---- D:\WINDOWS\system32\windowscodecs.dll
2012-08-06 21:35:56 ----N---- D:\WINDOWS\system32\tspkg.dll
2012-08-06 21:35:56 ----N---- D:\WINDOWS\system32\tsgqec.dll
2012-08-06 21:35:55 ----N---- D:\WINDOWS\system32\wmphoto.dll
2012-08-06 21:35:55 ----N---- D:\WINDOWS\system32\wlanapi.dll
2012-08-06 21:35:54 ----N---- D:\WINDOWS\slrundll.exe
2012-08-06 21:35:52 ----D---- D:\WINDOWS\system32\cs
2012-08-06 21:35:52 ----D---- D:\WINDOWS\l2schemas
2012-08-06 21:35:51 ----D---- D:\WINDOWS\system32\bits
2012-08-06 21:31:58 ----D---- D:\WINDOWS\ServicePackFiles
2012-08-06 21:29:32 ----N---- D:\WINDOWS\system32\drivers\agpcpq.sys
2012-08-06 21:29:32 ----N---- D:\WINDOWS\system32\drivers\agp440.sys
2012-08-06 21:29:32 ----N---- D:\WINDOWS\system32\drivers\adv11nt5.dll
2012-08-06 21:29:32 ----N---- D:\WINDOWS\system32\drivers\adv09nt5.dll
2012-08-06 21:29:32 ----N---- D:\WINDOWS\system32\drivers\adv08nt5.dll
2012-08-06 21:29:32 ----N---- D:\WINDOWS\system32\drivers\adv07nt5.dll
2012-08-06 21:29:32 ----N---- D:\WINDOWS\system32\drivers\adv05nt5.dll
2012-08-06 21:29:32 ----N---- D:\WINDOWS\system32\drivers\adv02nt5.dll
2012-08-06 21:29:32 ----N---- D:\WINDOWS\system32\drivers\adv01nt5.dll
2012-08-06 21:29:31 ----N---- D:\WINDOWS\system32\drivers\ati1rvxx.sys
2012-08-06 21:29:31 ----N---- D:\WINDOWS\system32\drivers\ati1raxx.sys
2012-08-06 21:29:31 ----N---- D:\WINDOWS\system32\drivers\ati1pdxx.sys
2012-08-06 21:29:31 ----N---- D:\WINDOWS\system32\drivers\ati1mdxx.sys
2012-08-06 21:29:31 ----N---- D:\WINDOWS\system32\drivers\ati1btxx.sys
2012-08-06 21:29:31 ----N---- D:\WINDOWS\system32\drivers\amdagp.sys
2012-08-06 21:29:31 ----N---- D:\WINDOWS\system32\drivers\alim1541.sys
2012-08-06 21:29:30 ----N---- D:\WINDOWS\system32\drivers\atinraxx.sys
2012-08-06 21:29:30 ----N---- D:\WINDOWS\system32\drivers\atinpdxx.sys
2012-08-06 21:29:30 ----N---- D:\WINDOWS\system32\drivers\atinmdxx.sys
2012-08-06 21:29:30 ----N---- D:\WINDOWS\system32\drivers\atinbtxx.sys
2012-08-06 21:29:30 ----N---- D:\WINDOWS\system32\drivers\ati2mtag.sys
2012-08-06 21:29:30 ----N---- D:\WINDOWS\system32\drivers\ati2mtaa.sys
2012-08-06 21:29:30 ----N---- D:\WINDOWS\system32\drivers\ati1xsxx.sys
2012-08-06 21:29:30 ----N---- D:\WINDOWS\system32\drivers\ati1xbxx.sys
2012-08-06 21:29:30 ----N---- D:\WINDOWS\system32\drivers\ati1tuxx.sys
2012-08-06 21:29:30 ----N---- D:\WINDOWS\system32\drivers\ati1ttxx.sys
2012-08-06 21:29:30 ----N---- D:\WINDOWS\system32\drivers\ati1snxx.sys
2012-08-06 21:29:29 ----N---- D:\WINDOWS\system32\drivers\bthpan.sys
2012-08-06 21:29:29 ----N---- D:\WINDOWS\system32\drivers\bthmodem.sys
2012-08-06 21:29:29 ----N---- D:\WINDOWS\system32\drivers\bthenum.sys
2012-08-06 21:29:29 ----N---- D:\WINDOWS\system32\drivers\atv10nt5.dll
2012-08-06 21:29:29 ----N---- D:\WINDOWS\system32\drivers\atv06nt5.dll
2012-08-06 21:29:29 ----N---- D:\WINDOWS\system32\drivers\atv04nt5.dll
2012-08-06 21:29:29 ----N---- D:\WINDOWS\system32\drivers\atv02nt5.dll
2012-08-06 21:29:29 ----N---- D:\WINDOWS\system32\drivers\atv01nt5.dll
2012-08-06 21:29:29 ----N---- D:\WINDOWS\system32\drivers\atinxsxx.sys
2012-08-06 21:29:29 ----N---- D:\WINDOWS\system32\drivers\atinxbxx.sys
2012-08-06 21:29:29 ----N---- D:\WINDOWS\system32\drivers\atintuxx.sys
2012-08-06 21:29:29 ----N---- D:\WINDOWS\system32\drivers\atinttxx.sys
2012-08-06 21:29:29 ----N---- D:\WINDOWS\system32\drivers\atinsnxx.sys
2012-08-06 21:29:29 ----N---- D:\WINDOWS\system32\drivers\atinrvxx.sys
2012-08-06 21:29:28 ----N---- D:\WINDOWS\system32\drivers\ch7xxnt5.dll
2012-08-06 21:29:28 ----N---- D:\WINDOWS\system32\drivers\bthusb.sys
2012-08-06 21:29:28 ----N---- D:\WINDOWS\system32\drivers\bthprint.sys
2012-08-06 21:29:27 ----N---- D:\WINDOWS\system32\drivers\hsfcxts2.sys
2012-08-06 21:29:27 ----N---- D:\WINDOWS\system32\drivers\hsfbs2s2.sys
2012-08-06 21:29:27 ----N---- D:\WINDOWS\system32\drivers\hidir.sys
2012-08-06 21:29:27 ----N---- D:\WINDOWS\system32\drivers\hidbth.sys
2012-08-06 21:29:27 ----N---- D:\WINDOWS\system32\drivers\gagp30kx.sys
2012-08-06 21:29:26 ----N---- D:\WINDOWS\system32\drivers\mtxparhm.sys
2012-08-06 21:29:26 ----N---- D:\WINDOWS\system32\drivers\mtlstrm.sys
2012-08-06 21:29:26 ----N---- D:\WINDOWS\system32\drivers\mtlmnt5.sys
2012-08-06 21:29:26 ----N---- D:\WINDOWS\system32\drivers\mdmxsdk.sys
2012-08-06 21:29:26 ----N---- D:\WINDOWS\system32\drivers\hsfdpsp2.sys
2012-08-06 21:29:25 ----N---- D:\WINDOWS\system32\drivers\s3gnbm.sys
2012-08-06 21:29:25 ----N---- D:\WINDOWS\system32\drivers\rndismpx.sys
2012-08-06 21:29:25 ----N---- D:\WINDOWS\system32\drivers\rfcomm.sys
2012-08-06 21:29:25 ----N---- D:\WINDOWS\system32\drivers\recagent.sys
2012-08-06 21:29:25 ----N---- D:\WINDOWS\system32\drivers\nv4_mini.sys
2012-08-06 21:29:25 ----N---- D:\WINDOWS\system32\drivers\ntmtlfax.sys
2012-08-06 21:29:25 ----N---- D:\WINDOWS\system32\drivers\mutohpen.sys
2012-08-06 21:29:24 ----N---- D:\WINDOWS\system32\drivers\smbali.sys
2012-08-06 21:29:24 ----N---- D:\WINDOWS\system32\drivers\slwdmsup.sys
2012-08-06 21:29:24 ----N---- D:\WINDOWS\system32\drivers\slnthal.sys
2012-08-06 21:29:24 ----N---- D:\WINDOWS\system32\drivers\slntamr.sys
2012-08-06 21:29:24 ----N---- D:\WINDOWS\system32\drivers\slnt7554.sys
2012-08-06 21:29:24 ----N---- D:\WINDOWS\system32\drivers\sisagp.sys
2012-08-06 21:29:24 ----N---- D:\WINDOWS\system32\drivers\siint5.dll
2012-08-06 21:29:24 ----N---- D:\WINDOWS\system32\drivers\sffp_mmc.sys
2012-08-06 21:29:23 ----N---- D:\WINDOWS\system32\drivers\watv06nt.sys
2012-08-06 21:29:23 ----N---- D:\WINDOWS\system32\drivers\wadv11nt.sys
2012-08-06 21:29:23 ----N---- D:\WINDOWS\system32\drivers\wadv09nt.sys
2012-08-06 21:29:23 ----N---- D:\WINDOWS\system32\drivers\wadv08nt.sys
2012-08-06 21:29:23 ----N---- D:\WINDOWS\system32\drivers\wadv07nt.sys
2012-08-06 21:29:23 ----N---- D:\WINDOWS\system32\drivers\wacompen.sys
2012-08-06 21:29:23 ----N---- D:\WINDOWS\system32\drivers\viaagp.sys
2012-08-06 21:29:23 ----N---- D:\WINDOWS\system32\drivers\vchnt5.dll
2012-08-06 21:29:23 ----N---- D:\WINDOWS\system32\drivers\usb8023x.sys
2012-08-06 21:29:23 ----N---- D:\WINDOWS\system32\drivers\uagp35.sys
2012-08-06 21:29:22 ----N---- D:\WINDOWS\system32\drivers\watv10nt.sys
2012-08-06 19:42:22 ----HDC---- D:\WINDOWS\$NtServicePackUninstall$
2012-08-05 22:19:40 ----D---- D:\Documents and Settings\Maca\Data aplikací\Malwarebytes
2012-08-05 22:19:25 ----D---- D:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2012-07-20 21:10:30 ----D---- D:\D2VAVS
2012-07-20 21:10:08 ----D---- D:\Ripp
2012-07-20 21:09:00 ----A---- D:\Rebuilder.ini
2012-07-20 21:09:00 ----A---- D:\Installer.txt
2012-07-20 21:08:10 ----A---- D:\info.txt
2012-07-20 21:07:16 ----D---- D:\Program Files\AviSynth 2.5

======List of files/folders modified in the last 1 month======

2012-09-12 23:05:32 ----D---- D:\Documents and Settings\All Users\Data aplikací\AVAST Software
2012-08-07 08:28:27 ----D---- D:\Program Files\Trend Micro
2012-08-07 08:26:49 ----RD---- D:\Program Files
2012-08-07 06:00:23 ----D---- D:\WINDOWS\Temp
2012-08-06 22:07:02 ----D---- D:\WINDOWS\Microsoft.NET
2012-08-06 21:59:10 ----D---- D:\WINDOWS\Debug
2012-08-06 21:59:10 ----D---- D:\WINDOWS
2012-08-06 21:56:03 ----N---- D:\WINDOWS\SchedLgU.Txt
2012-08-06 21:56:03 ----D---- D:\WINDOWS\system32\CatRoot2
2012-08-06 21:52:41 ----D---- D:\WINDOWS\system32
2012-08-06 21:52:41 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2012-08-06 21:50:16 ----RSD---- D:\WINDOWS\Fonts
2012-08-06 21:50:16 ----D---- D:\WINDOWS\system32\wbem
2012-08-06 21:50:16 ----D---- D:\WINDOWS\system32\Setup
2012-08-06 21:50:16 ----D---- D:\WINDOWS\AppPatch
2012-08-06 21:50:14 ----D---- D:\WINDOWS\system32\drivers
2012-08-06 21:46:01 ----D---- D:\WINDOWS\security
2012-08-06 21:44:43 ----D---- D:\WINDOWS\system32\CatRoot
2012-08-06 21:43:18 ----HD---- D:\WINDOWS\inf
2012-08-06 21:43:17 ----RSHDC---- D:\WINDOWS\system32\dllcache
2012-08-06 21:40:30 ----D---- D:\Program Files\Messenger
2012-08-06 21:36:26 ----D---- D:\WINDOWS\WinSxS
2012-08-06 21:36:19 ----D---- D:\WINDOWS\Help
2012-08-06 21:36:19 ----D---- D:\Program Files\Windows Media Player
2012-08-06 21:36:10 ----D---- D:\WINDOWS\ehome
2012-08-06 21:36:09 ----D---- D:\WINDOWS\system32\inetsrv
2012-08-06 21:36:09 ----D---- D:\WINDOWS\network diagnostic
2012-08-06 21:36:08 ----D---- D:\WINDOWS\ime
2012-08-06 21:35:54 ----D---- D:\WINDOWS\system32\cs-cz
2012-08-06 21:35:53 ----D---- D:\WINDOWS\system32\usmt
2012-08-06 21:35:52 ----SHD---- D:\WINDOWS\Installer
2012-08-06 21:35:51 ----D---- D:\WINDOWS\PeerNet
2012-08-06 21:35:51 ----D---- D:\Program Files\Movie Maker
2012-08-06 21:31:46 ----D---- D:\WINDOWS\system32\Restore
2012-08-06 21:31:46 ----D---- D:\WINDOWS\system32\npp
2012-08-06 21:31:44 ----D---- D:\WINDOWS\msagent
2012-08-06 21:31:43 ----D---- D:\WINDOWS\srchasst
2012-08-06 21:31:42 ----D---- D:\Program Files\NetMeeting
2012-08-06 21:31:41 ----D---- D:\WINDOWS\system32\Com
2012-08-06 21:31:38 ----D---- D:\Program Files\Windows NT
2012-08-06 21:31:37 ----D---- D:\Program Files\Outlook Express
2012-08-06 21:31:34 ----D---- D:\Program Files\Common Files\System
2012-08-06 21:31:12 ----D---- D:\WINDOWS\system32\oobe
2012-08-06 21:31:11 ----D---- D:\WINDOWS\system
2012-08-06 21:28:23 ----D---- D:\WINDOWS\system32\ReinstallBackups
2012-08-06 19:17:53 ----D---- D:\Program Files\Mozilla Firefox
2012-08-05 23:30:50 ----HDC---- D:\WINDOWS\$NtUninstallKB898461$
2012-08-05 22:08:49 ----SD---- D:\WINDOWS\Tasks
2012-08-05 22:08:45 ----D---- D:\WINDOWS\system32\drivers\etc
2012-08-03 09:41:51 ----D---- D:\WINDOWS\Minidump
2012-07-27 21:50:39 ----A---- D:\WINDOWS\NeroDigital.ini
2012-07-26 13:11:51 ----D---- D:\Documents and Settings\Maca\Data aplikací\Skype
2012-07-25 20:09:00 ----D---- D:\Documents and Settings\Maca\Data aplikací\ICQ
2012-07-20 21:02:43 ----D---- D:\Program Files\DVD Shrink

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI; D:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 PxHelp20;PxHelp20; D:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R1 Aavmker4;avast! Asynchronous Virus Monitor; D:\WINDOWS\system32\drivers\Aavmker4.sys [2012-07-03 25256]
R1 AswRdr;aswRdr; D:\WINDOWS\system32\drivers\AswRdr.sys [2012-07-03 35928]
R1 aswSnx;aswSnx; D:\WINDOWS\system32\drivers\aswSnx.sys [2012-07-03 721000]
R1 aswSP;aswSP; D:\WINDOWS\system32\drivers\aswSP.sys [2012-07-03 353688]
R1 aswTdi;avast! Network Shield Support; D:\WINDOWS\system32\drivers\aswTdi.sys [2012-07-03 54232]
R1 intelppm;Řadič procesoru Intel; D:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.10.0; D:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-04-11 21275]
R2 aswFsBlk;aswFsBlk; D:\WINDOWS\system32\drivers\aswFsBlk.sys [2012-07-03 21256]
R2 aswMon2;avast! Standard Shield Support; D:\WINDOWS\system32\drivers\aswMon2.sys [2012-07-03 97608]
R2 QBIOSIo;QBIOSIo.dll; D:\WINDOWS\system32\QBIOSIo.dll [2007-01-20 11520]
R3 AgereSoftModem;Agere Systems Soft Modem; D:\WINDOWS\system32\DRIVERS\AGRSM.sys [2008-04-05 1270540]
R3 AR5211;Atheros Wireless Network Adapter Service; D:\WINDOWS\system32\DRIVERS\ar5211.sys [2006-10-20 478432]
R3 Arp1394;Protokol 1394 ARP Client; D:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 btaudio;Bluetooth Audio Device; D:\WINDOWS\system32\drivers\btaudio.sys [2006-06-07 329901]
R3 btkrnl;Bluetooth Bus Enumerator; D:\WINDOWS\system32\DRIVERS\btkrnl.sys [2006-06-07 855018]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 ialm;ialm; D:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-04-05 5700096]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); D:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-07-10 4449280]
R3 nhcDriverDevice;Notebook Hardware Control Driver; \??\D:\WINDOWS\system32\drivers\nhcDriver.sys []
R3 NIC1394;1394 Net Driver; D:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 rimmptsk;rimmptsk; D:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2005-11-16 28928]
R3 rimsptsk;rimsptsk; D:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2006-09-08 51328]
R3 rismxdp;Ricoh xD-Picture Card Driver; D:\WINDOWS\system32\DRIVERS\rixdptsk.sys [2005-11-01 308992]
R3 sdbus;sdbus; D:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-14 79232]
R3 SynTP;Synaptics TouchPad Driver; D:\WINDOWS\system32\DRIVERS\SynTP.sys [2007-04-19 186552]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; D:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 usbvideo;Zobrazovací zařízení USB (WDM); D:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
R3 Wdf01000;Wdf01000; D:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; D:\WINDOWS\system32\DRIVERS\yk51x86.sys [2006-11-22 250496]
S1 kbdhid;Ovladač klávesnice standardu HID; D:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S2 DgiVecp;DgiVecp; \??\D:\WINDOWS\system32\Drivers\DgiVecp.sys []
S2 SSPORT;SSPORT; \??\D:\WINDOWS\system32\Drivers\SSPORT.sys []
S3 BTDriver;Bluetooth Virtual Communications Driver; D:\WINDOWS\system32\DRIVERS\btport.sys [2006-06-07 30459]
S3 BTWDNDIS;Bluetooth LAN Access Server; D:\WINDOWS\system32\DRIVERS\btwdndis.sys [2006-06-07 149028]
S3 btwhid;btwhid; D:\WINDOWS\system32\DRIVERS\btwhid.sys [2006-06-07 47811]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; D:\WINDOWS\System32\Drivers\btwusb.sys [2006-06-07 67384]
S3 CCDECODE;Dekodér Closed Caption; D:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 HidUsb;Ovladač třídy standardu HID; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 ipw_bus;IPWireless; D:\WINDOWS\system32\DRIVERS\ipw_bus.sys []
S3 ipw_mdfl;Wireless Broadband Modem Filter; D:\WINDOWS\system32\DRIVERS\ipw_mdfl.sys []
S3 ipw_mdm;Wireless Broadband Modem (WDM); D:\WINDOWS\system32\DRIVERS\ipw_mdm.sys []
S3 IpwP;IPWireless 3G Network Adapter; D:\WINDOWS\system32\DRIVERS\ipw3gnet.sys [2008-10-10 51040]
S3 mouhid;Ovladač myši standardu HID; D:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; D:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; D:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 nmwcd;Nokia USB Phone Parent; D:\WINDOWS\system32\drivers\ccdcmb.sys [2008-05-02 17536]
S3 sffdisk;Ovladač třídy úložiště SFF; D:\WINDOWS\system32\DRIVERS\sffdisk.sys [2008-04-14 11904]
S3 sffp_sd;Ovladač protokolu úložiště SFF pro paměť sběrnici SDBus; D:\WINDOWS\system32\DRIVERS\sffp_sd.sys [2008-04-14 11008]
S3 SkLaggProtocol;Marvell Link Aggregation Protocol (LAGG) Support; D:\WINDOWS\system32\DRIVERS\yk51lagg.sys []
S3 SkVlanProtocol;Marvell Virtual LAN (VLAN) Support; D:\WINDOWS\system32\DRIVERS\skvlan.sys [2006-05-17 19328]
S3 SLIP;BDA Slip De-Framer; D:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); D:\WINDOWS\system32\DRIVERS\snp2uvc.sys []
S3 streamip;BDA IPSink; D:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbprint;Třída USB Printer; D:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; D:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WpdUsb;WpdUsb; D:\WINDOWS\System32\Drivers\wpdusb.sys [2004-08-11 18944]
S3 WSTCODEC;Dálnopisný kodek světového standardu; D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACS;Ekahau Configuration Service; D:\WINDOWS\system32\acs.exe [2006-04-19 36864]
R2 avast! Antivirus;avast! Antivirus; D:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-07-03 44808]
R2 btwdins;Bluetooth Service; D:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2006-06-07 266295]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); D:\Program Files\CyberLink\Shared Files\RichVideo.exe [2005-08-08 167936]
R2 Samsung Network Fax Server;Samsung Network Fax Server; D:\WINDOWS\system32\spool\drivers\w32x86\3\NetFaxServer.exe [2009-09-11 162304]
R2 UMWdf;Windows User Mode Driver Framework; D:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S3 aspnet_state;ASP.NET State Service; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 ose;Office Source Engine; D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Preventivka - prosím

#12 Příspěvek od Márty84 »

:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Najdete tento soubor D:\Program Files\Trend Micro\Maca.exe a spustte ho.
Kliknete na Main menu a na Do a system scan only
U tohoto radku dejte vlevo zatrzitko

Kód: Vybrat vše

O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
Kliknete na nápis Fix checked a potvrdte.



:arrow: Jeste bych aktualizoval ten Internet Explorer.

:arrow: Jinak vypada log OK. Kdyby se to zhorsilo, staci se ozvat, udelame hlubsi kontrolu.



Nemate zac, mejte se :bye:
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Mufff
Návštěvník
Návštěvník
Příspěvky: 92
Registrován: 14 dub 2009 15:12

Re: Preventivka - prosím

#13 Příspěvek od Mufff »

Super! Aktualizaci provedu! :-) Jinak ještě jednou díky moc a mějte se!

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Preventivka - prosím

#14 Příspěvek od Márty84 »

Neni vubec zac, rado se stalo :wink:
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Zamčeno