Stránka 1 z 1

Pomalejší PC :(

Napsal: 10 říj 2012 20:07
od ave007
Děkuji za jakoukoliv pomoc :wub:


Logfile of random's system information tool 1.09 (written by random/random)
Run by Michael at 2012-10-10 21:06:47
Microsoft Windows XP Home Edition Service Pack 3
System drive H: has 625 GB (65%) free of 954 GB
Total RAM: 3327 MB (69% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:06:53, on 10.10.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17114)
Boot mode: Normal

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\Ati2evxx.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\Ati2evxx.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\Explorer.EXE
H:\Program Files\TO2SSM\McciTrayApp.exe
H:\PROGRA~1\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
H:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
H:\Program Files\Common Files\Java\Java Update\jusched.exe
H:\Programy\DAEMON Tools Lite\DTLite.exe
H:\Program Files\Skype\Phone\Skype.exe
H:\WINDOWS\system32\ctfmon.exe
H:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
H:\Program Files\Bonjour\mDNSResponder.exe
H:\ASUS.SYS\config\DVMExportService.exe
H:\Programy\ESET\ESET Smart Security\ekrn.exe
H:\Program Files\Java\jre7\bin\jqs.exe
H:\Program Files\Common Files\Motive\McciCMService.exe
H:\WINDOWS\system32\PnkBstrA.exe
H:\WINDOWS\system32\PnkBstrB.exe
H:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
h:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
h:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
H:\WINDOWS\system32\wbem\wmiapsrv.exe
H:\Programy\Origin\Origin.exe
H:\WINDOWS\system32\svchost.exe
H:\Program Files\iPod\bin\iPodService.exe
H:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
H:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe
H:\Documents and Settings\Michael\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
H:\Documents and Settings\Michael\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
H:\Documents and Settings\Michael\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
H:\Documents and Settings\Michael\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
H:\Documents and Settings\Michael\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
H:\Documents and Settings\Michael\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
H:\Documents and Settings\Michael\Plocha\RSIT.exe
H:\Program Files\trend micro\Michael.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 199.175.48.97:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - H:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - H:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - H:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - H:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - H:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - h:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [TO2SSM_McciTrayApp] H:\Program Files\TO2SSM\McciTrayApp.exe
O4 - HKLM\..\Run: [USBToolTip] H:\PROGRA~1\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [Samsung PanelMgr] H:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
O4 - HKLM\..\Run: [APSDaemon] "H:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] H:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "H:\Programy\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Steam] "H:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "H:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "H:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://H:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - H:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - H:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: h:\windows\system32\nwprovau.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - H:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - H:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - H:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - H:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - H:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - H:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - H:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - H:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM - H:\ASUS.SYS\config\DVMExportService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - H:\Programy\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - H:\Programy\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - H:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - H:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: McciCMService - Motive Communications, Inc. - H:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - H:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PnkBstrA - Unknown owner - H:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - H:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - H:\Program Files\Skype\Updater\Updater.exe

--
End of file - 9416 bytes

======Scheduled tasks folder======

H:\WINDOWS\tasks\Adobe Flash Player Updater.job

=========Mozilla firefox=========

ProfilePath - H:\Documents and Settings\Michael\Data aplikací\Mozilla\Firefox\Profiles\o2a010ob.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.centrum.cz/"
prefs.js - "extensions.enabledItems" - "DTToolbar@toolbarnet.com:1.1.1.0014, {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14, {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15, {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, jqs@sun.com:1.0, {20a82645-c095-46ed-80e3-08825760534b}:1.1, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2, {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.3, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9, {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94, {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94, engine@conduit.com:3.3.3.2, {51a86bb3-6602-4c85-92a5-130ee4864f13}:3.3.3.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.6"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.5.3&q="

"{20a82645-c095-46ed-80e3-08825760534b}"=h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"=H:\Program Files\DivX\DivX Plus Web Player\firefox\html5video
"{6904342A-8307-11DF-A508-4AE2DFD72085}"=H:\Program Files\DivX\DivX Plus Web Player\firefox\wpa


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.287 Plugin
"Path"=H:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=H:\Programy\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=H:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0]
"Description"=DivX® Player Plugin for VOD Content
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=H:\Program Files\DivX\DivX OVS Helper\npovshelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=H:\Programy\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=H:\WINDOWS\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=H:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=h:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=h:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@veetle.com/vbp;version=0.9.17]
"Description"=Veetle Broadcaster Plugin
"Path"=H:\Programy\Veetle\VLCBroadcast\npvbp.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=H:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

H:\Programy\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

H:\Programy\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt

H:\Programy\Mozilla Firefox\plugins\
np-mswmp.dll
npDivxPlayerPlugin.dll
NPOFF12.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nsIDivxPlayerPlugin.xpt
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

H:\Programy\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

H:\Documents and Settings\Michael\Data aplikací\Mozilla\Firefox\Profiles\o2a010ob.default\extensions\
ChoiceGuard@Microsoft
DTToolbar@toolbarnet.com
nostmp
{51a86bb3-6602-4c85-92a5-130ee4864f13}
{800b5000-a755-47e1-992b-48a1c1357f07}

H:\Documents and Settings\Michael\Data aplikací\Mozilla\Firefox\Profiles\o2a010ob.default\searchplugins\
icqplugin.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - H:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll [2011-02-08 3118976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}]
DivX HiQ - H:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll [2011-02-08 3118976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - H:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - H:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - H:\Program Files\Java\jre7\bin\ssv.dll [2012-09-30 449512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - h:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - H:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-09-30 157672]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TO2SSM_McciTrayApp"=H:\Program Files\TO2SSM\McciTrayApp.exe [2008-08-15 1473536]
"USBToolTip"=H:\PROGRA~1\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe [2007-02-20 199752]
"Samsung PanelMgr"=H:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe [2010-06-07 618496]
"APSDaemon"=H:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-05-30 59280]
"AppleSyncNotifier"=H:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [2012-02-23 59240]
"SunJavaUpdateSched"=H:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=H:\Programy\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Steam"=H:\Program Files\Steam\steam.exe [2012-08-05 1353080]
"Skype"=H:\Program Files\Skype\Phone\Skype.exe [2012-07-13 17418928]
"ctfmon.exe"=H:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"msnmsgr"=H:\Program Files\Windows Live\Messenger\msnmsgr.exe [2010-04-16 3872080]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
H:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
H:\WINDOWS\system32\Ati2evxx.dll [2009-03-04 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=H:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoInstrumentation"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoResolveSearch"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"H:\WINDOWS\system32\sessmgr.exe"="H:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"H:\WINDOWS\system32\PnkBstrB.exe"="H:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"H:\Programy\BitLord\BitLord.exe"="H:\Programy\BitLord\BitLord.exe:*:Enabled:BitLord"
"H:\Hry\Ubisoft\Related Designs\ANNO 1404\Anno4.exe"="H:\Hry\Ubisoft\Related Designs\ANNO 1404\Anno4.exe:*:Enabled:ANNO 1404"
"H:\Hry\Ubisoft\Related Designs\ANNO 1404\tools\Anno4Web.exe"="H:\Hry\Ubisoft\Related Designs\ANNO 1404\tools\Anno4Web.exe:*:Enabled:ANNO 1404 Web"
"J:\TmUnitedForever\TmForever.exe"="J:\TmUnitedForever\TmForever.exe:*:Enabled:TmForever"
"H:\Program Files\Skype\Plugin Manager\skypePM.exe"="H:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"H:\Program Files\Vietcong\vietcong.exe"="H:\Program Files\Vietcong\vietcong.exe:*:Enabled:vietcong"
"H:\Programy\Mozilla Firefox\firefox.exe"="H:\Programy\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"H:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="H:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"H:\Hry\KONAMI\Pro Evolution Soccer 2011\pes2011.exe"="H:\Hry\KONAMI\Pro Evolution Soccer 2011\pes2011.exe:*:Enabled:Pro Evolution Soccer 2011"
"H:\WINDOWS\system32\PnkBstrA.exe"="H:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"H:\Program Files\Opera\opera.exe"="H:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"H:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="H:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"H:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="H:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"H:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="H:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"H:\Programy\Pinnacle\Studio 14\Programs\RM.exe"="H:\Programy\Pinnacle\Studio 14\Programs\RM.exe:*:Enabled:Render Manager"
"H:\Programy\Pinnacle\Studio 14\Programs\Studio.exe"="H:\Programy\Pinnacle\Studio 14\Programs\Studio.exe:*:Enabled:Studio"
"H:\Programy\Pinnacle\Studio 14\Programs\umi.exe"="H:\Programy\Pinnacle\Studio 14\Programs\umi.exe:*:Enabled:umi"
"H:\Hry\Codemasters\F1 2011\F1_2011.exe"="H:\Hry\Codemasters\F1 2011\F1_2011.exe:*:Enabled:F1 2011"
"H:\Hry\KONAMI\Pro Evolution Soccer 2012\pes2012.exe"="H:\Hry\KONAMI\Pro Evolution Soccer 2012\pes2012.exe:*:Enabled:Pro Evolution Soccer 2012"
"H:\Program Files\Origin Games\FIFA 12\Game\fifa.exe"="H:\Program Files\Origin Games\FIFA 12\Game\fifa.exe:*:Enabled:FIFA 12"
"H:\Hry\Sports Interactive\Football Manager 2010\fm.exe"="H:\Hry\Sports Interactive\Football Manager 2010\fm.exe:*:Disabled:Football Manager 2010"
"H:\Documents and Settings\Michael\Local Settings\Data aplikací\Facebook\Video\Skype\FacebookVideoCalling.exe"="H:\Documents and Settings\Michael\Local Settings\Data aplikací\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Enabled:Facebook Video Calling Plugin"
"H:\Program Files\TeamViewer\Version7\TeamViewer.exe"="H:\Program Files\TeamViewer\Version7\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"H:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe"="H:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service"
"H:\Program Files\Bonjour\mDNSResponder.exe"="H:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"H:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="H:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"H:\Program Files\Windows Live\Messenger\wlcsdk.exe"="H:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"H:\Program Files\Windows Live\Messenger\msnmsgr.exe"="H:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"H:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="H:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"H:\Programy\iTunes\iTunes.exe"="H:\Programy\iTunes\iTunes.exe:*:Enabled:iTunes"
"H:\Program Files\Skype\Phone\Skype.exe"="H:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"H:\Program Files\Origin Games\FIFA 13\Game\fifa13.exe"="H:\Program Files\Origin Games\FIFA 13\Game\fifa13.exe:*:Enabled:FIFA 13"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"H:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="H:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"H:\Program Files\Windows Live\Messenger\wlcsdk.exe"="H:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"H:\Program Files\Windows Live\Messenger\msnmsgr.exe"="H:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=H:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=H:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"vidc.VP60"=H:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=H:\WINDOWS\system32\vp6vfw.dll
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll
"VIDC.FPS1"=frapsvid.dll
"vidc.mjpg"=pvmjpg30.dll
"msacm.siren"=sirenacm.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-10-09 15:28:15 ----D---- H:\DVDVideoSoft
2012-10-09 15:27:50 ----D---- H:\Program Files\Common Files\DVDVideoSoft
2012-09-30 11:11:10 ----A---- H:\WINDOWS\system32\javaws.exe
2012-09-30 11:03:24 ----D---- H:\Program Files\Common Files\Java
2012-09-30 11:03:13 ----A---- H:\WINDOWS\system32\WindowsAccessBridge.dll
2012-09-30 11:03:13 ----A---- H:\WINDOWS\system32\javaw.exe
2012-09-30 11:03:13 ----A---- H:\WINDOWS\system32\java.exe
2012-09-12 19:02:47 ----HDC---- H:\WINDOWS\$NtUninstallKB2736233$

======List of files/folders modified in the last 1 month======

2012-10-10 21:06:54 ----D---- H:\WINDOWS\Prefetch
2012-10-10 21:06:50 ----D---- H:\Program Files\trend micro
2012-10-10 21:06:48 ----D---- H:\WINDOWS\Temp
2012-10-10 21:05:00 ----D---- H:\Program Files\Steam
2012-10-10 21:04:37 ----AD---- H:\WINDOWS
2012-10-10 21:03:38 ----D---- H:\Program Files\CCleaner
2012-10-10 21:02:14 ----D---- H:\Documents and Settings\Michael\Data aplikací\Skype
2012-10-10 19:22:11 ----A---- H:\ntservicelogOutlook.txt
2012-10-10 11:22:39 ----D---- H:\WINDOWS\system32\CatRoot2
2012-10-10 00:23:03 ----N---- H:\WINDOWS\SchedLgU.Txt
2012-10-10 00:23:03 ----D---- H:\WINDOWS\system32
2012-10-09 15:40:04 ----AC---- H:\WINDOWS\NeroDigital.ini
2012-10-09 15:27:50 ----D---- H:\Programy
2012-10-09 15:27:50 ----D---- H:\Program Files\Common Files
2012-10-08 23:41:40 ----A---- H:\WINDOWS\system32\FlashPlayerApp.exe
2012-10-02 21:37:14 ----HD---- H:\WINDOWS\inf
2012-09-30 11:11:30 ----SHD---- H:\WINDOWS\Installer
2012-09-30 11:11:30 ----SHD---- H:\Config.Msi
2012-09-30 11:10:53 ----D---- H:\Program Files\Java
2012-09-30 11:02:57 ----A---- H:\WINDOWS\system32\npDeployJava1.dll
2012-09-30 11:02:57 ----A---- H:\WINDOWS\system32\deployJava1.dll
2012-09-29 14:59:26 ----SD---- H:\WINDOWS\Tasks
2012-09-28 12:35:02 ----D---- H:\WINDOWS\Logs
2012-09-26 20:59:47 ----D---- H:\Program Files\Origin Games
2012-09-25 19:06:04 ----D---- H:\WINDOWS\system32\DirectX
2012-09-25 19:05:25 ----RSD---- H:\WINDOWS\assembly
2012-09-25 18:47:43 ----D---- H:\Documents and Settings\All Users\Data aplikací\Origin
2012-09-25 02:08:37 ----RSHDC---- H:\WINDOWS\system32\dllcache
2012-09-25 02:08:36 ----D---- H:\WINDOWS\system32\cs-cz
2012-09-25 02:08:36 ----D---- H:\Program Files\Internet Explorer
2012-09-24 21:30:16 ----HD---- H:\WINDOWS\$hf_mig$
2012-09-12 21:45:17 ----D---- H:\WINDOWS\Debug
2012-09-12 19:03:38 ----D---- H:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2012-09-12 19:00:19 ----A---- H:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; H:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 PxHelp20;PxHelp20; H:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-03-31 44944]
R0 sptd;sptd; H:\WINDOWS\System32\Drivers\sptd.sys [2011-12-27 436792]
R1 ehdrv;ehdrv; H:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-02-26 114984]
R1 epfwtdi;epfwtdi; H:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2010-02-26 55232]
R1 intelppm;Řadič procesoru Intel; H:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; H:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 atksgt;atksgt; H:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-08-04 281760]
R2 eamon;eamon; H:\WINDOWS\system32\DRIVERS\eamon.sys [2010-02-26 139192]
R2 epfw;epfw; H:\WINDOWS\system32\DRIVERS\epfw.sys [2010-02-26 134488]
R2 lirsgt;lirsgt; H:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-08-04 25888]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; H:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; H:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2008-04-14 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; H:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2008-04-14 55936]
R3 Arp1394;Protokol 1394 ARP Client; H:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 ati2mtag;ati2mtag; H:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-03-04 3565568]
R3 AtiHdmiService;ATI Function Driver for HDMI Service; H:\WINDOWS\system32\drivers\AtiHdmi.sys [2008-10-31 93184]
R3 Epfwndis;Eset Personal Firewall; H:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2010-02-26 32584]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; H:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-01-15 23848]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; H:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Ovladač třídy standardu HID; H:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; H:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2008-09-23 38400]
R3 MarvinBus;Pinnacle Marvin Bus; H:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
R3 monfilt;monfilt; H:\WINDOWS\system32\drivers\monfilt.sys [2008-02-14 1389056]
R3 mouhid;Ovladač myši standardu HID; H:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; H:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; H:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; H:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; H:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; H:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; H:\WINDOWS\system32\drivers\viahduaa.sys [2008-12-19 993280]
R3 Wdf01000;Wdf01000; H:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
R3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; H:\WINDOWS\system32\DRIVERS\xusb21.sys [2007-08-28 55808]
S2 DgiVecp;DgiVecp; \??\H:\WINDOWS\system32\Drivers\DgiVecp.sys []
S2 SSPORT;SSPORT; \??\H:\WINDOWS\system32\Drivers\SSPORT.sys []
S3 aos0wmot;aos0wmot; H:\WINDOWS\system32\drivers\aos0wmot.sys []
S3 cpuz130;cpuz130; \??\H:\DOCUME~1\Michael\LOCALS~1\Temp\cpuz130\cpuz_x32.sys []
S3 ENTECH;ENTECH; \??\H:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 hamachi;Hamachi Network Interface; H:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\H:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS []
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\H:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\H:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\H:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver; \??\H:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS []
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\H:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 USBAAPL;Apple Mobile USB Driver; H:\WINDOWS\System32\Drivers\usbaapl.sys [2012-02-15 43520]
S3 usbaudio;Ovladač zvukové karty USB (WDM); H:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 usbprint;Třída USB Printer; H:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; H:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; H:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; H:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; H:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; H:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-05-24 55184]
R2 Ati HotKey Poller;Ati HotKey Poller; H:\WINDOWS\system32\Ati2evxx.exe [2009-03-04 602112]
R2 Bonjour Service;Bonjour Service; H:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 DvmMDES;DeviceVM Meta Data Export Service; H:\ASUS.SYS\config\DVMExportService.exe [2008-11-26 323584]
R2 ekrn;ESET Service; H:\Programy\ESET\ESET Smart Security\ekrn.exe [2010-02-26 810120]
R2 JavaQuickStarterService;Java Quick Starter; H:\Program Files\Java\jre7\bin\jqs.exe [2012-09-30 161768]
R2 McciCMService;McciCMService; H:\Program Files\Common Files\Motive\McciCMService.exe [2007-10-15 303104]
R2 NwSapAgent;Agent SAP; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 PnkBstrA;PnkBstrA; H:\WINDOWS\system32\PnkBstrA.exe [2010-11-07 75064]
R2 PnkBstrB;PnkBstrB; H:\WINDOWS\system32\PnkBstrB.exe [2009-06-23 107832]
R2 SeaPort;SeaPort; H:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R2 wlidsvc;Windows Live ID Sign-in Assistant; h:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R3 iPod Service;iPod Service; H:\Program Files\iPod\bin\iPodService.exe [2012-06-07 821648]
S2 ATI Smart;ATI Smart; H:\WINDOWS\system32\ati2sgag.exe [2009-03-03 593920]
S2 SkypeUpdate;Skype Updater; H:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; H:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-08 250808]
S3 aspnet_state;Stavová služba ASP.NET; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; H:\Programy\ESET\ESET Smart Security\EHttpSrv.exe [2010-02-26 33560]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; h:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; h:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; H:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; H:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-08-06 113120]
S3 odserv;Microsoft Office Diagnostics Service; H:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; H:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; H:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 gusvc;Google Updater Service; H:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; H:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-29 935208]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; h:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 Skype C2C Service;Skype C2C Service; H:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-08-13 3064000]

-----------------EOF-----------------

Re: Pomalejší PC :(

Napsal: 10 říj 2012 20:43
od Rudy
Zdravím!
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte na Search
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Pomalejší PC :(

Napsal: 10 říj 2012 21:03
od ave007
# AdwCleaner v2.004 - Logfile created 10/10/2012 at 22:03:00
# Updated 06/10/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Michael - MICHAL-83D99BA0
# Boot Mode : Normal
# Running from : H:\Documents and Settings\Michael\Plocha\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

Folder Found : H:\DOCUME~1\Michael\LOCALS~1\Temp\boost_interprocess
Folder Found : H:\Documents and Settings\All Users\Data aplikací\boost_interprocess
Folder Found : H:\Documents and Settings\Michael\Data aplikací\PriceGong
Folder Found : H:\Program Files\BrotherSoft_Extreme
Folder Found : H:\Program Files\Conduit

***** [Registry] *****

Key Found : HKCU\Software\BrotherSoft_Extreme
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{51A86BB3-6602-4C85-92A5-130EE4864F13}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DD5F877D-3076-42BE-8F12-8E809A98620B}
Key Found : HKCU\Software\PriceGong
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Toolbar
Key Found : HKLM\Software\BrotherSoft_Extreme
Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Found : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj
Key Found : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj.1
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2776682
Key Found : HKLM\Software\Conduit
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C244E4EE-68A9-4DD6-9CBC-E17967B45D06}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CF6C5B98-5FB9-49C5-9837-27F2FEFBB347}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BrotherSoft_Extreme Toolbar
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DD5F877D-3076-42BE-8F12-8E809A98620B}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrotherSoft_Extreme Toolbar
Key Found : HKU\S-1-5-21-1960408961-630328440-682003330-1004\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{51A86BB3-6602-4C85-92A5-130EE4864F13}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]

***** [Internet Browsers] *****

-\\ Internet Explorer v7.0.5730.13

[OK] Registry is clean.

-\\ Opera v11.60.1185.0

File : H:\Documents and Settings\Michael\Data aplikací\Opera\Opera\operaprefs.ini

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [3410 octets] - [10/10/2012 22:03:00]

########## EOF - H:\AdwCleaner[R1].txt - [3470 octets] ##########

Re: Pomalejší PC :(

Napsal: 10 říj 2012 21:13
od Rudy
Spusťte znovu ADWCleaner a klikněte na >Delete<. Vložte nový log.

Re: Pomalejší PC :(

Napsal: 10 říj 2012 21:57
od ave007
# AdwCleaner v2.004 - Logfile created 10/10/2012 at 22:55:14
# Updated 06/10/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Michael - MICHAL-83D99BA0
# Boot Mode : Normal
# Running from : H:\Documents and Settings\Michael\Plocha\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : H:\DOCUME~1\Michael\LOCALS~1\Temp\boost_interprocess
Folder Deleted : H:\Documents and Settings\All Users\Data aplikací\boost_interprocess
Folder Deleted : H:\Documents and Settings\Michael\Data aplikací\PriceGong
Folder Deleted : H:\Program Files\BrotherSoft_Extreme
Folder Deleted : H:\Program Files\Conduit

***** [Registry] *****

Key Deleted : HKCU\Software\BrotherSoft_Extreme
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{51A86BB3-6602-4C85-92A5-130EE4864F13}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DD5F877D-3076-42BE-8F12-8E809A98620B}
Key Deleted : HKCU\Software\PriceGong
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Toolbar
Key Deleted : HKLM\Software\BrotherSoft_Extreme
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj
Key Deleted : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2776682
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C244E4EE-68A9-4DD6-9CBC-E17967B45D06}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CF6C5B98-5FB9-49C5-9837-27F2FEFBB347}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BrotherSoft_Extreme Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DD5F877D-3076-42BE-8F12-8E809A98620B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrotherSoft_Extreme Toolbar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{51A86BB3-6602-4C85-92A5-130EE4864F13}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]

***** [Internet Browsers] *****

-\\ Internet Explorer v7.0.5730.13

[OK] Registry is clean.

-\\ Opera v11.60.1185.0

File : H:\Documents and Settings\Michael\Data aplikací\Opera\Opera\operaprefs.ini

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [3539 octets] - [10/10/2012 22:03:00]
AdwCleaner[S1].txt - [3383 octets] - [10/10/2012 22:55:14]

########## EOF - H:\AdwCleaner[S1].txt - [3443 octets] ##########

Re: Pomalejší PC :(

Napsal: 11 říj 2012 17:25
od Rudy
Vše smazáno. Nastala nějaká změna?

Re: Pomalejší PC :(

Napsal: 11 říj 2012 18:35
od ave007
Děkuji Rudy. PC se mi zdá stejně pomalé. Budou tam asi nějaké " lepší skryté viry"
Ale i přesto moc děkuji za snahu pomoci.

Re: Pomalejší PC :(

Napsal: 11 říj 2012 18:51
od Rudy
Dejte log ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware

Re: Pomalejší PC :(

Napsal: 11 říj 2012 21:08
od ave007
ComboFix 12-10-11.03 - Michael 11.10.2012 21:58:43.1.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.3327.2520 [GMT 2:00]
Spuštěný z: h:\documents and settings\Michael\Dokumenty\Downloads\ComboFix.exe
AV: ESET Smart Security 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *Enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
H:\Install.exe
h:\program files\HyperCam Toolbar\tbHElper.dll
H:\Win
h:\win\$LDR$
h:\win\082e483b636ae16da1\update\update.exe
h:\win\b64c0c1e1d69b2adfdaa58a9e055c8\update\update.exe
h:\win\b64c0c1e1d69b2adfdaa58a9e055c8\update\wpdinstallutil.dll
h:\win\eula.1028.txt
h:\win\eula.1031.txt
h:\win\eula.1033.txt
h:\win\eula.1036.txt
h:\win\eula.1040.txt
h:\win\eula.1041.txt
h:\win\eula.1042.txt
h:\win\eula.2052.txt
h:\win\eula.3082.txt
h:\win\globdata.ini
h:\win\install.exe
h:\win\install.ini
h:\win\install.res.1028.dll
h:\win\install.res.1031.dll
h:\win\install.res.1033.dll
h:\win\install.res.1036.dll
h:\win\install.res.1040.dll
h:\win\install.res.1041.dll
h:\win\install.res.1042.dll
h:\win\install.res.2052.dll
h:\win\install.res.3082.dll
h:\win\ntservicelogOutlook.txt
h:\win\txtsetup.sif
h:\win\VC_RED.cab
h:\win\VC_RED.MSI
h:\win\vcredist.bmp
h:\windows\iun6002.exe
h:\windows\pkunzip.pif
h:\windows\pkzip.pif
h:\windows\system32\dllcache\dlimport.exe
h:\windows\system32\drivers\tcpip.copy
h:\windows\system32\TZLog.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-09-11 do 2012-10-11 )))))))))))))))))))))))))))))))
.
.
2012-10-10 21:54 . 2012-10-10 21:54 -------- d-----w- h:\documents and settings\Michael\Data aplikací\Toolbar4
2012-10-10 21:54 . 2012-10-11 20:04 -------- d-----w- h:\program files\HyperCam Toolbar
2012-10-10 21:44 . 2012-10-10 21:52 -------- d-----w- H:\Fraps
2012-10-09 13:28 . 2012-10-09 13:28 -------- d-----w- H:\DVDVideoSoft
2012-10-09 13:27 . 2012-10-09 13:42 -------- d-----w- h:\program files\Common Files\DVDVideoSoft
2012-09-30 09:03 . 2012-09-30 09:03 -------- d-----w- h:\program files\Common Files\Java
2012-09-30 09:03 . 2012-09-30 09:03 93672 ----a-w- h:\windows\system32\WindowsAccessBridge.dll
2012-09-14 07:42 . 2012-09-14 07:42 -------- d-----w- h:\documents and settings\Počítač\Local Settings\Data aplikací\Apple Computer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-08 21:41 . 2012-04-07 14:09 696760 ----a-w- h:\windows\system32\FlashPlayerApp.exe
2012-10-08 21:41 . 2011-08-26 08:25 73656 ----a-w- h:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-30 09:02 . 2012-08-17 15:53 821736 ----a-w- h:\windows\system32\npDeployJava1.dll
2012-09-30 09:02 . 2012-04-11 16:49 143872 ----a-w- h:\windows\system32\javacpl.cpl
2012-09-30 09:02 . 2010-06-23 14:05 746984 ----a-w- h:\windows\system32\deployJava1.dll
2012-08-30 13:46 . 2012-08-30 13:46 65536 ----a-w- h:\windows\system32\frapsvid.dll
2012-08-27 18:40 . 2008-04-14 12:00 832512 ----a-w- h:\windows\system32\wininet.dll
2012-08-27 18:40 . 2008-04-14 12:00 1830912 ------w- h:\windows\system32\inetcpl.cpl
2012-08-27 18:40 . 2008-04-14 12:00 78336 ----a-w- h:\windows\system32\ieencode.dll
2012-08-27 18:40 . 2008-04-14 12:00 17408 ----a-w- h:\windows\system32\corpol.dll
2012-08-24 13:53 . 2008-04-14 12:00 177664 ----a-w- h:\windows\system32\wintrust.dll
2012-08-23 06:27 . 2008-04-14 12:00 2150912 ----a-w- h:\windows\system32\ntoskrnl.exe
2012-08-23 06:27 . 2008-04-14 08:06 2029568 ----a-w- h:\windows\system32\ntkrnlpa.exe
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2012-04-12 . 456E0F5B9BEB184521B0EE8FA7CC92C7 . 361600 . . [5.1.2600.5625] . . h:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . h:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . h:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . h:\windows\system32\dllcache\tcpip.sys
[7] 2008-04-14 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . h:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . h:\windows\ServicePackFiles\i386\tcpip.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="h:\programy\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Steam"="h:\program files\Steam\steam.exe" [2012-08-05 1353080]
"Skype"="h:\program files\Skype\Phone\Skype.exe" [2012-07-13 17418928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TO2SSM_McciTrayApp"="h:\program files\TO2SSM\McciTrayApp.exe" [2008-08-15 1473536]
"USBToolTip"="h:\progra~1\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
"Samsung PanelMgr"="h:\windows\Samsung\PanelMgr\SSMMgr.exe" [2010-06-07 618496]
"APSDaemon"="h:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-30 59280]
"AppleSyncNotifier"="h:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2012-02-23 59240]
"SunJavaUpdateSched"="h:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 12:00 15360 ----a-w- h:\windows\system32\ctfmon.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"h:\\WINDOWS\\system32\\sessmgr.exe"=
"h:\\WINDOWS\\system32\\PnkBstrB.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"h:\\Programy\\BitLord\\BitLord.exe"=
"h:\\Hry\\Ubisoft\\Related Designs\\ANNO 1404\\Anno4.exe"=
"h:\\Hry\\Ubisoft\\Related Designs\\ANNO 1404\\tools\\Anno4Web.exe"=
"h:\\Program Files\\Vietcong\\vietcong.exe"=
"h:\\Programy\\Mozilla Firefox\\firefox.exe"=
"h:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"h:\\WINDOWS\\system32\\PnkBstrA.exe"=
"h:\\Program Files\\Opera\\opera.exe"=
"h:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"h:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"h:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"h:\\Programy\\Pinnacle\\Studio 14\\Programs\\RM.exe"=
"h:\\Programy\\Pinnacle\\Studio 14\\Programs\\Studio.exe"=
"h:\\Programy\\Pinnacle\\Studio 14\\Programs\\umi.exe"=
"h:\\Program Files\\Origin Games\\FIFA 12\\Game\\fifa.exe"=
"h:\\Program Files\\TeamViewer\\Version7\\TeamViewer.exe"=
"h:\\Program Files\\TeamViewer\\Version7\\TeamViewer_Service.exe"=
"h:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"h:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"h:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"h:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"h:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"h:\\Programy\\iTunes\\iTunes.exe"=
"h:\\Program Files\\Skype\\Phone\\Skype.exe"=
"h:\\Program Files\\Origin Games\\FIFA 13\\Game\\fifa13.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 sptd;sptd;h:\windows\system32\drivers\sptd.sys [23.6.2009 22:15 436792]
R1 ehdrv;ehdrv;h:\windows\system32\drivers\ehdrv.sys [26.2.2010 6:41 114984]
R2 DvmMDES;DeviceVM Meta Data Export Service;h:\asus.sys\config\DVMExportService.exe [26.11.2008 10:36 323584]
R2 ekrn;ESET Service;h:\programy\ESET\ESET Smart Security\ekrn.exe [26.2.2010 6:41 810120]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;h:\windows\system32\drivers\viahduaa.sys [23.6.2009 21:12 993280]
S2 SkypeUpdate;Skype Updater;h:\program files\Skype\Updater\Updater.exe [13.7.2012 13:28 160944]
S2 SSPORT;SSPORT;\??\h:\windows\system32\Drivers\SSPORT.sys --> h:\windows\system32\Drivers\SSPORT.sys [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;h:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [7.4.2012 16:09 250808]
S3 cpuz130;cpuz130;\??\h:\docume~1\Michael\LOCALS~1\Temp\cpuz130\cpuz_x32.sys --> h:\docume~1\Michael\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;h:\program files\Mozilla Maintenance Service\maintenanceservice.exe [1.8.2012 23:49 113120]
S4 Skype C2C Service;Skype C2C Service;h:\documents and settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [13.8.2012 13:33 3064000]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-10-11 h:\windows\Tasks\Adobe Flash Player Updater.job
- h:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 21:41]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = 122.144.1.110:8080
IE: Add to Google Photos Screensa&ver - h:\windows\system32\GPhotos.scr/200
Trusted Zone: mojebanka.cz\*
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - h:\documents and settings\Michael\Data aplikací\Mozilla\Firefox\Profiles\o2a010ob.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2776682&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.5.3&q=
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
pref('extensions.shownSelectionUI',true);
pref('extensions.autoDisableScopes',0);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-Cool's_Codec_pack_4.12 - h:\windows\iun6002.exe
AddRemove-Octoshape add-in for Adobe Flash Player - h:\documents and settings\Michael\Data aplikací\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-11 22:05
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@h:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="h:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1096)
h:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2012-10-11 22:07:58
ComboFix-quarantined-files.txt 2012-10-11 20:07
.
Před spuštěním: Volných bajtů: 641 633 210 368
Po spuštění: Volných bajtů: 641 674 981 376
.
- - End Of File - - 290117F8FFF0DCD407B27484E70F2BB0

Re: Pomalejší PC :(

Napsal: 11 říj 2012 21:16
od Rudy
Ještě dočistíme. Přesuňte ComboFix na plochu. Otevřte poznámkový blok a zkopírujte do něj:
KillAll::

Folder::
h:\documents and settings\All Users\Data aplikací\Skype\Toolbars

Driver::
Skype C2C Service

Firefox::
FF - ProfilePath - h:\documents and settings\Michael\Data aplikací\Mozilla\Firefox\Profiles\o2a010ob.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_result ... r=1.5.3&q=
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
pref('extensions.shownSelectionUI',true);
pref('extensions.autoDisableScopes',0);

RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

Reboot::
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek

Re: Pomalejší PC :(

Napsal: 15 říj 2012 22:51
od ave007
Omlouvám se za pozdní odpověď. :(

Bohužel když to udělám podle návodu (CFScript přesunu na ComboFix) kontrola začne, ale nikdy se nedokončí, zkoušel jsem to 3x jednou jsem to nechal běžet i 3 hodiny.
Zasekne se to ve chvíli kdy to napíše, že kontrola může trvat 10minut a při hodně zavirovaném PC i dvojnásobek.
Děkuji za radu.

Re: Pomalejší PC :(

Napsal: 16 říj 2012 17:22
od Rudy
Zkuste to v nouz. režimu.

Re: Pomalejší PC :(

Napsal: 16 říj 2012 22:19
od ave007
bohužel stejný problém jako předtím...:(

Re: Pomalejší PC :(

Napsal: 17 říj 2012 17:28
od Rudy
1. Stáhněte Avenger: http://forum.viry.cz/viewtopic.php?f=11&t=19832 a spusťte. Do bílého okna zkopírujte:
Folders to delete:
h:\documents and settings\All Users\Data aplikací\Skype\Toolbars

Drivers to delete:
Skype C2C Service
a klikněte na >Execute<. PC bude restartován.

2. Pomocí MozBackUp: http://www.stahuj.centrum.cz/utility_a_ ... mozbackup/ zazálohujte profil firefoxu. FF pak kompletně odinstalujte a smažte jeho profil. Pak znovu nainstalujte a ze zálohy obnovte pouze záložky.