Stránka 1 z 1

Zpomalení PC, zaseknutý spořič

Napsal: 18 lis 2012 14:56
od hkotrc
Dobrý den,
mám problém se zasekaným pc, zasekává se spořič a Eset mi našel nějaké viry. Do minulého týdnu to prý bylo ok, pak to začalo.
Poradite mi prosím?

Log z RSIT

Logfile of random's system information tool 1.09 (written by random/random)
Run by Spravce at 2012-11-18 14:53:24
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 21 GB (27%) free of 79 GB
Total RAM: 1023 MB (57% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:53:28, on 18.11.2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\vsnpstd2.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Spravce\Plocha\RSIT.exe
C:\Program Files\trend micro\Spravce.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.superhry.cz/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.stahuj.cz/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Poskytovatel aplikace Windows Internet Explorer: Aktuálně.cz
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5825.1100\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Bleskově - {17DF9729-2156-43E0-9414-9B380D6C6504} - http://www.bleskove.cz (file missing) (HKCU)
O9 - Extra button: Slovníky - {1E3BC114-E8D1-439F-95BC-2819A5BD7EDA} - http://slovniky.centrum.cz (file missing) (HKCU)
O9 - Extra button: Supermapy - {4CC5BCEE-FD7F-4A00-A6C6-4DC9B57301C7} - http://www.supermapy.cz (file missing) (HKCU)
O9 - Extra button: Fotoalba - {502F2D2B-918B-41A4-8C82-663675B57A76} - http://www.fotoalba.cz (file missing) (HKCU)
O9 - Extra button: Xchat.cz - {535433DC-799E-4933-ABFD-85C3FD73AABC} - http://www.xchat.cz (file missing) (HKCU)
O9 - Extra button: Centrum.cz - {62FCE89E-7228-4B2F-85E5-EF4036286A90} - http://www.centrum.cz (file missing) (HKCU)
O9 - Extra button: Stahuj.cz - {A105EA4E-D180-401B-A429-34659CD84337} - http://www.stahuj.cz (file missing) (HKCU)
O9 - Extra button: Žena.cz - {CA9389BD-46C6-4A62-B2D4-FD6605FA96C2} - http://www.zena.cz (file missing) (HKCU)
O9 - Extra button: Aktuálně - {CAAEF9AB-2C6C-4A81-99DC-6F9DDD26BEC4} - http://aktualne.centrum.cz (file missing) (HKCU)
O9 - Extra button: Počasí - {DBD15340-F4AC-4F45-B9D3-DB287C0C4F29} - http://pocasi.centrum.cz (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Služba Google Update (gupdate1cabbbfe6a5be90) (gupdate1cabbbfe6a5be90) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe

--
End of file - 9980 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\At1.job
C:\WINDOWS\tasks\At10.job
C:\WINDOWS\tasks\At11.job
C:\WINDOWS\tasks\At12.job
C:\WINDOWS\tasks\At13.job
C:\WINDOWS\tasks\At14.job
C:\WINDOWS\tasks\At15.job
C:\WINDOWS\tasks\At16.job
C:\WINDOWS\tasks\At17.job
C:\WINDOWS\tasks\At18.job
C:\WINDOWS\tasks\At19.job
C:\WINDOWS\tasks\At2.job
C:\WINDOWS\tasks\At20.job
C:\WINDOWS\tasks\At21.job
C:\WINDOWS\tasks\At22.job
C:\WINDOWS\tasks\At23.job
C:\WINDOWS\tasks\At24.job
C:\WINDOWS\tasks\At3.job
C:\WINDOWS\tasks\At4.job
C:\WINDOWS\tasks\At5.job
C:\WINDOWS\tasks\At6.job
C:\WINDOWS\tasks\At7.job
C:\WINDOWS\tasks\At8.job
C:\WINDOWS\tasks\At9.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Install_NSS.job
C:\WINDOWS\tasks\NSSstub.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Spravce\Data aplikací\Mozilla\Firefox\Profiles\nx3qhs7k.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.google.cz/ig?hl=cs&source=webhp"
prefs.js - "extensions.enabledItems" - "{800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.19"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... id=afex&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.287 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll

C:\Program Files\Mozilla Firefox\extensions\
{800b5000-a755-47e1-992b-48a1c1357f07}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\Spravce\Data aplikací\Mozilla\Firefox\Profiles\nx3qhs7k.default\searchplugins\
icq-search.xml
icqplugin.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-04-05 251504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5825.1100\swg.dll [2010-10-29 841880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [2009-04-05 522224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-04-05 251504]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2007-12-21 1443072]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-02-24 5537792]
"SNPSTD2"=C:\WINDOWS\vsnpstd2.exe [2004-08-30 286720]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-04-05 39408]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2012-06-26 1516632]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-11-09 17877168]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Game Files\Valve\Condition Zero\czero.exe"="D:\Game Files\Valve\Condition Zero\czero.exe:*:Enabled:Condition Zero Launcher"
"D:\Game Files\Test Drive Unlimited\TestDriveUnlimited.exe"="D:\Game Files\Test Drive Unlimited\TestDriveUnlimited.exe:*:Enabled:Test Drive Unlimited"
"C:\Program Files\mozilla.org\Mozilla\mozilla.exe"="C:\Program Files\mozilla.org\Mozilla\mozilla.exe:*:Enabled:Mozilla"
"C:\Program Files\ICQLite\ICQLite.exe"="C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite"
"D:\Game Files\F1 2000\F1 2000\F1_2000.exe"="D:\Game Files\F1 2000\F1 2000\F1_2000.exe:*:Enabled:F1_2000"
"C:\Program Files\totalcmd\TOTALCMD.EXE"="C:\Program Files\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\BearShare Applications\BearShare\BearShare.exe"="C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Disabled:BearShare"
"C:\Program Files\BitLord\BitLord.exe"="C:\Program Files\BitLord\BitLord.exe:*:Disabled:BitLord"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll
"wave2"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-11-18 14:52:23 ----D---- C:\rsit
2012-11-18 14:52:23 ----D---- C:\Program Files\trend micro
2012-11-17 19:35:50 ----D---- C:\Program Files\Common Files\Skype
2012-11-17 19:35:32 ----RD---- C:\Program Files\Skype
2012-11-17 15:22:56 ----A---- C:\scu.dat
2012-11-08 19:08:19 ----D---- C:\Program Files\All Ten Fingers
2012-11-08 18:56:42 ----D---- C:\ATF
2012-10-28 17:59:31 ----D---- C:\Program Files\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2012-11-18 14:53:25 ----D---- C:\WINDOWS\Temp
2012-11-18 14:52:47 ----D---- C:\WINDOWS\Prefetch
2012-11-18 14:52:23 ----D---- C:\Program Files
2012-11-18 14:51:54 ----D---- C:\WINDOWS\system32
2012-11-18 14:51:54 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-11-18 14:49:00 ----D---- C:\Documents and Settings\Spravce\Data aplikací\Skype
2012-11-17 19:59:43 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-11-17 19:35:58 ----SHD---- C:\WINDOWS\Installer
2012-11-17 19:35:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2012-11-17 18:23:47 ----A---- C:\WINDOWS\NeroDigital.ini
2012-11-17 15:39:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2012-11-17 13:19:32 ----D---- C:\Program Files\Common Files
2012-11-17 13:16:37 ----D---- C:\WINDOWS
2012-11-17 13:10:55 ----D---- C:\Program Files\totalcmd
2012-11-17 13:10:55 ----D---- C:\Program Files\Celestia
2012-11-17 13:10:54 ----D---- C:\Documents and Settings\Spravce\Data aplikací\XnView
2012-11-17 13:03:12 ----D---- C:\WINDOWS\Minidump
2012-11-13 18:40:31 ----D---- C:\WINDOWS\system32\CatRoot2
2012-11-09 15:49:18 ----AC---- C:\WINDOWS\wincmd.ini
2012-10-31 18:25:48 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-10-27 18:34:59 ----RD---- C:\Dokumenty

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2004-08-03 61056]
R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2004-08-09 114016]
R0 prosync1;StarForce Protection Synchronization Driver v1; C:\WINDOWS\System32\drivers\prosync1.sys [2004-07-19 7040]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2006-10-18 36624]
R0 sfhlp01;StarForce Protection Helper Driver; C:\WINDOWS\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2012-06-29 477240]
R1 AmdK8;Ovladač procesoru AMD Athlon64; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2004-05-08 38400]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2012-10-07 242240]
R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2007-12-21 30216]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2007-12-21 53768]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-08-09 53920]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2011-03-20 278984]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2007-12-21 39944]
R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2007-12-21 71176]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2011-03-20 25416]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-06-20 2324480]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2007-12-21 30728]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-02-24 3454144]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-04-05 33536]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-04-05 12928]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 snpstd2;Trust WB-3400T Webcam; C:\WINDOWS\system32\DRIVERS\snpstd2.sys [2004-10-14 347264]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2009-07-13 91904]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
S3 adusbser;AnyDATA USB Device for Legacy Serial Communication; C:\WINDOWS\system32\DRIVERS\adusbser.sys [2006-10-23 93440]
S3 ag4atckb;ag4atckb; C:\WINDOWS\system32\drivers\ag4atckb.sys []
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-17 60800]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2004-08-03 17024]
S3 BTHMODEM;Ovladač komunikace modemu Bluetooth; C:\WINDOWS\system32\DRIVERS\bthmodem.sys [2004-08-03 38016]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2004-08-03 100992]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2004-08-17 274304]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2004-08-03 18944]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2012-01-09 18176]
S3 nmwcdc;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2012-01-09 23168]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2012-06-11 19072]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2004-08-03 59648]
S3 Ser2pl;Prolific Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2012-01-09 8192]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2004-08-03 25600]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2012-01-09 8192]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2009-07-13 132224]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-09-10 611664]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-02-24 127043]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2008-10-01 570880]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2012-06-11 724376]
S2 gupdate1cabbbfe6a5be90;Služba Google Update (gupdate1cabbbfe6a5be90); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-04 133104]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-09 250808]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2007-12-21 19200]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-04 133104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-05 137200]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe [2011-06-17 237008]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-28 115168]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 TUWinStylerThemeSvc;TuneUp WinStyler Theme Service; C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe [2004-08-05 117760]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]

-----------------EOF-----------------

Re: Zpomalení PC, zaseknutý spořič

Napsal: 18 lis 2012 18:58
od Rudy
1. Nainstalujte SP3, systém není aktuální.
2. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files\Google\Google Toolbar
C:\Program Files\Google\GoogleToolbarNotifier
C:\WINDOWS\tasks\At*.job
C:\Program Files\BearShare Applications

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=-
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\BearShare Applications\BearShare\BearShare.exe"=-

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
3. Odinstalujte Spybot a Ad-Aware. Mohou být v konfliktu nejen mezi sebou, ale i s antispywarem NODu.

Re: Zpomalení PC, zaseknutý spořič

Napsal: 21 lis 2012 21:17
od hkotrc
Systém jsem aktualizoval, otm projel a tady je nový rsit log. Spybot i Adware jsou také pryč.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Spravce at 2012-11-21 21:15:32
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 20 GB (25%) free of 79 GB
Total RAM: 1023 MB (52% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:15:46, on 21.11.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\vsnpstd2.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Skype\Updater\Updater.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Spravce\Plocha\RSIT.exe
C:\Program Files\trend micro\Spravce.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.superhry.cz/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.stahuj.cz/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Poskytovatel aplikace Windows Internet Explorer: Aktuálně.cz
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Bleskově - {17DF9729-2156-43E0-9414-9B380D6C6504} - http://www.bleskove.cz (file missing) (HKCU)
O9 - Extra button: Slovníky - {1E3BC114-E8D1-439F-95BC-2819A5BD7EDA} - http://slovniky.centrum.cz (file missing) (HKCU)
O9 - Extra button: Supermapy - {4CC5BCEE-FD7F-4A00-A6C6-4DC9B57301C7} - http://www.supermapy.cz (file missing) (HKCU)
O9 - Extra button: Fotoalba - {502F2D2B-918B-41A4-8C82-663675B57A76} - http://www.fotoalba.cz (file missing) (HKCU)
O9 - Extra button: Xchat.cz - {535433DC-799E-4933-ABFD-85C3FD73AABC} - http://www.xchat.cz (file missing) (HKCU)
O9 - Extra button: Centrum.cz - {62FCE89E-7228-4B2F-85E5-EF4036286A90} - http://www.centrum.cz (file missing) (HKCU)
O9 - Extra button: Stahuj.cz - {A105EA4E-D180-401B-A429-34659CD84337} - http://www.stahuj.cz (file missing) (HKCU)
O9 - Extra button: Žena.cz - {CA9389BD-46C6-4A62-B2D4-FD6605FA96C2} - http://www.zena.cz (file missing) (HKCU)
O9 - Extra button: Aktuálně - {CAAEF9AB-2C6C-4A81-99DC-6F9DDD26BEC4} - http://aktualne.centrum.cz (file missing) (HKCU)
O9 - Extra button: Počasí - {DBD15340-F4AC-4F45-B9D3-DB287C0C4F29} - http://pocasi.centrum.cz (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Služba Google Update (gupdate1cabbbfe6a5be90) (gupdate1cabbbfe6a5be90) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe

--
End of file - 9613 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Install_NSS.job
C:\WINDOWS\tasks\NSSstub.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Spravce\Data aplikací\Mozilla\Firefox\Profiles\nx3qhs7k.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.google.cz/ig?hl=cs&source=webhp"
prefs.js - "extensions.enabledItems" - "{800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.19"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... id=afex&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.287 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll

C:\Program Files\Mozilla Firefox\extensions\
{800b5000-a755-47e1-992b-48a1c1357f07}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\Spravce\Data aplikací\Mozilla\Firefox\Profiles\nx3qhs7k.default\searchplugins\
icq-search.xml
icqplugin.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2007-12-21 1443072]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-02-24 5537792]
"SNPSTD2"=C:\WINDOWS\vsnpstd2.exe [2004-08-30 286720]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2012-06-26 1516632]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-11-09 17877168]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Game Files\Valve\Condition Zero\czero.exe"="D:\Game Files\Valve\Condition Zero\czero.exe:*:Enabled:Condition Zero Launcher"
"D:\Game Files\Test Drive Unlimited\TestDriveUnlimited.exe"="D:\Game Files\Test Drive Unlimited\TestDriveUnlimited.exe:*:Enabled:Test Drive Unlimited"
"C:\Program Files\mozilla.org\Mozilla\mozilla.exe"="C:\Program Files\mozilla.org\Mozilla\mozilla.exe:*:Enabled:Mozilla"
"C:\Program Files\ICQLite\ICQLite.exe"="C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite"
"D:\Game Files\F1 2000\F1 2000\F1_2000.exe"="D:\Game Files\F1 2000\F1 2000\F1_2000.exe:*:Enabled:F1_2000"
"C:\Program Files\totalcmd\TOTALCMD.EXE"="C:\Program Files\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\BitLord\BitLord.exe"="C:\Program Files\BitLord\BitLord.exe:*:Disabled:BitLord"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll
"wave2"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-11-21 20:18:20 ----D---- C:\_OTM
2012-11-21 20:15:21 ----A---- C:\WINDOWS\OEWABLog.txt
2012-11-21 20:15:08 ----D---- C:\WINDOWS\Prefetch
2012-11-21 19:36:13 ----A---- C:\WINDOWS\setuplog.txt
2012-11-21 19:35:09 ----N---- C:\WINDOWS\system32\msxml6r.dll
2012-11-21 19:35:08 ----N---- C:\WINDOWS\system32\msxml6.dll
2012-11-21 19:35:06 ----N---- C:\WINDOWS\system32\drivers\irbus.sys
2012-11-21 19:35:06 ----N---- C:\WINDOWS\system32\comsdupd.exe
2012-11-21 19:35:05 ----N---- C:\WINDOWS\system32\smtpapi.dll
2012-11-21 19:35:05 ----N---- C:\WINDOWS\system32\rwnh.dll
2012-11-21 19:34:57 ----N---- C:\WINDOWS\system32\ati2dvag.dll
2012-11-21 19:34:57 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2012-11-21 19:34:57 ----N---- C:\WINDOWS\system32\ati2cqag.dll
2012-11-21 19:34:57 ----N---- C:\WINDOWS\system32\aaclient.dll
2012-11-21 19:34:56 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2012-11-21 19:34:55 ----N---- C:\WINDOWS\system32\ativvaxx.dll
2012-11-21 19:34:55 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2012-11-21 19:34:55 ----N---- C:\WINDOWS\system32\ati3duag.dll
2012-11-21 19:34:54 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2012-11-21 19:34:54 ----N---- C:\WINDOWS\system32\azroles.dll
2012-11-21 19:34:44 ----N---- C:\WINDOWS\system32\credssp.dll
2012-11-21 19:34:05 ----N---- C:\WINDOWS\system32\dot3api.dll
2012-11-21 19:34:05 ----N---- C:\WINDOWS\system32\dimsroam.dll
2012-11-21 19:34:05 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2012-11-21 19:34:05 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2012-11-21 19:33:56 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2012-11-21 19:33:56 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2012-11-21 19:33:48 ----N---- C:\WINDOWS\system32\dot3msm.dll
2012-11-21 19:33:48 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2012-11-21 19:33:39 ----N---- C:\WINDOWS\system32\dot3ui.dll
2012-11-21 19:33:39 ----N---- C:\WINDOWS\system32\dot3svc.dll
2012-11-21 19:33:38 ----N---- C:\WINDOWS\system32\eapolqec.dll
2012-11-21 19:33:30 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2012-11-21 19:33:18 ----N---- C:\WINDOWS\system32\eappcfg.dll
2012-11-21 19:33:09 ----N---- C:\WINDOWS\system32\eappgnui.dll
2012-11-21 19:33:01 ----N---- C:\WINDOWS\system32\eapphost.dll
2012-11-21 19:32:52 ----N---- C:\WINDOWS\system32\eappprxy.dll
2012-11-21 19:32:44 ----N---- C:\WINDOWS\system32\eapsvc.dll
2012-11-21 19:32:44 ----N---- C:\WINDOWS\system32\eapqec.dll
2012-11-21 19:32:42 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2012-11-21 19:32:39 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2012-11-21 19:32:38 ----N---- C:\WINDOWS\system32\kbdpash.dll
2012-11-21 19:32:38 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2012-11-21 19:32:38 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2012-11-21 19:32:29 ----N---- C:\WINDOWS\system32\kmsvc.dll
2012-11-21 19:32:21 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2012-11-21 19:32:19 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2012-11-21 19:32:19 ----N---- C:\WINDOWS\system32\mmcex.dll
2012-11-21 19:32:19 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2012-11-21 19:32:19 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2012-11-21 19:32:18 ----N---- C:\WINDOWS\system32\mmcperf.exe
2012-11-21 19:32:09 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2012-11-21 19:32:09 ----N---- C:\WINDOWS\system32\mssha.dll
2012-11-21 19:32:08 ----N---- C:\WINDOWS\system32\napipsec.dll
2012-11-21 19:32:08 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2012-11-21 19:31:59 ----N---- C:\WINDOWS\system32\onex.dll
2012-11-21 19:31:59 ----N---- C:\WINDOWS\system32\napstat.exe
2012-11-21 19:31:59 ----N---- C:\WINDOWS\system32\napmontr.dll
2012-11-21 19:31:57 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2012-11-21 19:31:49 ----N---- C:\WINDOWS\system32\qagent.dll
2012-11-21 19:31:40 ----N---- C:\WINDOWS\system32\qagentrt.dll
2012-11-21 19:31:32 ----N---- C:\WINDOWS\system32\qcliprov.dll
2012-11-21 19:31:24 ----N---- C:\WINDOWS\system32\qutil.dll
2012-11-21 19:31:23 ----N---- C:\WINDOWS\system32\s3gnb.dll
2012-11-21 19:31:23 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2012-11-21 19:31:23 ----N---- C:\WINDOWS\system32\rasqec.dll
2012-11-21 19:31:22 ----N---- C:\WINDOWS\system32\slgen.dll
2012-11-21 19:31:22 ----N---- C:\WINDOWS\system32\slextspk.dll
2012-11-21 19:31:22 ----N---- C:\WINDOWS\system32\slcoinst.dll
2012-11-21 19:31:22 ----N---- C:\WINDOWS\system32\setupn.exe
2012-11-21 19:31:21 ----N---- C:\WINDOWS\system32\slserv.exe
2012-11-21 19:31:21 ----N---- C:\WINDOWS\system32\slrundll.exe
2012-11-21 19:31:20 ----N---- C:\WINDOWS\system32\xpsp3res.dll
2012-11-21 19:31:19 ----N---- C:\WINDOWS\system32\verclsid.exe
2012-11-21 19:31:19 ----N---- C:\WINDOWS\system32\tzchange.exe
2012-11-21 19:31:19 ----N---- C:\WINDOWS\system32\tspkg.dll
2012-11-21 19:31:19 ----N---- C:\WINDOWS\system32\tsgqec.dll
2012-11-21 19:31:18 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2012-11-21 19:31:18 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2012-11-21 19:31:09 ----N---- C:\WINDOWS\system32\wmphoto.dll
2012-11-21 19:31:09 ----N---- C:\WINDOWS\system32\wlanapi.dll
2012-11-21 19:30:50 ----N---- C:\WINDOWS\slrundll.exe
2012-11-21 19:30:48 ----D---- C:\WINDOWS\l2schemas
2012-11-21 19:30:47 ----D---- C:\WINDOWS\system32\cs
2012-11-21 19:30:46 ----D---- C:\WINDOWS\system32\bits
2012-11-21 19:20:03 ----D---- C:\WINDOWS\ServicePackFiles
2012-11-21 19:15:11 ----D---- C:\WINDOWS\network diagnostic
2012-11-21 19:15:10 ----N---- C:\WINDOWS\system32\drivers\agp440.sys
2012-11-21 19:15:10 ----N---- C:\WINDOWS\system32\drivers\adv11nt5.dll
2012-11-21 19:15:10 ----N---- C:\WINDOWS\system32\drivers\adv09nt5.dll
2012-11-21 19:15:10 ----N---- C:\WINDOWS\system32\drivers\adv08nt5.dll
2012-11-21 19:15:10 ----N---- C:\WINDOWS\system32\drivers\adv07nt5.dll
2012-11-21 19:15:10 ----N---- C:\WINDOWS\system32\drivers\adv05nt5.dll
2012-11-21 19:15:10 ----N---- C:\WINDOWS\system32\drivers\adv02nt5.dll
2012-11-21 19:15:10 ----N---- C:\WINDOWS\system32\drivers\adv01nt5.dll
2012-11-21 19:15:09 ----N---- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2012-11-21 19:15:09 ----N---- C:\WINDOWS\system32\drivers\ati1btxx.sys
2012-11-21 19:15:09 ----N---- C:\WINDOWS\system32\drivers\amdagp.sys
2012-11-21 19:15:09 ----N---- C:\WINDOWS\system32\drivers\alim1541.sys
2012-11-21 19:15:09 ----N---- C:\WINDOWS\system32\drivers\agpcpq.sys
2012-11-21 19:15:08 ----N---- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2012-11-21 19:15:08 ----N---- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2012-11-21 19:15:08 ----N---- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2012-11-21 19:15:08 ----N---- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2012-11-21 19:15:08 ----N---- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2012-11-21 19:15:08 ----N---- C:\WINDOWS\system32\drivers\ati1snxx.sys
2012-11-21 19:15:08 ----N---- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2012-11-21 19:15:08 ----N---- C:\WINDOWS\system32\drivers\ati1raxx.sys
2012-11-21 19:15:08 ----N---- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2012-11-21 19:15:07 ----N---- C:\WINDOWS\system32\drivers\atinxbxx.sys
2012-11-21 19:15:07 ----N---- C:\WINDOWS\system32\drivers\atintuxx.sys
2012-11-21 19:15:07 ----N---- C:\WINDOWS\system32\drivers\atinttxx.sys
2012-11-21 19:15:07 ----N---- C:\WINDOWS\system32\drivers\atinsnxx.sys
2012-11-21 19:15:07 ----N---- C:\WINDOWS\system32\drivers\atinrvxx.sys
2012-11-21 19:15:07 ----N---- C:\WINDOWS\system32\drivers\atinraxx.sys
2012-11-21 19:15:07 ----N---- C:\WINDOWS\system32\drivers\atinpdxx.sys
2012-11-21 19:15:07 ----N---- C:\WINDOWS\system32\drivers\atinmdxx.sys
2012-11-21 19:15:07 ----N---- C:\WINDOWS\system32\drivers\atinbtxx.sys
2012-11-21 19:15:07 ----N---- C:\WINDOWS\system32\drivers\ati2mtag.sys
2012-11-21 19:15:06 ----N---- C:\WINDOWS\system32\drivers\atv10nt5.dll
2012-11-21 19:15:06 ----N---- C:\WINDOWS\system32\drivers\atv06nt5.dll
2012-11-21 19:15:06 ----N---- C:\WINDOWS\system32\drivers\atv04nt5.dll
2012-11-21 19:15:06 ----N---- C:\WINDOWS\system32\drivers\atv02nt5.dll
2012-11-21 19:15:06 ----N---- C:\WINDOWS\system32\drivers\atv01nt5.dll
2012-11-21 19:15:06 ----N---- C:\WINDOWS\system32\drivers\atinxsxx.sys
2012-11-21 19:15:05 ----N---- C:\WINDOWS\system32\drivers\bthprint.sys
2012-11-21 19:15:04 ----N---- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
2012-11-21 19:15:04 ----N---- C:\WINDOWS\system32\drivers\hidbth.sys
2012-11-21 19:15:04 ----N---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2012-11-21 19:15:04 ----N---- C:\WINDOWS\system32\drivers\gagp30kx.sys
2012-11-21 19:15:03 ----N---- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2012-11-21 19:15:03 ----N---- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2012-11-21 19:15:03 ----N---- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2012-11-21 19:15:03 ----N---- C:\WINDOWS\system32\drivers\hidir.sys
2012-11-21 19:15:02 ----N---- C:\WINDOWS\system32\drivers\mtlstrm.sys
2012-11-21 19:15:02 ----N---- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2012-11-21 19:15:02 ----N---- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2012-11-21 19:15:01 ----N---- C:\WINDOWS\system32\drivers\recagent.sys
2012-11-21 19:15:01 ----N---- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2012-11-21 19:15:01 ----N---- C:\WINDOWS\system32\drivers\mutohpen.sys
2012-11-21 19:15:01 ----N---- C:\WINDOWS\system32\drivers\mtxparhm.sys
2012-11-21 19:15:00 ----N---- C:\WINDOWS\system32\drivers\sisagp.sys
2012-11-21 19:15:00 ----N---- C:\WINDOWS\system32\drivers\siint5.dll
2012-11-21 19:15:00 ----N---- C:\WINDOWS\system32\drivers\sffp_mmc.sys
2012-11-21 19:15:00 ----N---- C:\WINDOWS\system32\drivers\s3gnbm.sys
2012-11-21 19:15:00 ----N---- C:\WINDOWS\system32\drivers\rndismpx.sys
2012-11-21 19:14:59 ----N---- C:\WINDOWS\system32\drivers\uagp35.sys
2012-11-21 19:14:59 ----N---- C:\WINDOWS\system32\drivers\smbali.sys
2012-11-21 19:14:59 ----N---- C:\WINDOWS\system32\drivers\slwdmsup.sys
2012-11-21 19:14:59 ----N---- C:\WINDOWS\system32\drivers\slnthal.sys
2012-11-21 19:14:59 ----N---- C:\WINDOWS\system32\drivers\slntamr.sys
2012-11-21 19:14:59 ----N---- C:\WINDOWS\system32\drivers\slnt7554.sys
2012-11-21 19:14:58 ----N---- C:\WINDOWS\system32\drivers\wadv08nt.sys
2012-11-21 19:14:58 ----N---- C:\WINDOWS\system32\drivers\wadv07nt.sys
2012-11-21 19:14:58 ----N---- C:\WINDOWS\system32\drivers\wacompen.sys
2012-11-21 19:14:58 ----N---- C:\WINDOWS\system32\drivers\viaagp.sys
2012-11-21 19:14:58 ----N---- C:\WINDOWS\system32\drivers\vchnt5.dll
2012-11-21 19:14:58 ----N---- C:\WINDOWS\system32\drivers\usbvideo.sys
2012-11-21 19:14:58 ----N---- C:\WINDOWS\system32\drivers\usb8023x.sys
2012-11-21 19:14:57 ----N---- C:\WINDOWS\system32\drivers\watv10nt.sys
2012-11-21 19:14:57 ----N---- C:\WINDOWS\system32\drivers\watv06nt.sys
2012-11-21 19:14:57 ----N---- C:\WINDOWS\system32\drivers\wadv11nt.sys
2012-11-21 19:14:57 ----N---- C:\WINDOWS\system32\drivers\wadv09nt.sys
2012-11-21 19:05:18 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2012-11-18 14:52:23 ----D---- C:\rsit
2012-11-18 14:52:23 ----D---- C:\Program Files\trend micro
2012-11-17 19:35:50 ----D---- C:\Program Files\Common Files\Skype
2012-11-17 19:35:32 ----RD---- C:\Program Files\Skype
2012-11-17 15:22:56 ----A---- C:\scu.dat
2012-11-08 19:08:19 ----D---- C:\Program Files\All Ten Fingers
2012-11-08 18:56:42 ----D---- C:\ATF
2012-10-28 17:59:31 ----D---- C:\Program Files\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2012-11-21 21:15:33 ----D---- C:\WINDOWS\Temp
2012-11-21 21:15:25 ----D---- C:\Documents and Settings\Spravce\Data aplikací\Skype
2012-11-21 20:24:25 ----D---- C:\WINDOWS\system32
2012-11-21 20:24:25 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-11-21 20:18:55 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-11-21 20:18:40 ----D---- C:\WINDOWS
2012-11-21 20:18:21 ----SD---- C:\WINDOWS\Tasks
2012-11-21 20:18:21 ----D---- C:\Program Files\Google
2012-11-21 20:16:25 ----D---- C:\WINDOWS\Debug
2012-11-21 20:15:28 ----D---- C:\WINDOWS\system32\CatRoot2
2012-11-21 20:14:19 ----D---- C:\WINDOWS\system32\wbem
2012-11-21 20:14:19 ----D---- C:\WINDOWS\system32\Setup
2012-11-21 20:14:19 ----D---- C:\WINDOWS\AppPatch
2012-11-21 20:14:17 ----RSD---- C:\WINDOWS\Fonts
2012-11-21 20:14:12 ----D---- C:\WINDOWS\system32\drivers
2012-11-21 20:13:33 ----D---- C:\WINDOWS\security
2012-11-21 19:38:16 ----HD---- C:\WINDOWS\inf
2012-11-21 19:37:59 ----D---- C:\WINDOWS\system32\CatRoot
2012-11-21 19:35:23 ----D---- C:\WINDOWS\WinSxS
2012-11-21 19:35:16 ----D---- C:\Program Files\Messenger
2012-11-21 19:35:10 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-11-21 19:35:07 ----D---- C:\WINDOWS\ehome
2012-11-21 19:35:05 ----D---- C:\WINDOWS\system32\inetsrv
2012-11-21 19:35:03 ----D---- C:\WINDOWS\ime
2012-11-21 19:35:02 ----D---- C:\WINDOWS\Help
2012-11-21 19:30:50 ----D---- C:\WINDOWS\system32\cs-cz
2012-11-21 19:30:49 ----D---- C:\WINDOWS\system32\usmt
2012-11-21 19:30:47 ----SHD---- C:\WINDOWS\Installer
2012-11-21 19:30:46 ----D---- C:\WINDOWS\PeerNet
2012-11-21 19:30:45 ----D---- C:\Program Files\Movie Maker
2012-11-21 19:19:38 ----D---- C:\WINDOWS\system32\Restore
2012-11-21 19:19:38 ----D---- C:\WINDOWS\system32\npp
2012-11-21 19:19:36 ----D---- C:\WINDOWS\msagent
2012-11-21 19:19:32 ----D---- C:\WINDOWS\srchasst
2012-11-21 19:19:26 ----D---- C:\Program Files\NetMeeting
2012-11-21 19:19:23 ----D---- C:\WINDOWS\system32\Com
2012-11-21 19:19:19 ----D---- C:\Program Files\Windows Media Player
2012-11-21 19:19:17 ----D---- C:\Program Files\Windows NT
2012-11-21 19:19:17 ----D---- C:\Program Files\Outlook Express
2012-11-21 19:19:11 ----D---- C:\Program Files\Common Files\System
2012-11-21 19:18:33 ----D---- C:\WINDOWS\system32\oobe
2012-11-21 19:18:30 ----D---- C:\WINDOWS\system
2012-11-19 19:36:27 ----SD---- C:\WINDOWS\Downloaded Program Files
2012-11-18 14:52:23 ----D---- C:\Program Files
2012-11-17 19:35:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2012-11-17 18:23:47 ----A---- C:\WINDOWS\NeroDigital.ini
2012-11-17 15:39:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2012-11-17 13:19:32 ----D---- C:\Program Files\Common Files
2012-11-17 13:10:55 ----D---- C:\Program Files\totalcmd
2012-11-17 13:10:55 ----D---- C:\Program Files\Celestia
2012-11-17 13:10:54 ----D---- C:\Documents and Settings\Spravce\Data aplikací\XnView
2012-11-17 13:03:12 ----D---- C:\WINDOWS\Minidump
2012-11-09 15:49:18 ----AC---- C:\WINDOWS\wincmd.ini
2012-10-31 18:25:48 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-10-27 18:34:59 ----RD---- C:\Dokumenty

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2004-08-09 114016]
R0 prosync1;StarForce Protection Synchronization Driver v1; C:\WINDOWS\System32\drivers\prosync1.sys [2004-07-19 7040]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2006-10-18 36624]
R0 sfhlp01;StarForce Protection Helper Driver; C:\WINDOWS\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2012-06-29 477240]
R1 AmdK8;Ovladač procesoru AMD Athlon64; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2004-05-08 38400]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2012-10-07 242240]
R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2007-12-21 30216]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2007-12-21 53768]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-08-09 53920]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2011-03-20 278984]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2007-12-21 39944]
R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2007-12-21 71176]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2011-03-20 25416]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-06-20 2324480]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2007-12-21 30728]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-02-24 3454144]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-04-05 33536]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-04-05 12928]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 snpstd2;Trust WB-3400T Webcam; C:\WINDOWS\system32\DRIVERS\snpstd2.sys [2004-10-14 347264]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2009-07-13 91904]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 aa2x8uy6;aa2x8uy6; C:\WINDOWS\system32\drivers\aa2x8uy6.sys []
S3 adusbser;AnyDATA USB Device for Legacy Serial Communication; C:\WINDOWS\system32\DRIVERS\adusbser.sys [2006-10-23 93440]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 BthEnum;Služba Bluetooth Enumerator; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-14 17024]
S3 BTHMODEM;Ovladač komunikace modemu Bluetooth; C:\WINDOWS\system32\DRIVERS\bthmodem.sys [2008-04-14 37888]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-14 101120]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-04-14 272896]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-14 18944]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2012-01-09 18176]
S3 nmwcdc;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2012-01-09 23168]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2012-06-11 19072]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-14 59136]
S3 Ser2pl;Prolific Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2012-01-09 8192]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-14 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2012-01-09 8192]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2009-07-13 132224]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-09-10 611664]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-02-24 127043]
R2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-11-09 160944]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2008-10-01 570880]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2012-06-11 724376]
S2 gupdate1cabbbfe6a5be90;Služba Google Update (gupdate1cabbbfe6a5be90); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-04 133104]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-09 250808]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2007-12-21 19200]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-04 133104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-05 137200]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe [2011-06-17 237008]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-28 115168]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 TUWinStylerThemeSvc;TuneUp WinStyler Theme Service; C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe [2004-08-05 117760]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]

-----------------EOF-----------------

Re: Zpomalení PC, zaseknutý spořič

Napsal: 21 lis 2012 21:47
od Rudy
Dvouklikem na soubor C:\Program Files\trend micro\Spravce.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
R3 - URLSearchHook: (no name) - - (no file)
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: Bleskově - {17DF9729-2156-43E0-9414-9B380D6C6504} - http://www.bleskove.cz (file missing) (HKCU)
O9 - Extra button: Slovníky - {1E3BC114-E8D1-439F-95BC-2819A5BD7EDA} - http://slovniky.centrum.cz (file missing) (HKCU)
O9 - Extra button: Supermapy - {4CC5BCEE-FD7F-4A00-A6C6-4DC9B57301C7} - http://www.supermapy.cz (file missing) (HKCU)
O9 - Extra button: Fotoalba - {502F2D2B-918B-41A4-8C82-663675B57A76} - http://www.fotoalba.cz (file missing) (HKCU)
O9 - Extra button: Xchat.cz - {535433DC-799E-4933-ABFD-85C3FD73AABC} - http://www.xchat.cz (file missing) (HKCU)
O9 - Extra button: Centrum.cz - {62FCE89E-7228-4B2F-85E5-EF4036286A90} - http://www.centrum.cz (file missing) (HKCU)
O9 - Extra button: Stahuj.cz - {A105EA4E-D180-401B-A429-34659CD84337} - http://www.stahuj.cz (file missing) (HKCU)
O9 - Extra button: Žena.cz - {CA9389BD-46C6-4A62-B2D4-FD6605FA96C2} - http://www.zena.cz (file missing) (HKCU)
O9 - Extra button: Aktuálně - {CAAEF9AB-2C6C-4A81-99DC-6F9DDD26BEC4} - http://aktualne.centrum.cz (file missing) (HKCU)
O9 - Extra button: Počasí - {DBD15340-F4AC-4F45-B9D3-DB287C0C4F29} - http://pocasi.centrum.cz (file missing) (HKCU)
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.

Re: Zpomalení PC, zaseknutý spořič

Napsal: 22 lis 2012 18:52
od hkotrc
Uděláno :)

Re: Zpomalení PC, zaseknutý spořič

Napsal: 22 lis 2012 19:39
od Rudy
OK. Nastala nějaká změna?

Re: Zpomalení PC, zaseknutý spořič

Napsal: 22 lis 2012 21:02
od hkotrc
Už jsem se k tomu dostal na delší dobu a změna nenastala:/ PC je stále zasekaný. Chápu, že nebude běhat jako nový, ale aspoň ho zbavit havěti bych chtěl:)

Re: Zpomalení PC, zaseknutý spořič

Napsal: 22 lis 2012 21:09
od Rudy
Zkuste obnovu systému k datu, kdy korketně fungoval. Pokud se nic nezmění ani pak, dejte log ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware

Re: Zpomalení PC, zaseknutý spořič

Napsal: 25 lis 2012 12:55
od hkotrc
Tak nakonec pomohla obnova systému k datu, co to pracovalo dobře. Díky moc za rady!
Ještě bych se chtěl zeptat..tou obnovou se vrátil service pack 2. Je asi lepší tam dát ten novější, co?

Re: Zpomalení PC, zaseknutý spořič

Napsal: 25 lis 2012 13:05
od Rudy
Ještě bych se chtěl zeptat..tou obnovou se vrátil service pack 2. Je asi lepší tam dát ten novější, co?
Zcela určitě a hlavně mít zapnuty aut. aktualizace. Tím je systém zabezpečen proti napadení.

Re: Zpomalení PC, zaseknutý spořič

Napsal: 25 lis 2012 15:26
od hkotrc
Ok, nastavím to, děkuju vám:)

Re: Zpomalení PC, zaseknutý spořič

Napsal: 25 lis 2012 16:54
od Rudy
Nemáte zač!