Stránka 1 z 1

Sekající se hry po instalaci avg 2013

Napsal: 20 led 2013 14:48
od kamzl
Zdravim, po instalaci avg internet security 2013 se mi budto nespustí nebo při hraní jak online tak offline sekne komp.

Dřívější stav byl avast, pak jsem dal to avg 2013, našel mi pět virů po té sem použil combofix.
Můj odhad byl že to dělaj ovladače grafárny, což mi ale dx diag vyvrátil.
Zdá se mi i že ping na net je pomalejší, načítání stránek myslim.

Více viz LOG, prosím o radu co s tim, díky.

ComboFix 13-01-17.04 - jpk 19.01.2013 17:04:34.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1279.720 [GMT 1:00]
Spuštěný z: E:\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\jpk\WINDOWS
c:\windows\IsUn0405.exe
c:\windows\iun6002.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\DEBUG.log
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\muzapp.exe
c:\windows\system32\Oleaut32.1
c:\windows\system32\oobe\msoobe.err
c:\windows\system32\SET16C.tmp
c:\windows\system32\SET4D.tmp
c:\windows\system32\TZLog.log
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-12-19 do 2013-01-19 )))))))))))))))))))))))))))))))
.
.
2013-01-19 15:54 . 2013-01-19 15:54 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Oblíbené položky
2013-01-18 19:30 . 2013-01-18 19:30 -------- d-----w- c:\documents and settings\jpk\Data aplikací\AVG2013
2013-01-18 19:30 . 2013-01-18 19:30 -------- d-----w- c:\windows\system32\config\systemprofile\Data aplikací\AVG2013
2013-01-18 19:29 . 2013-01-18 19:29 -------- d-----w- c:\documents and settings\jpk\Data aplikací\TuneUp Software
2013-01-18 19:26 . 2013-01-18 19:30 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\AVG2013
2013-01-18 19:26 . 2013-01-18 19:26 -------- d-----w- C:\$AVG
2013-01-18 19:25 . 2013-01-18 19:25 -------- d-----w- c:\program files\AVG
2013-01-18 19:22 . 2013-01-18 19:22 -------- d--h--w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Common Files
2013-01-18 19:22 . 2013-01-19 15:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\MFAData
2013-01-18 19:22 . 2013-01-18 19:41 -------- d-----w- c:\documents and settings\jpk\Local Settings\Data aplikací\Avg2013
2013-01-18 19:22 . 2013-01-18 19:22 -------- d-----w- c:\documents and settings\jpk\Local Settings\Data aplikací\MFAData
2013-01-18 18:51 . 2013-01-18 19:16 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Kaspersky Lab
2013-01-18 18:27 . 2013-01-18 18:27 227424 ----a-w- c:\documents and settings\All Users.WINDOWS\Data aplikací\1358533384.bdinstall.bin
2013-01-18 11:40 . 2013-01-18 11:40 -------- d-----w- c:\documents and settings\jpk\Local Settings\Data aplikací\PCHealth
2013-01-18 09:38 . 2008-09-24 19:41 839680 ----a-w- c:\windows\system32\lameACM.acm
2013-01-18 09:38 . 2004-05-18 19:16 39936 ----a-w- c:\windows\system32\huffyuv.dll
2013-01-18 09:38 . 2012-07-01 23:15 4102656 ----a-w- c:\windows\system32\x264vfw.dll
2013-01-18 09:38 . 2011-12-07 18:32 216064 ----a-w- c:\windows\system32\lagarith.dll
2013-01-18 09:38 . 2011-06-24 15:44 243200 ----a-w- c:\windows\system32\xvidvfw.dll
2013-01-18 09:38 . 2011-06-24 15:28 650752 ----a-w- c:\windows\system32\xvidcore.dll
2013-01-18 09:38 . 2011-12-21 18:14 151552 ----a-w- c:\windows\system32\ac3acm.acm
2013-01-18 09:37 . 2012-12-24 18:00 112640 ----a-w- c:\windows\system32\ff_vfw.dll
2013-01-17 15:04 . 2013-01-17 15:04 -------- d-----w- c:\windows\system32\config\systemprofile\Data aplikací\Bitdefender
2013-01-17 10:01 . 2013-01-17 10:01 735311 ----a-w- c:\documents and settings\All Users.WINDOWS\Data aplikací\1358414556.bdinstall.bin
2013-01-17 09:50 . 2013-01-17 12:41 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\BDLogging
2013-01-17 09:48 . 2007-04-11 09:11 511328 ----a-w- c:\windows\capicom.dll
2013-01-17 09:47 . 2009-07-14 21:27 1461992 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2013-01-17 09:31 . 2013-01-17 09:31 -------- d-----w- c:\documents and settings\jpk\Data aplikací\QuickScan
2013-01-17 08:56 . 2013-01-18 18:25 -------- d-----w- c:\program files\Common Files\Bitdefender
2013-01-15 21:56 . 2013-01-16 10:41 -------- d-----w- c:\program files\SCi
2013-01-15 21:56 . 2000-01-04 05:39 212992 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\ILog.dll
2013-01-15 20:41 . 2013-01-15 20:41 -------- d-----w- c:\documents and settings\jpk\Local Settings\Data aplikací\URSE Games
2013-01-15 19:24 . 2013-01-15 19:24 -------- d-----w- c:\documents and settings\jpk\Data aplikací\Enki Games
2013-01-15 17:32 . 2013-01-15 17:34 -------- d-----w- c:\program files\Unlock Codes Calculator (by Crux)
2013-01-15 15:46 . 2013-01-15 15:46 -------- d-----w- c:\documents and settings\jpk\Data aplikací\Alawar
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-19 15:30 . 2011-12-20 16:06 214520 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-01-19 15:30 . 2011-12-20 16:05 214520 ----a-w- c:\windows\system32\PnkBstrB.xtr
2013-01-16 18:51 . 2011-12-20 16:27 137464 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-12-16 12:31 . 2010-01-14 14:59 290560 ----a-w- c:\windows\system32\atmfd.dll
2012-12-02 15:02 . 2011-12-20 16:05 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-11-15 22:33 . 2012-11-15 22:33 94048 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2012-11-13 11:56 . 2010-01-14 15:02 1875456 ----a-w- c:\windows\system32\win32k.sys
2012-11-08 10:29 . 2012-11-08 10:29 1402312 ----a-w- c:\windows\system32\msxml4.dll
2012-11-06 02:00 . 2010-01-14 15:01 1446912 ----a-w- c:\windows\system32\msxml6.dll
2012-11-02 02:03 . 2008-04-14 11:00 375296 ----a-w- c:\windows\system32\dpnet.dll
2012-11-01 22:54 . 2012-09-07 18:02 139152 ----a-w- c:\documents and settings\jpk\Data aplikací\PnkBstrK.sys
2012-11-01 22:53 . 2012-09-07 18:02 794408 ----a-w- c:\windows\system32\pbsvc.exe
2012-11-01 12:11 . 2010-01-14 15:02 920064 ----a-w- c:\windows\system32\wininet.dll
2012-11-01 12:11 . 2010-01-14 15:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-11-01 12:11 . 2010-01-14 15:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-10-31 23:39 . 2010-01-14 15:00 385024 ----a-w- c:\windows\system32\html.iec
2012-10-22 12:02 . 2012-10-22 12:02 179936 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2011-09-29 07:07 . 2011-11-08 15:58 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"Advanced SystemCare 6"="c:\program files\IObit\Advanced SystemCare 6\ASCTray.exe" [2012-09-24 490880]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"="Mixer.exe" [2002-10-15 1818624]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"AVG_UI"="c:\program files\AVG\AVG2013\avgui.exe" [2012-12-11 3147384]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2013\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^Bluetooth Manager.lnk]
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^GamePark klient 2.lnk]
backup=c:\windows\pss\GamePark klient 2.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Nabídka Start\Programy\Po spuštění\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^jpk^Nabídka Start^Programy^Po spuštění^Facebook Messenger.lnk]
backup=c:\windows\pss\Facebook Messenger.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioDeck
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CmPCIaudio
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cpqek
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Free Navigator Installer 5.0
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InkMonitor
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesAirMessage
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smart File Advisor
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-12-03 07:35 946352 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-01-20 09:20 1305408 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-11-21 22:13 136176 ----atw- c:\documents and settings\jpk\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-10-14 20:17 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
2007-08-22 15:31 80896 ----a-w- c:\program files\HP\Digital Imaging\bin\HpqSRmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 06:52 1695232 --sh--w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=3 (0x3)
"wscsvc"=2 (0x2)
"Schedule"=2 (0x2)
"helpsvc"=3 (0x3)
"CiSvc"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"PnkBstrA"=2 (0x2)
"EPSON_PM_RPCV4_01"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\CesarFTP\\Server.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"e:\\hry\\NFS Underground\\Speed.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgemcx.exe"=
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [15.10.2012 3:48 55776]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [21.9.2012 3:46 177376]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [14.9.2012 3:05 35552]
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [22.10.2012 13:02 179936]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [21.9.2012 3:45 19936]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2.10.2012 3:30 159712]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [21.9.2012 3:46 164832]
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files\IObit\Advanced SystemCare 6\ASCService.exe [25.10.2012 12:20 1026432]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2013\avgwdsvc.exe [22.10.2012 13:05 196664]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [12.1.2012 19:52 30944]
S1 DumpDrv;Crash Dump Driver;c:\windows\system32\drivers\dumpdrv.sys [14.1.2010 16:04 9472]
S2 avgfws;AVG Firewall;c:\program files\AVG\AVG2013\avgfws.exe [10.12.2012 11:11 1342024]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2013\avgidsagent.exe [15.11.2012 23:34 5814904]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [3.11.2012 0:45 30312]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [12.1.2012 19:52 30944]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [19.5.2012 0:17 20032]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [23.5.2012 10:30 112640]
S3 fdrawcmd;Low-level Floppy Driver; [x]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [28.8.2012 16:34 12400]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [23.5.2012 10:48 100480]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [3.11.2012 0:45 121192]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [3.11.2012 0:45 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [3.11.2012 0:45 136680]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [3.11.2012 0:45 114152]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - PNKBSTRB
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
mStart Page = about:blank
uInternet Settings,ProxyServer = 192.168.0.1:80
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-10 - (no file)
Notify-RailNotification - (no file)
MSConfigStartUp-EPSON Stylus DX4400 Series - c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-19 17:16
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
Celkový čas: 2013-01-19 17:21:07
ComboFix-quarantined-files.txt 2013-01-19 16:20
.
Před spuštěním: Volných bajtů: 55 648 030 720
Po spuštění: Volných bajtů: 56 016 084 992
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 0E477C0DACBAD63F054E16611C730B3A

Posílám LOg ze Rsitu. Prosím o zkouknutí.

Napsal: 20 led 2013 16:53
od kamzl
Logfile of random's system information tool 1.09 (written by random/random)
Run by jpk at 2013-01-20 16:21:52
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 52 GB (40%) free of 131 GB
Total RAM: 1279 MB (52% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:22:39, on 20.1.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG2013\avgfws.exe
C:\Program Files\AVG\AVG2013\avgidsagent.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\AVG\AVG2013\avgnsx.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\AVG\AVG2013\avgemcx.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\jpk\Dokumenty\Downloads\RSIT.exe
C:\Program Files\trend micro\jpk.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)
O2 - BHO: (no name) - {CA4520F3-AE13-4FB1-A513-58E23991C86D} - (no file)
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - (no file)
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

--
End of file - 4424 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4520F3-AE13-4FB1-A513-58E23991C86D}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"=Mixer.exe /startup []
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-16 13529088]
"AVG_UI"=C:\Program Files\AVG\AVG2013\avgui.exe [2012-12-11 3147384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\jpk\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-11-21 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^Bluetooth Manager.lnk]
C:\PROGRA~1\Toshiba\BLUETO~1\TosBtMng.exe [2007-02-02 2756608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^GamePark klient 2.lnk]
C:\PROGRA~1\GAMEPA~1\gpcl.exe [2011-07-29 409088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-10-14 214360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^Windows Search.lnk]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^jpk^Nabídka Start^Programy^Po spuštění^Facebook Messenger.lnk]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2
"wscsvc"=2
"Schedule"=2
"helpsvc"=2
"CiSvc"=3
"WMPNetworkSvc"=3
"PnkBstrA"=2
"EPSON_PM_RPCV4_01"=2

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-06-03 190464]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2010-01-14 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoResolveSearch"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe"="C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\Program Files\CesarFTP\Server.exe"="C:\Program Files\CesarFTP\Server.exe:*:Enabled:Server"
"C:\Program Files\Vuze\Azureus.exe"="C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"E:\hry\NFS Underground\Speed.exe"="E:\hry\NFS Underground\Speed.exe:*:Enabled:Speed"
"C:\Program Files\AVG\AVG2013\avgnsx.exe"="C:\Program Files\AVG\AVG2013\avgnsx.exe:*:Enabled:Webový štít"
"C:\Program Files\AVG\AVG2013\avgdiagex.exe"="C:\Program Files\AVG\AVG2013\avgdiagex.exe:*:Enabled:AVG Diagnostika 2013"
"C:\Program Files\AVG\AVG2013\avgmfapx.exe"="C:\Program Files\AVG\AVG2013\avgmfapx.exe:*:Enabled:Instalátor AVG"
"C:\Program Files\AVG\AVG2013\avgemcx.exe"="C:\Program Files\AVG\AVG2013\avgemcx.exe:*:Enabled:Obecná kontrola pošty"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"VIDC.XVID"=xvidvfw.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.HFYU"=huffyuv.dll
"VIDC.FFDS"=ff_vfw.dll
"VIDC.X264"=x264vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"msacm.l3codecp"=l3codecp.acm

======List of files/folders created in the last 1 month======

2013-01-20 16:21:57 ----D---- C:\Program Files\trend micro
2013-01-20 16:21:52 ----D---- C:\rsit
2013-01-20 15:47:43 ----D---- C:\Program Files\CCleaner
2013-01-20 15:23:09 ----A---- C:\WINDOWS\UPGRADE.TXT
2013-01-20 12:09:53 ----A---- C:\WINDOWS\imsins.BAK
2013-01-20 12:09:31 ----A---- C:\WINDOWS\system32\SET2C.tmp
2013-01-19 17:34:38 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2013-01-19 17:32:12 ----SHD---- C:\RECYCLER
2013-01-19 17:27:10 ----D---- C:\Program Files\xerox
2013-01-19 17:21:08 ----A---- C:\ComboFix.txt
2013-01-19 16:58:08 ----A---- C:\Boot.bak
2013-01-19 16:57:48 ----RASHD---- C:\cmdcons
2013-01-19 16:55:03 ----A---- C:\WINDOWS\zip.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\SWXCACLS.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\SWSC.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\SWREG.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\sed.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\PEV.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\NIRCMD.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\MBR.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\grep.exe
2013-01-19 16:54:28 ----D---- C:\Qoobox
2013-01-19 16:53:43 ----D---- C:\WINDOWS\erdnt
2013-01-18 20:30:56 ----D---- C:\Documents and Settings\jpk\Data aplikací\AVG2013
2013-01-18 20:29:28 ----D---- C:\Documents and Settings\jpk\Data aplikací\TuneUp Software
2013-01-18 20:26:50 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\AVG2013
2013-01-18 20:26:50 ----D---- C:\$AVG
2013-01-18 20:25:16 ----D---- C:\Program Files\AVG
2013-01-18 20:22:06 ----HD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Common Files
2013-01-18 20:22:05 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\MFAData
2013-01-18 19:51:53 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Kaspersky Lab
2013-01-18 10:48:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2757638$
2013-01-18 10:48:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2753842-v2$
2013-01-18 10:47:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2779562$
2013-01-18 10:45:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2770660$
2013-01-18 10:45:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2779030$
2013-01-18 10:45:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2758857$
2013-01-18 10:44:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2727528$
2013-01-18 10:38:14 ----A---- C:\WINDOWS\system32\huffyuv.dll
2013-01-18 10:38:13 ----A---- C:\WINDOWS\system32\x264vfw.dll
2013-01-18 10:38:13 ----A---- C:\WINDOWS\system32\lagarith.dll
2013-01-18 10:38:12 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2013-01-18 10:38:12 ----A---- C:\WINDOWS\system32\xvidcore.dll
2013-01-18 10:37:55 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2013-01-17 16:07:40 ----A---- C:\bdlog.txt
2013-01-17 10:50:06 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\BDLogging
2013-01-17 10:48:23 ----A---- C:\WINDOWS\capicom.dll
2013-01-17 10:47:31 ----A---- C:\WINDOWS\system32\WdfCoInstaller01009.dll
2013-01-17 10:31:26 ----D---- C:\Documents and Settings\jpk\Data aplikací\QuickScan
2013-01-17 09:56:46 ----D---- C:\Program Files\Common Files\Bitdefender
2013-01-15 22:56:18 ----D---- C:\Program Files\SCi
2013-01-15 20:24:49 ----D---- C:\Documents and Settings\jpk\Data aplikací\Enki Games
2013-01-15 16:46:00 ----D---- C:\Documents and Settings\jpk\Data aplikací\Alawar

======List of files/folders modified in the last 1 month======

2013-01-20 16:21:57 ----RD---- C:\Program Files
2013-01-20 16:19:20 ----SHD---- C:\WINDOWS\Installer
2013-01-20 16:18:20 ----D---- C:\Config.Msi
2013-01-20 16:17:38 ----D---- C:\WINDOWS\system32
2013-01-20 16:17:30 ----D---- C:\Program Files\Common Files
2013-01-20 16:16:25 ----D---- C:\Program Files\HP
2013-01-20 16:16:25 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\HP
2013-01-20 15:39:10 ----HD---- C:\WINDOWS\$hf_mig$
2013-01-20 15:39:03 ----RSHDC---- C:\WINDOWS\system32\dllcache
2013-01-20 15:38:55 ----D---- C:\WINDOWS
2013-01-20 15:38:27 ----D---- C:\Program Files\Microsoft Office
2013-01-20 15:37:59 ----D---- C:\Program Files\Messenger
2013-01-20 15:27:43 ----D---- C:\WINDOWS\Temp
2013-01-20 15:27:22 ----D---- C:\WINDOWS\system32\CatRoot2
2013-01-20 15:25:09 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-01-20 15:24:50 ----RASH---- C:\boot.ini
2013-01-20 15:24:50 ----A---- C:\WINDOWS\win.ini
2013-01-20 15:24:50 ----A---- C:\WINDOWS\system.ini
2013-01-20 15:21:41 ----D---- C:\Documents and Settings\jpk\Data aplikací\DAEMON Tools Lite
2013-01-20 15:21:41 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\DAEMON Tools Lite
2013-01-20 15:20:14 ----D---- C:\WINDOWS\system32\Restore
2013-01-20 15:14:04 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2013-01-20 13:59:57 ----D---- C:\WINDOWS\Microsoft.NET
2013-01-20 13:49:33 ----RSD---- C:\WINDOWS\assembly
2013-01-20 13:05:13 ----D---- C:\Downloads
2013-01-20 12:10:02 ----HD---- C:\WINDOWS\inf
2013-01-20 12:09:30 ----D---- C:\WINDOWS\ie8updates
2013-01-20 12:07:53 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2013-01-20 12:06:58 ----D---- C:\WINDOWS\WinSxS
2013-01-19 20:32:14 ----D---- C:\WINDOWS\system32\drivers
2013-01-19 18:01:30 ----D---- C:\Program Files\Microsoft ActiveSync
2013-01-19 18:00:35 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-01-19 17:34:37 ----D---- C:\WINDOWS\Help
2013-01-19 17:28:21 ----SHD---- C:\System Volume Information
2013-01-19 17:18:17 ----SD---- C:\WINDOWS\Tasks
2013-01-19 17:16:14 ----D---- C:\WINDOWS\system32\drivers\etc
2013-01-19 17:15:21 ----D---- C:\WINDOWS\system32\oobe
2013-01-19 17:12:04 ----D---- C:\WINDOWS\AppPatch
2013-01-19 14:55:42 ----D---- C:\WINDOWS\Prefetch
2013-01-19 05:08:37 ----D---- C:\Documents and Settings\jpk\Data aplikací\Media Player Classic
2013-01-19 05:05:45 ----D---- C:\WINDOWS\Debug
2013-01-18 21:08:50 ----D---- C:\Documents and Settings\jpk\Data aplikací\Azureus
2013-01-18 19:10:31 ----D---- C:\Documents and Settings\jpk\Data aplikací\ERS Game Studios
2013-01-18 10:46:51 ----D---- C:\Program Files\Internet Explorer
2013-01-18 10:38:03 ----D---- C:\Program Files\K-Lite Codec Pack
2013-01-18 10:08:17 ----RSD---- C:\WINDOWS\Fonts
2013-01-18 10:03:17 ----D---- C:\WINDOWS\system32\CatRoot
2013-01-17 10:02:12 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\AVAST Software
2013-01-16 12:39:58 ----D---- C:\WINDOWS\system32\DirectX
2013-01-16 12:30:02 ----HD---- C:\Program Files\InstallShield Installation Information
2013-01-16 08:56:33 ----A---- C:\WINDOWS\game.ini
2013-01-15 21:41:52 ----D---- C:\Documents and Settings\jpk\Data aplikací\URSE Games
2013-01-15 17:15:30 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\IObit
2013-01-15 15:21:57 ----D---- C:\WINDOWS\Network Diagnostic
2013-01-15 14:25:05 ----D---- C:\Program Files\SRWare Iron
2013-01-14 19:19:47 ----D---- C:\WINDOWS\system32\config
2013-01-14 18:46:38 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Sony Ericsson
2013-01-14 18:43:41 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Samsung
2013-01-06 06:32:23 ----N---- C:\WINDOWS\system32\mshtml.dll
2013-01-01 20:22:44 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\NFS Underground

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHX;AVGIDSHX; C:\WINDOWS\system32\DRIVERS\avgidshx.sys [2012-10-15 55776]
R0 Avglogx;AVG Logging Driver; C:\WINDOWS\system32\DRIVERS\avglogx.sys [2012-09-21 177376]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS\system32\DRIVERS\avgmfx86.sys [2012-11-15 94048]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\WINDOWS\system32\DRIVERS\avgrkx86.sys [2012-09-14 35552]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2012-09-01 477240]
R0 uagp35;Filtr Microsoft AGPv3.5; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-14 44672]
R0 viaagp;Filtr VIA sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-14 42240]
R0 viamraid;viamraid; C:\WINDOWS\system32\DRIVERS\viamraid.sys [2005-11-23 92672]
R0 videX32;videX32; C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-02-23 9728]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2010-01-14 41600]
R1 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\avgidsdriverx.sys [2012-10-22 179936]
R1 AVGIDSShim;AVGIDSShim; C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys [2012-09-21 19936]
R1 Avgldx86;AVG AVI Loader Driver; C:\WINDOWS\system32\DRIVERS\avgldx86.sys [2012-10-02 159712]
R1 Avgtdix;AVG TDI Driver; C:\WINDOWS\system32\DRIVERS\avgtdix.sys [2012-09-21 164832]
R1 Tosrfcom;Bluetooth RFCOMM; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2005-08-01 64896]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]
R2 rspndr;Odpovídající zařízení zjišťování topologie linkové vrstvy; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2010-01-14 62848]
R3 Avgfwdx;Avgfwdx; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2012-01-12 30944]
R3 cmpci;C-Media PCI Audio Driver (WDM); C:\WINDOWS\system32\drivers\cmaudio.sys [2002-11-18 377358]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-16 6557408]
R3 tosporte;Bluetooth COM Port; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2006-10-10 41600]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S1 DumpDrv;Crash Dump Driver; C:\WINDOWS\system32\drivers\DumpDrv.sys [2010-01-14 9472]
S3 ai88bomh;ai88bomh; C:\WINDOWS\system32\drivers\ai88bomh.sys []
S3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS []
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver; C:\WINDOWS\System32\Drivers\ssadadb.sys [2010-12-21 30312]
S3 Avgfwfd;AVG network filter service; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2012-01-12 30944]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-14 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-14 101120]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2010-01-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-14 18944]
S3 catchme;catchme; \??\C:\DOCUME~1\jpk\LOCALS~1\Temp\catchme.sys []
S3 cmuda3;C-Media PCI Audio Interface; C:\WINDOWS\system32\drivers\cmudax3.sys [2009-03-18 1512960]
S3 dgderdrv;dgderdrv; C:\WINDOWS\System32\drivers\dgderdrv.sys [2012-05-23 20032]
S3 ewusbnet;HUAWEI USB-NDIS miniport; C:\WINDOWS\system32\DRIVERS\ewusbnet.sys [2009-07-23 112640]
S3 fdrawcmd;Low-level Floppy Driver; C:\WINDOWS\system32\drivers\fdrawcmd.sys []
S3 ggflt;SEMC USB Flash Driver Filter; C:\WINDOWS\system32\DRIVERS\ggflt.sys [2012-08-28 12400]
S3 ggsemc;SEMC USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsemc.sys [2012-08-28 25200]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-10-31 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-10-31 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-10-31 21568]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2009-07-23 102528]
S3 hwusbfake;Huawei DataCard USB Fake; C:\WINDOWS\system32\DRIVERS\ewusbfake.sys [2009-07-23 100480]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-14 59136]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\ssadbus.sys [2011-01-03 121192]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\WINDOWS\system32\DRIVERS\ssadmdfl.sys [2011-01-03 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\WINDOWS\system32\DRIVERS\ssadmdm.sys [2011-01-03 136680]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\WINDOWS\system32\DRIVERS\ssadserd.sys [2011-01-03 114152]
S3 tosrfbd;Bluetooth RFBUS; C:\WINDOWS\system32\DRIVERS\tosrfbd.sys [2007-01-12 113792]
S3 tosrfbnp;Bluetooth RFBNEP; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2006-11-20 36480]
S3 Tosrfhid;Bluetooth RFHID; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2007-01-24 73728]
S3 tosrfnds;Bluetooth Personal Area Network; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2005-01-06 18612]
S3 TosRfSnd;Bluetooth Audio; C:\WINDOWS\system32\drivers\tosrfsnd.sys [2007-01-22 53376]
S3 tosrfusb;Bluetooth USB Controller; C:\WINDOWS\system32\DRIVERS\tosrfusb.sys [2007-01-12 40576]
S3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-14 12800]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-22 32384]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\vinyl97.sys []
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2009-07-14 444136]
S3 WinUSB;Sony Ericsson USB Device sa0101 Driver; C:\WINDOWS\system32\DRIVERS\WinUSB.sys [2006-11-02 39368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2010-01-14 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2010-01-14 82944]
S4 exFat;exFat; C:\WINDOWS\system32\drivers\exFat.sys [2010-01-14 133632]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avgfws;AVG Firewall; C:\Program Files\AVG\AVG2013\avgfws.exe [2012-12-10 1342024]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [2012-11-15 5814904]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-16 159812]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2013-01-20 214520]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-02 118784]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2010-01-14 14848]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2010-01-14 14848]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2012-12-02 75136]
S4 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2010-01-14 913920]

-----------------EOF-----------------

Soráč za smazzání nechtěl aby v tom byl chaoz.

Napsal: 20 led 2013 17:22
od kamzl
Jinak dik. Do toho druhýho příspěvku sem hodil log ze rsitu.

je tam něco zvlastniho?


Logfile of random's system information tool 1.09 (written by random/random)
Run by jpk at 2013-01-20 16:21:52
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 52 GB (40%) free of 131 GB
Total RAM: 1279 MB (52% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:22:39, on 20.1.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG2013\avgfws.exe
C:\Program Files\AVG\AVG2013\avgidsagent.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\AVG\AVG2013\avgnsx.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\AVG\AVG2013\avgemcx.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\jpk\Dokumenty\Downloads\RSIT.exe
C:\Program Files\trend micro\jpk.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)
O2 - BHO: (no name) - {CA4520F3-AE13-4FB1-A513-58E23991C86D} - (no file)
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - (no file)
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

--
End of file - 4424 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4520F3-AE13-4FB1-A513-58E23991C86D}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"=Mixer.exe /startup []
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-16 13529088]
"AVG_UI"=C:\Program Files\AVG\AVG2013\avgui.exe [2012-12-11 3147384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\jpk\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-11-21 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^Bluetooth Manager.lnk]
C:\PROGRA~1\Toshiba\BLUETO~1\TosBtMng.exe [2007-02-02 2756608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^GamePark klient 2.lnk]
C:\PROGRA~1\GAMEPA~1\gpcl.exe [2011-07-29 409088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-10-14 214360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^Windows Search.lnk]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^jpk^Nabídka Start^Programy^Po spuštění^Facebook Messenger.lnk]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2
"wscsvc"=2
"Schedule"=2
"helpsvc"=2
"CiSvc"=3
"WMPNetworkSvc"=3
"PnkBstrA"=2
"EPSON_PM_RPCV4_01"=2

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-06-03 190464]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2010-01-14 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoResolveSearch"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe"="C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\Program Files\CesarFTP\Server.exe"="C:\Program Files\CesarFTP\Server.exe:*:Enabled:Server"
"C:\Program Files\Vuze\Azureus.exe"="C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"E:\hry\NFS Underground\Speed.exe"="E:\hry\NFS Underground\Speed.exe:*:Enabled:Speed"
"C:\Program Files\AVG\AVG2013\avgnsx.exe"="C:\Program Files\AVG\AVG2013\avgnsx.exe:*:Enabled:Webový štít"
"C:\Program Files\AVG\AVG2013\avgdiagex.exe"="C:\Program Files\AVG\AVG2013\avgdiagex.exe:*:Enabled:AVG Diagnostika 2013"
"C:\Program Files\AVG\AVG2013\avgmfapx.exe"="C:\Program Files\AVG\AVG2013\avgmfapx.exe:*:Enabled:Instalátor AVG"
"C:\Program Files\AVG\AVG2013\avgemcx.exe"="C:\Program Files\AVG\AVG2013\avgemcx.exe:*:Enabled:Obecná kontrola pošty"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"VIDC.XVID"=xvidvfw.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.HFYU"=huffyuv.dll
"VIDC.FFDS"=ff_vfw.dll
"VIDC.X264"=x264vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"msacm.l3codecp"=l3codecp.acm

======List of files/folders created in the last 1 month======

2013-01-20 16:21:57 ----D---- C:\Program Files\trend micro
2013-01-20 16:21:52 ----D---- C:\rsit
2013-01-20 15:47:43 ----D---- C:\Program Files\CCleaner
2013-01-20 15:23:09 ----A---- C:\WINDOWS\UPGRADE.TXT
2013-01-20 12:09:53 ----A---- C:\WINDOWS\imsins.BAK
2013-01-20 12:09:31 ----A---- C:\WINDOWS\system32\SET2C.tmp
2013-01-19 17:34:38 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2013-01-19 17:32:12 ----SHD---- C:\RECYCLER
2013-01-19 17:27:10 ----D---- C:\Program Files\xerox
2013-01-19 17:21:08 ----A---- C:\ComboFix.txt
2013-01-19 16:58:08 ----A---- C:\Boot.bak
2013-01-19 16:57:48 ----RASHD---- C:\cmdcons
2013-01-19 16:55:03 ----A---- C:\WINDOWS\zip.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\SWXCACLS.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\SWSC.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\SWREG.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\sed.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\PEV.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\NIRCMD.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\MBR.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\grep.exe
2013-01-19 16:54:28 ----D---- C:\Qoobox
2013-01-19 16:53:43 ----D---- C:\WINDOWS\erdnt
2013-01-18 20:30:56 ----D---- C:\Documents and Settings\jpk\Data aplikací\AVG2013
2013-01-18 20:29:28 ----D---- C:\Documents and Settings\jpk\Data aplikací\TuneUp Software
2013-01-18 20:26:50 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\AVG2013
2013-01-18 20:26:50 ----D---- C:\$AVG
2013-01-18 20:25:16 ----D---- C:\Program Files\AVG
2013-01-18 20:22:06 ----HD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Common Files
2013-01-18 20:22:05 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\MFAData
2013-01-18 19:51:53 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Kaspersky Lab
2013-01-18 10:48:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2757638$
2013-01-18 10:48:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2753842-v2$
2013-01-18 10:47:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2779562$
2013-01-18 10:45:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2770660$
2013-01-18 10:45:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2779030$
2013-01-18 10:45:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2758857$
2013-01-18 10:44:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2727528$
2013-01-18 10:38:14 ----A---- C:\WINDOWS\system32\huffyuv.dll
2013-01-18 10:38:13 ----A---- C:\WINDOWS\system32\x264vfw.dll
2013-01-18 10:38:13 ----A---- C:\WINDOWS\system32\lagarith.dll
2013-01-18 10:38:12 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2013-01-18 10:38:12 ----A---- C:\WINDOWS\system32\xvidcore.dll
2013-01-18 10:37:55 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2013-01-17 16:07:40 ----A---- C:\bdlog.txt
2013-01-17 10:50:06 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\BDLogging
2013-01-17 10:48:23 ----A---- C:\WINDOWS\capicom.dll
2013-01-17 10:47:31 ----A---- C:\WINDOWS\system32\WdfCoInstaller01009.dll
2013-01-17 10:31:26 ----D---- C:\Documents and Settings\jpk\Data aplikací\QuickScan
2013-01-17 09:56:46 ----D---- C:\Program Files\Common Files\Bitdefender
2013-01-15 22:56:18 ----D---- C:\Program Files\SCi
2013-01-15 20:24:49 ----D---- C:\Documents and Settings\jpk\Data aplikací\Enki Games
2013-01-15 16:46:00 ----D---- C:\Documents and Settings\jpk\Data aplikací\Alawar

======List of files/folders modified in the last 1 month======

2013-01-20 16:21:57 ----RD---- C:\Program Files
2013-01-20 16:19:20 ----SHD---- C:\WINDOWS\Installer
2013-01-20 16:18:20 ----D---- C:\Config.Msi
2013-01-20 16:17:38 ----D---- C:\WINDOWS\system32
2013-01-20 16:17:30 ----D---- C:\Program Files\Common Files
2013-01-20 16:16:25 ----D---- C:\Program Files\HP
2013-01-20 16:16:25 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\HP
2013-01-20 15:39:10 ----HD---- C:\WINDOWS\$hf_mig$
2013-01-20 15:39:03 ----RSHDC---- C:\WINDOWS\system32\dllcache
2013-01-20 15:38:55 ----D---- C:\WINDOWS
2013-01-20 15:38:27 ----D---- C:\Program Files\Microsoft Office
2013-01-20 15:37:59 ----D---- C:\Program Files\Messenger
2013-01-20 15:27:43 ----D---- C:\WINDOWS\Temp
2013-01-20 15:27:22 ----D---- C:\WINDOWS\system32\CatRoot2
2013-01-20 15:25:09 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-01-20 15:24:50 ----RASH---- C:\boot.ini
2013-01-20 15:24:50 ----A---- C:\WINDOWS\win.ini
2013-01-20 15:24:50 ----A---- C:\WINDOWS\system.ini
2013-01-20 15:21:41 ----D---- C:\Documents and Settings\jpk\Data aplikací\DAEMON Tools Lite
2013-01-20 15:21:41 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\DAEMON Tools Lite
2013-01-20 15:20:14 ----D---- C:\WINDOWS\system32\Restore
2013-01-20 15:14:04 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2013-01-20 13:59:57 ----D---- C:\WINDOWS\Microsoft.NET
2013-01-20 13:49:33 ----RSD---- C:\WINDOWS\assembly
2013-01-20 13:05:13 ----D---- C:\Downloads
2013-01-20 12:10:02 ----HD---- C:\WINDOWS\inf
2013-01-20 12:09:30 ----D---- C:\WINDOWS\ie8updates
2013-01-20 12:07:53 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2013-01-20 12:06:58 ----D---- C:\WINDOWS\WinSxS
2013-01-19 20:32:14 ----D---- C:\WINDOWS\system32\drivers
2013-01-19 18:01:30 ----D---- C:\Program Files\Microsoft ActiveSync
2013-01-19 18:00:35 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-01-19 17:34:37 ----D---- C:\WINDOWS\Help
2013-01-19 17:28:21 ----SHD---- C:\System Volume Information
2013-01-19 17:18:17 ----SD---- C:\WINDOWS\Tasks
2013-01-19 17:16:14 ----D---- C:\WINDOWS\system32\drivers\etc
2013-01-19 17:15:21 ----D---- C:\WINDOWS\system32\oobe
2013-01-19 17:12:04 ----D---- C:\WINDOWS\AppPatch
2013-01-19 14:55:42 ----D---- C:\WINDOWS\Prefetch
2013-01-19 05:08:37 ----D---- C:\Documents and Settings\jpk\Data aplikací\Media Player Classic
2013-01-19 05:05:45 ----D---- C:\WINDOWS\Debug
2013-01-18 21:08:50 ----D---- C:\Documents and Settings\jpk\Data aplikací\Azureus
2013-01-18 19:10:31 ----D---- C:\Documents and Settings\jpk\Data aplikací\ERS Game Studios
2013-01-18 10:46:51 ----D---- C:\Program Files\Internet Explorer
2013-01-18 10:38:03 ----D---- C:\Program Files\K-Lite Codec Pack
2013-01-18 10:08:17 ----RSD---- C:\WINDOWS\Fonts
2013-01-18 10:03:17 ----D---- C:\WINDOWS\system32\CatRoot
2013-01-17 10:02:12 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\AVAST Software
2013-01-16 12:39:58 ----D---- C:\WINDOWS\system32\DirectX
2013-01-16 12:30:02 ----HD---- C:\Program Files\InstallShield Installation Information
2013-01-16 08:56:33 ----A---- C:\WINDOWS\game.ini
2013-01-15 21:41:52 ----D---- C:\Documents and Settings\jpk\Data aplikací\URSE Games
2013-01-15 17:15:30 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\IObit
2013-01-15 15:21:57 ----D---- C:\WINDOWS\Network Diagnostic
2013-01-15 14:25:05 ----D---- C:\Program Files\SRWare Iron
2013-01-14 19:19:47 ----D---- C:\WINDOWS\system32\config
2013-01-14 18:46:38 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Sony Ericsson
2013-01-14 18:43:41 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Samsung
2013-01-06 06:32:23 ----N---- C:\WINDOWS\system32\mshtml.dll
2013-01-01 20:22:44 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\NFS Underground

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHX;AVGIDSHX; C:\WINDOWS\system32\DRIVERS\avgidshx.sys [2012-10-15 55776]
R0 Avglogx;AVG Logging Driver; C:\WINDOWS\system32\DRIVERS\avglogx.sys [2012-09-21 177376]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS\system32\DRIVERS\avgmfx86.sys [2012-11-15 94048]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\WINDOWS\system32\DRIVERS\avgrkx86.sys [2012-09-14 35552]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2012-09-01 477240]
R0 uagp35;Filtr Microsoft AGPv3.5; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-14 44672]
R0 viaagp;Filtr VIA sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-14 42240]
R0 viamraid;viamraid; C:\WINDOWS\system32\DRIVERS\viamraid.sys [2005-11-23 92672]
R0 videX32;videX32; C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-02-23 9728]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2010-01-14 41600]
R1 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\avgidsdriverx.sys [2012-10-22 179936]
R1 AVGIDSShim;AVGIDSShim; C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys [2012-09-21 19936]
R1 Avgldx86;AVG AVI Loader Driver; C:\WINDOWS\system32\DRIVERS\avgldx86.sys [2012-10-02 159712]
R1 Avgtdix;AVG TDI Driver; C:\WINDOWS\system32\DRIVERS\avgtdix.sys [2012-09-21 164832]
R1 Tosrfcom;Bluetooth RFCOMM; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2005-08-01 64896]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]
R2 rspndr;Odpovídající zařízení zjišťování topologie linkové vrstvy; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2010-01-14 62848]
R3 Avgfwdx;Avgfwdx; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2012-01-12 30944]
R3 cmpci;C-Media PCI Audio Driver (WDM); C:\WINDOWS\system32\drivers\cmaudio.sys [2002-11-18 377358]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-16 6557408]
R3 tosporte;Bluetooth COM Port; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2006-10-10 41600]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S1 DumpDrv;Crash Dump Driver; C:\WINDOWS\system32\drivers\DumpDrv.sys [2010-01-14 9472]
S3 ai88bomh;ai88bomh; C:\WINDOWS\system32\drivers\ai88bomh.sys []
S3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS []
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver; C:\WINDOWS\System32\Drivers\ssadadb.sys [2010-12-21 30312]
S3 Avgfwfd;AVG network filter service; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2012-01-12 30944]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-14 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-14 101120]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2010-01-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-14 18944]
S3 catchme;catchme; \??\C:\DOCUME~1\jpk\LOCALS~1\Temp\catchme.sys []
S3 cmuda3;C-Media PCI Audio Interface; C:\WINDOWS\system32\drivers\cmudax3.sys [2009-03-18 1512960]
S3 dgderdrv;dgderdrv; C:\WINDOWS\System32\drivers\dgderdrv.sys [2012-05-23 20032]
S3 ewusbnet;HUAWEI USB-NDIS miniport; C:\WINDOWS\system32\DRIVERS\ewusbnet.sys [2009-07-23 112640]
S3 fdrawcmd;Low-level Floppy Driver; C:\WINDOWS\system32\drivers\fdrawcmd.sys []
S3 ggflt;SEMC USB Flash Driver Filter; C:\WINDOWS\system32\DRIVERS\ggflt.sys [2012-08-28 12400]
S3 ggsemc;SEMC USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsemc.sys [2012-08-28 25200]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-10-31 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-10-31 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-10-31 21568]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2009-07-23 102528]
S3 hwusbfake;Huawei DataCard USB Fake; C:\WINDOWS\system32\DRIVERS\ewusbfake.sys [2009-07-23 100480]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-14 59136]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\ssadbus.sys [2011-01-03 121192]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\WINDOWS\system32\DRIVERS\ssadmdfl.sys [2011-01-03 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\WINDOWS\system32\DRIVERS\ssadmdm.sys [2011-01-03 136680]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\WINDOWS\system32\DRIVERS\ssadserd.sys [2011-01-03 114152]
S3 tosrfbd;Bluetooth RFBUS; C:\WINDOWS\system32\DRIVERS\tosrfbd.sys [2007-01-12 113792]
S3 tosrfbnp;Bluetooth RFBNEP; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2006-11-20 36480]
S3 Tosrfhid;Bluetooth RFHID; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2007-01-24 73728]
S3 tosrfnds;Bluetooth Personal Area Network; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2005-01-06 18612]
S3 TosRfSnd;Bluetooth Audio; C:\WINDOWS\system32\drivers\tosrfsnd.sys [2007-01-22 53376]
S3 tosrfusb;Bluetooth USB Controller; C:\WINDOWS\system32\DRIVERS\tosrfusb.sys [2007-01-12 40576]
S3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-14 12800]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-22 32384]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\vinyl97.sys []
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2009-07-14 444136]
S3 WinUSB;Sony Ericsson USB Device sa0101 Driver; C:\WINDOWS\system32\DRIVERS\WinUSB.sys [2006-11-02 39368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2010-01-14 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2010-01-14 82944]
S4 exFat;exFat; C:\WINDOWS\system32\drivers\exFat.sys [2010-01-14 133632]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avgfws;AVG Firewall; C:\Program Files\AVG\AVG2013\avgfws.exe [2012-12-10 1342024]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [2012-11-15 5814904]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-16 159812]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2013-01-20 214520]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-02 118784]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2010-01-14 14848]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2010-01-14 14848]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2012-12-02 75136]
S4 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2010-01-14 913920]

-----------------EOF-----------------

Zamrzající PC, díkec za kontrolu.

Napsal: 20 led 2013 23:04
od kamzl
Logfile of random's system information tool 1.09 (written by random/random)
Run by jpk at 2013-01-20 16:21:52
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 52 GB (40%) free of 131 GB
Total RAM: 1279 MB (52% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:22:39, on 20.1.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG2013\avgfws.exe
C:\Program Files\AVG\AVG2013\avgidsagent.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\AVG\AVG2013\avgnsx.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\AVG\AVG2013\avgemcx.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\jpk\Dokumenty\Downloads\RSIT.exe
C:\Program Files\trend micro\jpk.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)
O2 - BHO: (no name) - {CA4520F3-AE13-4FB1-A513-58E23991C86D} - (no file)
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - (no file)
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

--
End of file - 4424 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4520F3-AE13-4FB1-A513-58E23991C86D}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"=Mixer.exe /startup []
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-16 13529088]
"AVG_UI"=C:\Program Files\AVG\AVG2013\avgui.exe [2012-12-11 3147384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\jpk\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-11-21 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^Bluetooth Manager.lnk]
C:\PROGRA~1\Toshiba\BLUETO~1\TosBtMng.exe [2007-02-02 2756608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^GamePark klient 2.lnk]
C:\PROGRA~1\GAMEPA~1\gpcl.exe [2011-07-29 409088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-10-14 214360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Nabídka Start^Programy^Po spuštění^Windows Search.lnk]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^jpk^Nabídka Start^Programy^Po spuštění^Facebook Messenger.lnk]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2
"wscsvc"=2
"Schedule"=2
"helpsvc"=2
"CiSvc"=3
"WMPNetworkSvc"=3
"PnkBstrA"=2
"EPSON_PM_RPCV4_01"=2

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-06-03 190464]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2010-01-14 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoResolveSearch"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe"="C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\Program Files\CesarFTP\Server.exe"="C:\Program Files\CesarFTP\Server.exe:*:Enabled:Server"
"C:\Program Files\Vuze\Azureus.exe"="C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"E:\hry\NFS Underground\Speed.exe"="E:\hry\NFS Underground\Speed.exe:*:Enabled:Speed"
"C:\Program Files\AVG\AVG2013\avgnsx.exe"="C:\Program Files\AVG\AVG2013\avgnsx.exe:*:Enabled:Webový štít"
"C:\Program Files\AVG\AVG2013\avgdiagex.exe"="C:\Program Files\AVG\AVG2013\avgdiagex.exe:*:Enabled:AVG Diagnostika 2013"
"C:\Program Files\AVG\AVG2013\avgmfapx.exe"="C:\Program Files\AVG\AVG2013\avgmfapx.exe:*:Enabled:Instalátor AVG"
"C:\Program Files\AVG\AVG2013\avgemcx.exe"="C:\Program Files\AVG\AVG2013\avgemcx.exe:*:Enabled:Obecná kontrola pošty"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"VIDC.XVID"=xvidvfw.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.HFYU"=huffyuv.dll
"VIDC.FFDS"=ff_vfw.dll
"VIDC.X264"=x264vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"msacm.l3codecp"=l3codecp.acm

======List of files/folders created in the last 1 month======

2013-01-20 16:21:57 ----D---- C:\Program Files\trend micro
2013-01-20 16:21:52 ----D---- C:\rsit
2013-01-20 15:47:43 ----D---- C:\Program Files\CCleaner
2013-01-20 15:23:09 ----A---- C:\WINDOWS\UPGRADE.TXT
2013-01-20 12:09:53 ----A---- C:\WINDOWS\imsins.BAK
2013-01-20 12:09:31 ----A---- C:\WINDOWS\system32\SET2C.tmp
2013-01-19 17:34:38 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2013-01-19 17:32:12 ----SHD---- C:\RECYCLER
2013-01-19 17:27:10 ----D---- C:\Program Files\xerox
2013-01-19 17:21:08 ----A---- C:\ComboFix.txt
2013-01-19 16:58:08 ----A---- C:\Boot.bak
2013-01-19 16:57:48 ----RASHD---- C:\cmdcons
2013-01-19 16:55:03 ----A---- C:\WINDOWS\zip.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\SWXCACLS.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\SWSC.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\SWREG.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\sed.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\PEV.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\NIRCMD.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\MBR.exe
2013-01-19 16:55:03 ----A---- C:\WINDOWS\grep.exe
2013-01-19 16:54:28 ----D---- C:\Qoobox
2013-01-19 16:53:43 ----D---- C:\WINDOWS\erdnt
2013-01-18 20:30:56 ----D---- C:\Documents and Settings\jpk\Data aplikací\AVG2013
2013-01-18 20:29:28 ----D---- C:\Documents and Settings\jpk\Data aplikací\TuneUp Software
2013-01-18 20:26:50 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\AVG2013
2013-01-18 20:26:50 ----D---- C:\$AVG
2013-01-18 20:25:16 ----D---- C:\Program Files\AVG
2013-01-18 20:22:06 ----HD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Common Files
2013-01-18 20:22:05 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\MFAData
2013-01-18 19:51:53 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Kaspersky Lab
2013-01-18 10:48:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2757638$
2013-01-18 10:48:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2753842-v2$
2013-01-18 10:47:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2779562$
2013-01-18 10:45:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2770660$
2013-01-18 10:45:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2779030$
2013-01-18 10:45:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2758857$
2013-01-18 10:44:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2727528$
2013-01-18 10:38:14 ----A---- C:\WINDOWS\system32\huffyuv.dll
2013-01-18 10:38:13 ----A---- C:\WINDOWS\system32\x264vfw.dll
2013-01-18 10:38:13 ----A---- C:\WINDOWS\system32\lagarith.dll
2013-01-18 10:38:12 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2013-01-18 10:38:12 ----A---- C:\WINDOWS\system32\xvidcore.dll
2013-01-18 10:37:55 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2013-01-17 16:07:40 ----A---- C:\bdlog.txt
2013-01-17 10:50:06 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\BDLogging
2013-01-17 10:48:23 ----A---- C:\WINDOWS\capicom.dll
2013-01-17 10:47:31 ----A---- C:\WINDOWS\system32\WdfCoInstaller01009.dll
2013-01-17 10:31:26 ----D---- C:\Documents and Settings\jpk\Data aplikací\QuickScan
2013-01-17 09:56:46 ----D---- C:\Program Files\Common Files\Bitdefender
2013-01-15 22:56:18 ----D---- C:\Program Files\SCi
2013-01-15 20:24:49 ----D---- C:\Documents and Settings\jpk\Data aplikací\Enki Games
2013-01-15 16:46:00 ----D---- C:\Documents and Settings\jpk\Data aplikací\Alawar

======List of files/folders modified in the last 1 month======

2013-01-20 16:21:57 ----RD---- C:\Program Files
2013-01-20 16:19:20 ----SHD---- C:\WINDOWS\Installer
2013-01-20 16:18:20 ----D---- C:\Config.Msi
2013-01-20 16:17:38 ----D---- C:\WINDOWS\system32
2013-01-20 16:17:30 ----D---- C:\Program Files\Common Files
2013-01-20 16:16:25 ----D---- C:\Program Files\HP
2013-01-20 16:16:25 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\HP
2013-01-20 15:39:10 ----HD---- C:\WINDOWS\$hf_mig$
2013-01-20 15:39:03 ----RSHDC---- C:\WINDOWS\system32\dllcache
2013-01-20 15:38:55 ----D---- C:\WINDOWS
2013-01-20 15:38:27 ----D---- C:\Program Files\Microsoft Office
2013-01-20 15:37:59 ----D---- C:\Program Files\Messenger
2013-01-20 15:27:43 ----D---- C:\WINDOWS\Temp
2013-01-20 15:27:22 ----D---- C:\WINDOWS\system32\CatRoot2
2013-01-20 15:25:09 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-01-20 15:24:50 ----RASH---- C:\boot.ini
2013-01-20 15:24:50 ----A---- C:\WINDOWS\win.ini
2013-01-20 15:24:50 ----A---- C:\WINDOWS\system.ini
2013-01-20 15:21:41 ----D---- C:\Documents and Settings\jpk\Data aplikací\DAEMON Tools Lite
2013-01-20 15:21:41 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\DAEMON Tools Lite
2013-01-20 15:20:14 ----D---- C:\WINDOWS\system32\Restore
2013-01-20 15:14:04 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2013-01-20 13:59:57 ----D---- C:\WINDOWS\Microsoft.NET
2013-01-20 13:49:33 ----RSD---- C:\WINDOWS\assembly
2013-01-20 13:05:13 ----D---- C:\Downloads
2013-01-20 12:10:02 ----HD---- C:\WINDOWS\inf
2013-01-20 12:09:30 ----D---- C:\WINDOWS\ie8updates
2013-01-20 12:07:53 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2013-01-20 12:06:58 ----D---- C:\WINDOWS\WinSxS
2013-01-19 20:32:14 ----D---- C:\WINDOWS\system32\drivers
2013-01-19 18:01:30 ----D---- C:\Program Files\Microsoft ActiveSync
2013-01-19 18:00:35 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-01-19 17:34:37 ----D---- C:\WINDOWS\Help
2013-01-19 17:28:21 ----SHD---- C:\System Volume Information
2013-01-19 17:18:17 ----SD---- C:\WINDOWS\Tasks
2013-01-19 17:16:14 ----D---- C:\WINDOWS\system32\drivers\etc
2013-01-19 17:15:21 ----D---- C:\WINDOWS\system32\oobe
2013-01-19 17:12:04 ----D---- C:\WINDOWS\AppPatch
2013-01-19 14:55:42 ----D---- C:\WINDOWS\Prefetch
2013-01-19 05:08:37 ----D---- C:\Documents and Settings\jpk\Data aplikací\Media Player Classic
2013-01-19 05:05:45 ----D---- C:\WINDOWS\Debug
2013-01-18 21:08:50 ----D---- C:\Documents and Settings\jpk\Data aplikací\Azureus
2013-01-18 19:10:31 ----D---- C:\Documents and Settings\jpk\Data aplikací\ERS Game Studios
2013-01-18 10:46:51 ----D---- C:\Program Files\Internet Explorer
2013-01-18 10:38:03 ----D---- C:\Program Files\K-Lite Codec Pack
2013-01-18 10:08:17 ----RSD---- C:\WINDOWS\Fonts
2013-01-18 10:03:17 ----D---- C:\WINDOWS\system32\CatRoot
2013-01-17 10:02:12 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\AVAST Software
2013-01-16 12:39:58 ----D---- C:\WINDOWS\system32\DirectX
2013-01-16 12:30:02 ----HD---- C:\Program Files\InstallShield Installation Information
2013-01-16 08:56:33 ----A---- C:\WINDOWS\game.ini
2013-01-15 21:41:52 ----D---- C:\Documents and Settings\jpk\Data aplikací\URSE Games
2013-01-15 17:15:30 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\IObit
2013-01-15 15:21:57 ----D---- C:\WINDOWS\Network Diagnostic
2013-01-15 14:25:05 ----D---- C:\Program Files\SRWare Iron
2013-01-14 19:19:47 ----D---- C:\WINDOWS\system32\config
2013-01-14 18:46:38 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Sony Ericsson
2013-01-14 18:43:41 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Samsung
2013-01-06 06:32:23 ----N---- C:\WINDOWS\system32\mshtml.dll
2013-01-01 20:22:44 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\NFS Underground

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHX;AVGIDSHX; C:\WINDOWS\system32\DRIVERS\avgidshx.sys [2012-10-15 55776]
R0 Avglogx;AVG Logging Driver; C:\WINDOWS\system32\DRIVERS\avglogx.sys [2012-09-21 177376]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS\system32\DRIVERS\avgmfx86.sys [2012-11-15 94048]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\WINDOWS\system32\DRIVERS\avgrkx86.sys [2012-09-14 35552]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2012-09-01 477240]
R0 uagp35;Filtr Microsoft AGPv3.5; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-14 44672]
R0 viaagp;Filtr VIA sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-14 42240]
R0 viamraid;viamraid; C:\WINDOWS\system32\DRIVERS\viamraid.sys [2005-11-23 92672]
R0 videX32;videX32; C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-02-23 9728]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2010-01-14 41600]
R1 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\avgidsdriverx.sys [2012-10-22 179936]
R1 AVGIDSShim;AVGIDSShim; C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys [2012-09-21 19936]
R1 Avgldx86;AVG AVI Loader Driver; C:\WINDOWS\system32\DRIVERS\avgldx86.sys [2012-10-02 159712]
R1 Avgtdix;AVG TDI Driver; C:\WINDOWS\system32\DRIVERS\avgtdix.sys [2012-09-21 164832]
R1 Tosrfcom;Bluetooth RFCOMM; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2005-08-01 64896]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]
R2 rspndr;Odpovídající zařízení zjišťování topologie linkové vrstvy; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2010-01-14 62848]
R3 Avgfwdx;Avgfwdx; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2012-01-12 30944]
R3 cmpci;C-Media PCI Audio Driver (WDM); C:\WINDOWS\system32\drivers\cmaudio.sys [2002-11-18 377358]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-16 6557408]
R3 tosporte;Bluetooth COM Port; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2006-10-10 41600]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S1 DumpDrv;Crash Dump Driver; C:\WINDOWS\system32\drivers\DumpDrv.sys [2010-01-14 9472]
S3 ai88bomh;ai88bomh; C:\WINDOWS\system32\drivers\ai88bomh.sys []
S3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS []
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver; C:\WINDOWS\System32\Drivers\ssadadb.sys [2010-12-21 30312]
S3 Avgfwfd;AVG network filter service; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2012-01-12 30944]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-14 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-14 101120]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2010-01-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-14 18944]
S3 catchme;catchme; \??\C:\DOCUME~1\jpk\LOCALS~1\Temp\catchme.sys []
S3 cmuda3;C-Media PCI Audio Interface; C:\WINDOWS\system32\drivers\cmudax3.sys [2009-03-18 1512960]
S3 dgderdrv;dgderdrv; C:\WINDOWS\System32\drivers\dgderdrv.sys [2012-05-23 20032]
S3 ewusbnet;HUAWEI USB-NDIS miniport; C:\WINDOWS\system32\DRIVERS\ewusbnet.sys [2009-07-23 112640]
S3 fdrawcmd;Low-level Floppy Driver; C:\WINDOWS\system32\drivers\fdrawcmd.sys []
S3 ggflt;SEMC USB Flash Driver Filter; C:\WINDOWS\system32\DRIVERS\ggflt.sys [2012-08-28 12400]
S3 ggsemc;SEMC USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsemc.sys [2012-08-28 25200]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-10-31 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-10-31 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-10-31 21568]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2009-07-23 102528]
S3 hwusbfake;Huawei DataCard USB Fake; C:\WINDOWS\system32\DRIVERS\ewusbfake.sys [2009-07-23 100480]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-14 59136]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\ssadbus.sys [2011-01-03 121192]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\WINDOWS\system32\DRIVERS\ssadmdfl.sys [2011-01-03 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\WINDOWS\system32\DRIVERS\ssadmdm.sys [2011-01-03 136680]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\WINDOWS\system32\DRIVERS\ssadserd.sys [2011-01-03 114152]
S3 tosrfbd;Bluetooth RFBUS; C:\WINDOWS\system32\DRIVERS\tosrfbd.sys [2007-01-12 113792]
S3 tosrfbnp;Bluetooth RFBNEP; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2006-11-20 36480]
S3 Tosrfhid;Bluetooth RFHID; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2007-01-24 73728]
S3 tosrfnds;Bluetooth Personal Area Network; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2005-01-06 18612]
S3 TosRfSnd;Bluetooth Audio; C:\WINDOWS\system32\drivers\tosrfsnd.sys [2007-01-22 53376]
S3 tosrfusb;Bluetooth USB Controller; C:\WINDOWS\system32\DRIVERS\tosrfusb.sys [2007-01-12 40576]
S3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-14 12800]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-22 32384]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\vinyl97.sys []
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2009-07-14 444136]
S3 WinUSB;Sony Ericsson USB Device sa0101 Driver; C:\WINDOWS\system32\DRIVERS\WinUSB.sys [2006-11-02 39368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2010-01-14 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2010-01-14 82944]
S4 exFat;exFat; C:\WINDOWS\system32\drivers\exFat.sys [2010-01-14 133632]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avgfws;AVG Firewall; C:\Program Files\AVG\AVG2013\avgfws.exe [2012-12-10 1342024]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [2012-11-15 5814904]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [2012-10-22 196664]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-16 159812]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2013-01-20 214520]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-02 118784]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2010-01-14 14848]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2010-01-14 14848]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2012-12-02 75136]
S4 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2010-01-14 913920]

-----------------EOF-----------------

Zde ještě LOG z DSS jesli pomůže.

Napsal: 20 led 2013 23:17
od kamzl
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702
Run by jpk at 23:14:36 on 2013-01-20
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1279.778 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ================
.
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k bthsvcs
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mStart Page = about:blank
uProxyServer = 192.168.0.1:80
BHO: {CA4520F3-AE13-4FB1-A513-58E23991C86D} - <orphaned>
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRunOnce: [NVIDIASetup] c:\nvidia\win2k\175.16\is\SETUP.EXE
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:323
uPolicies-Explorer: NoDriveAutoRun = dword:67108863
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDrives = dword:0
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
IE: Download with &Media Finder - c:\program files\media finder\hook.html
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\micros~1\office11\EXCEL.EXE/3000
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{4EA9C2B5-F97A-4DEE-8B7B-9E25D579156A} : DHCPNameServer = 84.21.97.129 84.16.96.2
TCP: Interfaces\{6480C3D9-6CFC-4E3F-BB50-CED7CEAF689A} : DHCPNameServer = 77.48.254.254 77.48.100.254
TCP: Interfaces\{760D9A86-5B73-4120-A1F1-B96630CE9E8E} : DHCPNameServer = 84.21.97.129 84.16.96.2
TCP: Interfaces\{8AE8DD5B-0048-40A4-9028-D6E3D5F49D25} : DHCPNameServer = 192.168.0.1
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-1-20 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-1-20 361032]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2013-1-20 21256]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2013-1-20 44808]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2010-1-14 70272]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys --> c:\windows\system32\drivers\avgidsdriverx.sys [?]
S1 DumpDrv;Crash Dump Driver;c:\windows\system32\drivers\dumpdrv.sys [2010-1-14 9472]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [2012-11-3 30312]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2012-5-19 20032]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [2012-5-23 112640]
S3 fdrawcmd;Low-level Floppy Driver; [x]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2012-8-28 12400]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [2012-5-23 100480]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2012-11-3 121192]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2012-11-3 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2012-11-3 136680]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [2012-11-3 114152]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2010-1-14 14848]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2013-01-20 20:48:33 -------- d-----w- c:\documents and settings\jpk\data aplikací\flashInstall
2013-01-20 20:03:55 446464 ----a-w- c:\windows\system32\nvudisp.exe
2013-01-20 19:07:33 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-01-20 19:07:05 41224 ----a-w- c:\windows\avastSS.scr
2013-01-20 19:05:53 -------- d-----w- c:\program files\AVAST Software
2013-01-20 17:19:17 6016 ----a-r- c:\windows\system32\ntsim.sys
2013-01-20 17:03:04 965120 ----a-w- c:\windows\system32\ac3filter.acm
2013-01-20 17:02:51 -------- d-----w- c:\program files\XP Codec Pack
2013-01-20 16:37:11 -------- d-----w- c:\program files\Total Uninstall 6
2013-01-20 15:21:57 -------- d-----w- c:\program files\trend micro
2013-01-20 14:47:43 -------- d-----w- c:\program files\CCleaner
2013-01-19 16:34:38 -------- d-----w- c:\windows\system32\SoftwareDistribution
2013-01-19 15:57:48 -------- d-sha-r- C:\cmdcons
2013-01-19 15:55:03 98816 ----a-w- c:\windows\sed.exe
2013-01-19 15:55:03 256000 ----a-w- c:\windows\PEV.exe
2013-01-19 15:55:03 208896 ----a-w- c:\windows\MBR.exe
2013-01-19 15:54:10 -------- d-----w- c:\documents and settings\all users.windows\Oblíbené položky
2013-01-18 19:29:28 -------- d-----w- c:\documents and settings\jpk\data aplikací\TuneUp Software
2013-01-18 19:26:50 -------- d-----w- C:\$AVG
2013-01-17 09:48:23 511328 ----a-w- c:\windows\capicom.dll
2013-01-17 09:47:31 1461992 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2013-01-17 09:31:26 -------- d-----w- c:\documents and settings\jpk\data aplikací\QuickScan
2013-01-17 08:56:46 -------- d-----w- c:\program files\common files\Bitdefender
2013-01-15 21:56:18 -------- d-----w- c:\program files\SCi
2013-01-15 21:56:01 212992 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ILog.dll
2013-01-15 19:24:49 -------- d-----w- c:\documents and settings\jpk\data aplikací\Enki Games
2013-01-15 15:46:00 -------- d-----w- c:\documents and settings\jpk\data aplikací\Alawar
.
==================== Find3M ====================
.
2013-01-20 20:23:54 137464 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-01-20 20:23:17 214520 ----a-w- c:\windows\system32\PnkBstrB.xtr
2013-01-20 20:23:17 214520 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-01-20 16:48:06 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-12-16 12:31:02 290560 ----a-w- c:\windows\system32\atmfd.dll
2012-11-13 11:56:25 1875456 ----a-w- c:\windows\system32\win32k.sys
2012-11-08 10:29:12 1402312 ----a-w- c:\windows\system32\msxml4.dll
2012-11-06 02:00:18 1446912 ----a-w- c:\windows\system32\msxml6.dll
2012-11-02 02:03:56 375296 ----a-w- c:\windows\system32\dpnet.dll
2012-11-01 22:54:23 139152 ----a-w- c:\documents and settings\jpk\data aplikací\PnkBstrK.sys
2012-11-01 22:53:04 794408 ----a-w- c:\windows\system32\pbsvc.exe
2012-11-01 12:11:09 920064 ----a-w- c:\windows\system32\wininet.dll
2012-11-01 12:11:09 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-11-01 12:11:09 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-10-31 23:39:31 385024 ----a-w- c:\windows\system32\html.iec
.
============= FINISH: 23:15:39,59 ===============

Re: Zamrzající PC, díkec za kontrolu.

Napsal: 21 led 2013 09:18
od JaRon
ahoj,
no nejak mas tych prispevkov k jednemu PC hodne ,,, :!:
vycisti PC s CCleanerom - hlavne registre a potom vloz aktualny log z ComboFix-u

Re: Zamrzající PC, díkec za kontrolu.

Napsal: 21 led 2013 12:33
od vyosek
Zdravim :)

Vsechno jsem to sloucil do jednoho, takovy bordel uz to dlouho nikdo nedelal :x :x Nota bene kdyz se Vam kolega Naughty pise s odpovedi a vy to mezitim smazete...

byt na me, tak vam tu pomoc odmitnu a konec...

Re: Zamrzající PC, díkec za kontrolu.

Napsal: 21 led 2013 17:13
od kamzl
Jsem už z toho nějaký zmatený.

Zde poslední aktuální log z DSS.

Ještě navíc se k tomu přidalo to že se to sekne a zčerná obrazovka a zobrazí se plná takovejch těch bílejch ksichtíků(jako když v COmmandu,teny styl písma myslim) a je to na restart.

AVAST nic nehlásí ale tušim že tam něco je, takže doufám že aktuální log něco poví. Odezvy na pouštění chromu a samotných webů katastrofální, pak už když se to otevře už to jakžtakž jede.

CCleaner použit.Opraven co šlo dle něj.

Tottall unistall 6 taky co šlo odjebal.

TADY TEN LOG:

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702
Run by jpk at 17:08:15 on 2013-01-21
#Option Extended Search is enabled.
#Option Whitelisting is disabled.
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1279.837 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ================
.
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\Program Files\Comodo\Dragon\dragon.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uSearch Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
mStart Page = about:blank
mSearch Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
mDefault_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157
mDefault_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
uProxyServer = 192.168.0.1:80
mSearchAssistant = hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
mCustomizeSearch = hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
uURLSearchHooks: Microsoft Url Search Hook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - c:\windows\system32\ieframe.dll
mWinlogon: Shell = Explorer.exe
mWinlogon: Userinit = c:\windows\system32\userinit.exe,
mWinlogon: SFCDisable = dword:0
BHO: {CA4520F3-AE13-4FB1-A513-58E23991C86D} - <orphaned>
TB: &Adresa: {01E04581-4EEE-11D0-BFE9-00AA005B4383} - c:\windows\system32\browseui.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [KernelFaultCheck] c:\windows\system32\dumprep 0 -k
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:323
uPolicies-Explorer: LinkResolveIgnoreLinkInfo = dword:0
uPolicies-Explorer: NoDriveAutoRun = dword:67108863
uPolicies-Explorer: NoDrives = dword:0
uPolicies-Explorer: NoRecentDocsNetHood = dword:1
mPolicies-Explorer: HonorAutoRunSetting = dword:1
mPolicies-Explorer: NoCDBurning = dword:0
mPolicies-Explorer: LinkResolveIgnoreLinkInfo = dword:0
mPolicies-Explorer: NoResolveSearch = dword:1
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: dontdisplaylastusername = dword:0
mPolicies-System: shutdownwithoutlogon = dword:1
mPolicies-System: undockwithoutlogon = dword:1
mPolicies-System: DisableRegistryTools = dword:0
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
IE: Download with &Media Finder - c:\program files\media finder\hook.html
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\micros~1\office11\EXCEL.EXE/3000
LSP: %SystemRoot%\system32\mswsock.dll
LSP: %SystemRoot%\system32\rsvpsp.dll
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{4EA9C2B5-F97A-4DEE-8B7B-9E25D579156A} : DHCPNameServer = 84.21.97.129 84.16.96.2
TCP: Interfaces\{6480C3D9-6CFC-4E3F-BB50-CED7CEAF689A} : DHCPNameServer = 77.48.254.254 77.48.100.254
TCP: Interfaces\{760D9A86-5B73-4120-A1F1-B96630CE9E8E} : DHCPNameServer = 84.21.97.129 84.16.96.2
TCP: Interfaces\{8AE8DD5B-0048-40A4-9028-D6E3D5F49D25} : DHCPNameServer = 192.168.0.1
Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} -
Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} -
Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} -
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - c:\windows\system32\urlmon.dll
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - c:\windows\system32\urlmon.dll
Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - c:\windows\system32\shell32.dll
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office11\MSOXMLMF.DLL
Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll
Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - c:\windows\system32\urlmon.dll
Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - c:\windows\system32\msvidctl.dll
Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll
Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll
Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll
Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll
Handler: ipp - <Clsid value has no data>
Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - c:\windows\system32\itss.dll
Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll
Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll
Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll
Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - c:\windows\system32\inetcomm.dll
Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - c:\windows\system32\urlmon.dll
Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - c:\windows\system32\itss.dll
Handler: msdaipp - <Clsid value has no data>
Handler: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - c:\program files\common files\microsoft shared\web components\11\OWC11.DLL
Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll
Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - c:\windows\system32\msvidctl.dll
Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - c:\windows\system32\mshtml.dll
Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - c:\windows\system32\wiascr.dll
Name-Space Handler: mk\* - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - c:\windows\system32\itss.dll
Notify: crypt32chain - crypt32.dll
Notify: cryptnet - cryptnet.dll
Notify: cscdll - cscdll.dll
Notify: dimsntfy - c:\windows\system32\dimsntfy.dll
Notify: ScCertProp - wlnotify.dll
Notify: Schedule - wlnotify.dll
Notify: sclgntfy - sclgntfy.dll
Notify: SensLogn - WlNotify.dll
Notify: termsrv - wlnotify.dll
Notify: WgaLogon - <no file>
Notify: wlballoon - wlnotify.dll
SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - c:\windows\system32\webcheck.dll
SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - c:\windows\system32\shell32.dll
SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - c:\windows\system32\SHELL32.dll
SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - c:\windows\system32\stobject.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - c:\windows\system32\browseui.dll
STS: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - c:\windows\system32\browseui.dll
SEH: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - <orphaned>
SecurityProviders: SecurityProviders = msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
LSA: Authentication Packages = msv1_0
LSA: Notification Packages = scecli
LSA: Security Packages = kerberos msv1_0 schannel wdigest
SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 winsrv:ConServerDllInitialization,2
mASetup: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - c:\windows\system32\ieudinit.exe
mASetup: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - c:\windows\inf\unregmp2.exe /ShowWMP
mASetup: >{26923b43-4d38-484f-9b9e-de460746276c} - c:\windows\system32\shmgrate.exe OCInstallUserConfigIE
mASetup: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIEActiveSetup SIGNUP
mASetup: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - c:\windows\system32\shmgrate.exe OCInstallUserConfigOE
mASetup: >{99820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
mASetup: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - c:\windows\system32\regsvr32.exe /s /n /i:/userinstall c:\windows\system32\themeui.dll
mASetup: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "c:\program files\outlook express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
mASetup: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection c:\windows\inf\msnetmtg.inf,NetMtg.Install.PerUser.NT
mASetup: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection c:\windows\inf\msmsgs.inf,BLC.QuietInstall.PerUser
mASetup: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - rundll32.exe advpack.dll,LaunchINFSection c:\windows\inf\wmp.inf,PerUserStub
mASetup: {7790769C-0471-11d2-AF11-00C04FA35D02} - "c:\program files\outlook express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
mASetup: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
mASetup: {89820200-ECBD-11cf-8B85-00AA005B4383} - c:\windows\system32\ie4uinit.exe -BaseSettings
mASetup: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\windows\system32\rundll32.exe c:\windows\system32\mscories.dll,Install
CLSID: {603D3801-BD81-11d0-A3A5-00C04FD706EC} - c:\windows\system32\browseui.dll
.
============= SERVICES / DRIVERS ===============
.
R0 ACPI;Microsoft ACPI Driver;c:\windows\system32\drivers\acpi.sys [2008-4-14 188288]
R0 atapi;Standardní řadič disku IDE/ESDI;c:\windows\system32\drivers\atapi.sys [2008-4-14 96512]
R0 Disk;Ovladač disku;c:\windows\system32\drivers\disk.sys [2010-1-14 36352]
R0 dmio;Ovladač správce logických disků;c:\windows\system32\drivers\dmio.sys [2008-4-14 153856]
R0 dmload;dmload;c:\windows\system32\drivers\dmload.sys [2008-4-14 5888]
R0 FltMgr;FltMgr;c:\windows\system32\drivers\fltMgr.sys [2011-11-21 129792]
R0 Ftdisk;Ovladač správce svazků;c:\windows\system32\drivers\ftdisk.sys [2008-4-14 125184]
R0 isapnp;Řadič Plug and Play sběrnice ISA/EISA;c:\windows\system32\drivers\isapnp.sys [2008-4-14 37248]
R0 KSecDD;KSecDD;c:\windows\system32\drivers\ksecdd.sys [2009-6-24 92928]
R0 MountMgr;Správce připojovacích bodů;c:\windows\system32\drivers\mountmgr.sys [2010-1-14 42752]
R0 Mup;Služba Multiple UNC Provider;c:\windows\system32\drivers\mup.sys [2010-1-14 105472]
R0 NDIS;Systémový ovladač NDIS;c:\windows\system32\drivers\ndis.sys [2010-1-14 182912]
R0 PartMgr;Správce oddílů;c:\windows\system32\drivers\partmgr.sys [2008-4-14 19712]
R0 PCI;Řadič sběrnice PCI;c:\windows\system32\drivers\pci.sys [2008-4-14 68736]
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R0 uagp35;Filtr Microsoft AGPv3.5;c:\windows\system32\drivers\uagp35.sys [2012-2-26 44672]
R0 viaagp;Filtr VIA sběrnice AGP ;c:\windows\system32\drivers\VIAAGP.SYS [2011-11-21 42240]
R0 ViaIde;ViaIde;c:\windows\system32\drivers\viaide.sys [2008-4-14 5376]
R0 viamraid;viamraid;c:\windows\system32\drivers\viamraid.sys [2012-5-17 92672]
R0 videX32;videX32;c:\windows\system32\drivers\videX32.sys [2012-5-17 9728]
R0 VolSnap;VolSnap;c:\windows\system32\drivers\volsnap.sys [2008-4-14 52480]
R1 Aavmker4;avast! Asynchronous Virus Monitor;c:\windows\system32\drivers\aavmker4.sys [2013-1-20 25256]
R1 AFD;AFD;c:\windows\system32\drivers\afd.sys [2010-1-14 138496]
R1 AmdK7;Ovladač procesoru AMD K7;c:\windows\system32\drivers\amdk7.sys [2008-4-14 41600]
R1 AswRdr;aswRdr;c:\windows\system32\drivers\aswRdr.sys [2013-1-20 35928]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-1-20 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-1-20 361032]
R1 aswTdi;avast! Network Shield Support;c:\windows\system32\drivers\aswTdi.sys [2013-1-20 54232]
R1 Beep;Beep;c:\windows\system32\drivers\beep.sys [2008-4-14 4224]
R1 Cdrom;Ovladač jednotky CD-ROM;c:\windows\system32\drivers\cdrom.sys [2010-1-14 62976]
R1 Fips;Fips;c:\windows\system32\drivers\fips.sys [2008-4-14 44544]
R1 i8042prt;i8042 Keyboard and PS/2 Mouse Port Driver;c:\windows\system32\drivers\i8042prt.sys [2008-4-14 52096]
R1 Imapi;CD-Burning Filter Driver;c:\windows\system32\drivers\imapi.sys [2008-4-14 42112]
R1 IPSec;Ovladač IPSEC;c:\windows\system32\drivers\ipsec.sys [2008-4-14 75264]
R1 Kbdclass;Ovladač třídy klávesnic;c:\windows\system32\drivers\kbdclass.sys [2008-4-14 24576]
R1 mnmdd;mnmdd;c:\windows\system32\drivers\mnmdd.sys [2008-4-14 4224]
R1 Mouclass;Ovladač třídy myší;c:\windows\system32\drivers\mouclass.sys [2008-4-14 23040]
R1 MRxSmb;MRXSMB;c:\windows\system32\drivers\mrxsmb.sys [2010-1-14 457856]
R1 Msfs;Msfs;c:\windows\system32\drivers\msfs.sys [2008-4-14 19072]
R1 NetBIOS;Rozhraní NetBIOS;c:\windows\system32\drivers\netbios.sys [2008-4-14 34688]
R1 NetBT;Rozhraní NetBios nad protokolem TCP/IP;c:\windows\system32\drivers\netbt.sys [2008-4-14 162816]
R1 Npfs;Npfs;c:\windows\system32\drivers\npfs.sys [2008-4-14 30848]
R1 Null;Null;c:\windows\system32\drivers\null.sys [2008-4-14 2944]
R1 RasAcd;Ovladač automatického připojení pomocí vzdáleného přístupu;c:\windows\system32\drivers\rasacd.sys [2008-4-14 8832]
R1 Rdbss;Rdbss;c:\windows\system32\drivers\rdbss.sys [2010-1-14 174848]
R1 RDPCDD;RDPCDD;c:\windows\system32\drivers\rdpcdd.sys [2008-4-14 4224]
R1 redbook;Digital CD Audio Playback Filter Driver;c:\windows\system32\drivers\redbook.sys [2011-11-21 58496]
R1 Serial;Ovladač sériového portu;c:\windows\system32\drivers\serial.sys [2008-4-14 64256]
R1 Tcpip;Ovladač protokolu TCP/IP;c:\windows\system32\drivers\tcpip.sys [2010-1-14 361600]
R1 TermDD;Ovladač terminálového zařízení;c:\windows\system32\drivers\termdd.sys [2011-11-21 40840]
R1 VgaSave;Řadič zobrazovače VGA;c:\windows\system32\drivers\vga.sys [2008-4-14 20992]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment;c:\windows\system32\drivers\ws2ifsl.sys [2008-4-14 12032]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2013-1-20 21256]
R2 aswMon2;aswMon2;c:\windows\system32\drivers\aswmon2.sys [2013-1-20 97608]
R2 AudioSrv;Zvuk systému Windows;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2013-1-20 44808]
R2 DcomLaunch;Spouštěč procesů serveru DCOM;c:\windows\system32\svchost.exe -k DcomLaunch [2010-1-14 14848]
R2 Dhcp;Klient DHCP;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
R2 dmserver;Správce logických disků;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
R2 Dnscache;Klient DNS;c:\windows\system32\svchost.exe -k NetworkService [2010-1-14 14848]
R2 Eventlog;Protokol událostí;c:\windows\system32\services.exe [2010-1-14 111104]
R2 LmHosts;Podpora rozhraní NetBIOS nad protokolem TCP/IP;c:\windows\system32\svchost.exe -k LocalService [2010-1-14 14848]
R2 Netman;Síťová připojení;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
R2 NVSvc;NVIDIA Display Driver Service;c:\windows\system32\nvsvc32.exe [2006-10-22 159810]
R2 ParVdm;ParVdm;c:\windows\system32\drivers\parvdm.sys [2008-4-14 6784]
R2 PlugPlay;Plug and Play;c:\windows\system32\services.exe [2010-1-14 111104]
R2 PnkBstrA;PnkBstrA;c:\windows\system32\PnkBstrA.exe [2011-12-20 75064]
R2 PnkBstrB;PnkBstrB;c:\windows\system32\PnkBstrB.exe [2011-12-20 214520]
R2 PolicyAgent;Služby IPSEC;c:\windows\system32\lsass.exe [2008-4-14 13312]
R2 ProtectedStorage;Chráněné úložiště;c:\windows\system32\lsass.exe [2008-4-14 13312]
R2 RpcSs;Vzdálené volání procedur (RPC);c:\windows\system32\svchost.exe -k rpcss [2010-1-14 14848]
R2 rspndr;Odpovídající zařízení zjišťování topologie linkové vrstvy;c:\windows\system32\drivers\rspndr.sys [2010-1-14 62848]
R2 SamSs;Správce zabezpečení účtů;c:\windows\system32\lsass.exe [2008-4-14 13312]
R2 SENS;Oznamování systémových událostí;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
R2 ShellHWDetection;Rozpoznávání hardwaru;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
R2 Spooler;Zařazování tisku;c:\windows\system32\spoolsv.exe [2008-4-14 58880]
R2 stisvc;Načítání obrázků (WIA);c:\windows\system32\svchost.exe -k imgsvc [2010-1-14 14848]
R2 Themes;Motivy;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
R2 winmgmt;Služba WMI;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
R2 WZCSVC;Automatická konfigurace bezdrátových zařízení;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
R3 audstub;Prázdný zvukový ovladač;c:\windows\system32\drivers\audstub.sys [2011-11-21 3072]
R3 cmpci;C-Media PCI Audio Driver (WDM);c:\windows\system32\drivers\cmaudio.sys [2011-11-22 377358]
R3 CryptSvc;CryptSvc;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
R3 EventSystem;Systém událostí modelu COM+;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
R3 Fdc;Ovladač řadiče disketové jednotky;c:\windows\system32\drivers\fdc.sys [2008-4-14 27392]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;c:\windows\system32\drivers\fetnd5.sys [2003-12-31 27165]
R3 gameenum;Game Port Enumerator;c:\windows\system32\drivers\gameenum.sys [2011-11-21 10624]
R3 Gpc;Obecné třídění paketů;c:\windows\system32\drivers\msgpc.sys [2008-4-14 35072]
R3 mssmbios;Ovladač Microsoft System Management BIOS;c:\windows\system32\drivers\mssmbios.sys [2008-4-14 15488]
R3 NdisTapi;Ovladač Remote Access NDIS TAPI;c:\windows\system32\drivers\ndistapi.sys [2008-4-14 10496]
R3 Ndisuio;Protokol NDIS uživatelského režimu V/V;c:\windows\system32\drivers\ndisuio.sys [2008-4-14 14592]
R3 NdisWan;Ovladač Remote Access NDIS WAN;c:\windows\system32\drivers\ndiswan.sys [2010-1-14 91776]
R3 NDProxy;NDIS Proxy;c:\windows\system32\drivers\ndproxy.sys [2008-4-14 40960]
R3 nv;nv;c:\windows\system32\drivers\nv4_mini.sys [2011-11-21 3994624]
R3 Parport;Ovladač paralelního portu;c:\windows\system32\drivers\parport.sys [2008-4-14 80000]
R3 PptpMiniport;WAN Miniport (PPTP);c:\windows\system32\drivers\raspptp.sys [2008-4-14 48384]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2010-1-14 70272]
R3 Ptilink;Direct Parallel Link Driver;c:\windows\system32\drivers\ptilink.sys [2008-4-14 17792]
R3 Rasl2tp;WAN Miniport (L2TP);c:\windows\system32\drivers\rasl2tp.sys [2008-4-14 51328]
R3 RasPppoe;Remote Access PPPOE Driver;c:\windows\system32\drivers\raspppoe.sys [2010-1-14 41472]
R3 Raspti;Přímé propojení paralelním kabelem;c:\windows\system32\drivers\raspti.sys [2008-4-14 16512]
R3 rdpdr;Ovladač přesměrovače zařízení terminálového serveru;c:\windows\system32\drivers\rdpdr.sys [2011-11-21 195712]
R3 serenum;Ovladač filtru Serenum;c:\windows\system32\drivers\serenum.sys [2008-4-14 15744]
R3 swenum;Softwarový ovladač sběrnice;c:\windows\system32\drivers\swenum.sys [2008-4-14 4352]
R3 sysaudio;Microsoft Kernel System Audio Device;c:\windows\system32\drivers\sysaudio.sys [2011-11-21 60800]
R3 Update;Ovladač aktualizace mikrokódu;c:\windows\system32\drivers\update.sys [2008-4-14 384768]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0;c:\windows\system32\drivers\usbehci.sys [2012-2-26 30208]
R3 usbhub;Rozbočovač umožnující USB2;c:\windows\system32\drivers\usbhub.sys [2008-4-14 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft;c:\windows\system32\drivers\usbuhci.sys [2008-4-14 20608]
R3 Wanarp;Ovladač Remote Access IP ARP;c:\windows\system32\drivers\wanarp.sys [2008-4-14 34560]
R3 wdmaud;Microsoft WINMM WDM Audio Compatibility Driver;c:\windows\system32\drivers\wdmaud.sys [2011-11-21 83072]
R4 Cdfs;Cdfs;c:\windows\system32\drivers\cdfs.sys [2008-4-14 63744]
R4 Ntfs;Ntfs;c:\windows\system32\drivers\ntfs.sys [2009-3-23 576512]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys --> c:\windows\system32\drivers\avgidsdriverx.sys [?]
S1 Cdaudio;Cdaudio;c:\windows\system32\drivers\cdaudio.sys [2001-8-17 18688]
S1 DumpDrv;Crash Dump Driver;c:\windows\system32\drivers\dumpdrv.sys [2010-1-14 9472]
S1 Changer;Changer; [x]
S1 i2omgmt;i2omgmt; [x]
S1 lbrtfdc;lbrtfdc; [x]
S1 PCIDump;PCIDump; [x]
S1 Sfloppy;Sfloppy;c:\windows\system32\drivers\sfloppy.sys [2008-4-14 11392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 Net Driver HPZ12;Net Driver HPZ12;c:\windows\system32\svchost.exe -k HPZ12 [2010-1-14 14848]
S3 aec;Microsoft Kernel Acoustic Echo Canceller;c:\windows\system32\drivers\aec.sys [2011-11-21 142592]
S3 ALCXWDM;Service for Realtek AC97 Audio (WDM);c:\windows\system32\drivers\alcxwdm.sys --> c:\windows\system32\drivers\ALCXWDM.SYS [?]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [2012-11-3 30312]
S3 AppMgmt;Správa aplikací;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S3 aspnet_state;ASP.NET State Service;c:\windows\microsoft.net\framework\v4.0.30319\aspnet_state.exe [2010-3-18 35160]
S3 AsyncMac;Ovladač asynchronních médií připojení RAS;c:\windows\system32\drivers\asyncmac.sys [2008-4-14 14336]
S3 Atmarpc;Protokol ATM ARP Client;c:\windows\system32\drivers\atmarpc.sys [2008-4-14 59904]
S3 BthEnum;Ovladač pro Bluetooth Request Block;c:\windows\system32\drivers\bthenum.sys [2012-2-26 17024]
S3 BthPan;Bluetooth Device (Personal Area Network);c:\windows\system32\drivers\bthpan.sys [2012-2-26 101120]
S3 BTHPORT;Ovladač portu Bluetooth;c:\windows\system32\drivers\bthport.sys [2010-1-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth;c:\windows\system32\drivers\bthusb.sys [2012-2-26 18944]
S3 catchme;catchme;\??\c:\docume~1\jpk\locals~1\temp\catchme.sys --> c:\docume~1\jpk\locals~1\temp\catchme.sys [?]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86;c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe [2008-7-25 69632]
S3 cmuda3;C-Media PCI Audio Interface;c:\windows\system32\drivers\cmudax3.sys [2012-9-22 1512960]
S3 COMSysApp;Systémové aplikace modelu COM+;c:\windows\system32\dllhost.exe [2008-4-14 5120]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2012-5-19 20032]
S3 dmadmin;Služba správy pro Správce logických disků;c:\windows\system32\dmadmin.exe [2008-4-14 225280]
S3 DMusic;Syntezátor Microsoft Kernel DLS;c:\windows\system32\drivers\DMusic.sys [2011-11-21 52864]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler;c:\windows\system32\drivers\drmkaud.sys [2011-11-21 2944]
S3 EapHost;Služba EAP (Extensible Authentication Protocol);c:\windows\system32\svchost.exe -k eapsvcs [2010-1-14 14848]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [2012-5-23 112640]
S3 fdrawcmd;Low-level Floppy Driver; [x]
S3 Flpydisk;Ovladač disketové jednotky;c:\windows\system32\drivers\flpydisk.sys [2008-4-14 20480]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0;c:\windows\microsoft.net\framework\v3.0\wpf\PresentationFontCache.exe [2008-7-29 46104]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2012-8-28 12400]
S3 ggsemc;SEMC USB Flash Driver;c:\windows\system32\drivers\ggsemc.sys [2012-8-28 25200]
S3 hkmsvc;Služba Správa klíčů a certifikátů stavu;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S3 HPZid412;IEEE-1284.4 Driver HPZid412;c:\windows\system32\drivers\HPZid412.sys [2012-3-1 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12;c:\windows\system32\drivers\HPZipr12.sys [2012-3-1 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12;c:\windows\system32\drivers\HPZius12.sys [2012-3-1 21568]
S3 HTTP;Služba HTTP;c:\windows\system32\drivers\http.sys [2010-1-14 265728]
S3 HTTPFilter;Služba HTTP SSL;c:\windows\system32\svchost.exe -k HTTPFilter [2010-1-14 14848]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial;c:\windows\system32\drivers\ewusbmdm.sys [2012-5-23 102528]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [2012-5-23 100480]
S3 IDriverT;InstallDriver Table Manager;c:\program files\common files\installshield\driver\1150\intel 32\IDriverT.exe [2005-11-14 69632]
S3 Ip6Fw;Ovladač IPv6 brány firewall systému Windows;c:\windows\system32\drivers\ip6fw.sys [2008-4-14 36608]
S3 IpFilterDriver;IP Traffic Filter Driver;c:\windows\system32\drivers\ipfltdrv.sys [2008-4-14 32896]
S3 IpInIp;IP in IP Tunnel Driver;c:\windows\system32\drivers\ipinip.sys [2008-4-14 20864]
S3 IpNat;IP Network Address Translator;c:\windows\system32\drivers\ipnat.sys [2008-4-14 152832]
S3 IRENUM;Služba čítače výčtu IR;c:\windows\system32\drivers\irenum.sys [2011-11-21 11264]
S3 kmixer;Směšovač Microsoft Kernel Wave Audio Mixer;c:\windows\system32\drivers\kmixer.sys [2011-11-21 172416]
S3 lanmanworkstation;Pracovní stanice;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S3 Modem;Modem;c:\windows\system32\drivers\modem.sys [2008-4-14 30080]
S3 MRxDAV;Přesměrovač klienta WebDav;c:\windows\system32\drivers\mrxdav.sys [2010-1-14 180096]
S3 MSDTC;Koordinátor DTC;c:\windows\system32\msdtc.exe [2011-11-21 6144]
S3 MSIServer;Instalační služba systému Windows;c:\windows\system32\msiexec.exe [2010-1-14 95744]
S3 MSKSSRV;Microsoft Streaming Service Proxy;c:\windows\system32\drivers\MSKSSRV.sys [2011-11-21 7552]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy;c:\windows\system32\drivers\MSPCLOCK.sys [2011-11-21 5376]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy;c:\windows\system32\drivers\MSPQM.sys [2011-11-21 4992]
S3 napagent;Agent architektury NAP (Network Access Protection);c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S3 NtLmSsp;Zprostředkovatel zabezpečení NT LM;c:\windows\system32\lsass.exe [2008-4-14 13312]
S3 NtmsSvc;Vyměnitelné úložiště;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S3 NTSIM;NTSIM;c:\windows\system32\ntsim.sys [2013-1-20 6016]
S3 NwlnkFlt;IPX Traffic Filter Driver;c:\windows\system32\drivers\nwlnkflt.sys [2008-4-14 12416]
S3 NwlnkFwd;IPX Traffic Forwarder Driver;c:\windows\system32\drivers\nwlnkfwd.sys [2008-4-14 32512]
S3 PDCOMP;PDCOMP; [x]
S3 PDFRAME;PDFRAME; [x]
S3 PDRELI;PDRELI; [x]
S3 PDRFRAME;PDRFRAME; [x]
S3 Pml Driver HPZ12;Pml Driver HPZ12;c:\windows\system32\svchost.exe -k HPZ12 [2010-1-14 14848]
S3 RasAuto;Správce automatického připojení pomocí vzdáleného přístupu;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S3 RasMan;Správce vzdáleného přístupu;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S3 RDPWD;RDPWD;c:\windows\system32\drivers\rdpwd.sys [2011-11-21 139784]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI);c:\windows\system32\drivers\rfcomm.sys [2012-2-26 59136]
S3 RpcLocator;Lokátor vzdáleného volání procedur (RPC);c:\windows\system32\locator.exe [2008-4-14 75264]
S3 RSVP;QoS RSVP;c:\windows\system32\rsvp.exe [2008-4-14 132608]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver;c:\windows\system32\drivers\RTL8139.sys [2011-11-21 20992]
S3 Secdrv;Secdrv;c:\windows\system32\drivers\secdrv.sys [2008-4-14 20480]
S3 splitter;Microsoft Kernel Audio Splitter;c:\windows\system32\drivers\splitter.sys [2011-11-21 6272]
S3 Srv;Srv;c:\windows\system32\drivers\srv.sys [2010-1-14 357888]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2012-11-3 121192]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2012-11-3 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2012-11-3 136680]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [2012-11-3 114152]
S3 swmidi;Microsoft Kernel GS Wavetable Synthesizer;c:\windows\system32\drivers\swmidi.sys [2011-11-21 56576]
S3 TDPIPE;TDPIPE;c:\windows\system32\drivers\tdpipe.sys [2011-11-21 12040]
S3 TDTCP;TDTCP;c:\windows\system32\drivers\tdtcp.sys [2011-11-21 22024]
S3 tosrfbd;Bluetooth RFBUS;c:\windows\system32\drivers\tosrfbd.sys --> c:\windows\system32\drivers\tosrfbd.sys [?]
S3 tosrfbnp;Bluetooth RFBNEP;c:\windows\system32\drivers\tosrfbnp.sys --> c:\windows\system32\drivers\tosrfbnp.sys [?]
S3 Tosrfhid;Bluetooth RFHID;c:\windows\system32\drivers\tosrfhid.sys --> c:\windows\system32\drivers\Tosrfhid.sys [?]
S3 tosrfnds;Bluetooth Personal Area Network;c:\windows\system32\drivers\tosrfnds.sys --> c:\windows\system32\drivers\tosrfnds.sys [?]
S3 TosRfSnd;Bluetooth Audio;c:\windows\system32\drivers\tosrfsnd.sys --> c:\windows\system32\drivers\tosrfsnd.sys [?]
S3 tosrfusb;Bluetooth USB Controller;c:\windows\system32\drivers\tosrfusb.sys --> c:\windows\system32\drivers\tosrfusb.sys [?]
S3 usb_rndisx;Adaptér USB RNDIS;c:\windows\system32\drivers\usb8023x.sys [2012-2-26 12800]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB;c:\windows\system32\drivers\usbccgp.sys [2011-11-22 32384]
S3 usbprint;Třída USB Printer;c:\windows\system32\drivers\usbprint.sys [2011-11-22 25856]
S3 usbscan;Ovladač skeneru USB;c:\windows\system32\drivers\usbscan.sys [2011-12-21 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB;c:\windows\system32\drivers\USBSTOR.SYS [2012-3-1 26368]
S3 VIAudio;Vinyl AC'97 Audio Controller (WDM);c:\windows\system32\drivers\vinyl97.sys --> c:\windows\system32\drivers\vinyl97.sys [?]
S3 Wdf01000;Wdf01000;c:\windows\system32\drivers\wdf01000.sys [2006-11-2 444136]
S3 WDICA;WDICA; [x]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2010-1-14 14848]
S3 WinUSB;Sony Ericsson USB Device sa0101 Driver;c:\windows\system32\drivers\winusb.sys [2006-11-2 39368]
S3 Wmi;Rozšíření ovladače WMI;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S3 WmiApSrv;Adaptér výkonu služby WMI;c:\windows\system32\wbem\wmiapsrv.exe [2011-11-21 126464]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver;c:\windows\system32\drivers\wudfpf.sys [2010-1-14 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector;c:\windows\system32\drivers\wudfrd.sys [2010-1-14 82944]
S3 xmlprov;Služba pro síťová ustanovení;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 Abiosdsk;Abiosdsk; [x]
S4 abp480n5;abp480n5; [x]
S4 ACPIEC;ACPIEC;c:\windows\system32\drivers\acpiec.sys [2008-4-14 11776]
S4 adpu160m;adpu160m; [x]
S4 Aha154x;Aha154x; [x]
S4 aic78u2;aic78u2; [x]
S4 aic78xx;aic78xx; [x]
S4 Alerter;Výstrahy;c:\windows\system32\svchost.exe -k LocalService [2010-1-14 14848]
S4 ALG;Služba brány aplikačního rozhraní;c:\windows\system32\alg.exe [2008-4-14 44544]
S4 AliIde;AliIde; [x]
S4 amsint;amsint; [x]
S4 asc;asc; [x]
S4 asc3350p;asc3350p; [x]
S4 asc3550;asc3550; [x]
S4 Atdisk;Atdisk; [x]
S4 BITS;BITS;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 Browser;Prohledávání počítačů;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 BthServ;Bluetooth Support Service;c:\windows\system32\svchost.exe -k bthsvcs [2010-1-14 14848]
S4 cbidf2k;cbidf2k;c:\windows\system32\drivers\cbidf2k.sys [2008-4-14 13952]
S4 cd20xrnt;cd20xrnt; [x]
S4 CiSvc;Indexing Service;c:\windows\system32\cisvc.exe [2008-4-14 5632]
S4 ClipSrv;Síťová schránka;c:\windows\system32\clipsrv.exe [2008-4-14 33280]
S4 CmdIde;CmdIde; [x]
S4 Cpqarray;Cpqarray; [x]
S4 dac960nt;dac960nt; [x]
S4 dmboot;dmboot;c:\windows\system32\drivers\dmboot.sys [2008-4-14 800000]
S4 Dot3svc;Automatická konfigurace pevné sítě;c:\windows\system32\svchost.exe -k dot3svc [2010-1-14 14848]
S4 dpti2o;dpti2o; [x]
S4 ERSvc;Zasílání zpráv o chybách;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 exFat;exFat;c:\windows\system32\drivers\exfat.sys [2010-1-14 133632]
S4 Fastfat;Fastfat;c:\windows\system32\drivers\fastfat.sys [2008-4-14 143744]
S4 FastUserSwitchingCompatibility;Kompatibilita pro rychlé přepínání uživatelů;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 helpsvc;Nápověda a odborná pomoc;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 HidServ;Přístup k zařízením standardu HID;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 hpn;hpn; [x]
S4 i2omp;i2omp; [x]
S4 idsvc;Služba Windows CardSpace;c:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe [2008-7-29 881664]
S4 ImapiService;Služba modelu COM pro zápis na disk CD (IMAPI);c:\windows\system32\imapi.exe [2008-4-14 150528]
S4 ini910u;ini910u; [x]
S4 IntelIde;IntelIde; [x]
S4 LanmanServer;Server;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 Messenger;Kurýrní služba;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 mnmsrvc;NetMeeting - Vzdálené sdílení plochy;c:\windows\system32\mnmsrvc.exe [2011-11-21 32768]
S4 mraid35x;mraid35x; [x]
S4 NetDDE;Služba DDE v síti;c:\windows\system32\netdde.exe [2008-4-14 111616]
S4 NetDDEdsdm;Správce DSDM služby DDE v síti;c:\windows\system32\netdde.exe [2008-4-14 111616]
S4 Netlogon;Přihlašování k síti;c:\windows\system32\lsass.exe [2008-4-14 13312]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service;c:\windows\microsoft.net\framework\v4.0.30319\SMSvcHost.exe [2010-3-18 124240]
S4 Nla;Sledování umístění v síti (NLA);c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 ose;Office Source Engine;c:\program files\common files\microsoft shared\source engine\OSE.EXE [2003-7-28 89136]
S4 PCIIde;PCIIde; [x]
S4 Pcmcia;Pcmcia;c:\windows\system32\drivers\pcmcia.sys [2008-4-14 120064]
S4 perc2;perc2; [x]
S4 perc2hib;perc2hib; [x]
S4 ql1080;ql1080; [x]
S4 Ql10wnt;Ql10wnt; [x]
S4 ql12160;ql12160; [x]
S4 ql1240;ql1240; [x]
S4 ql1280;ql1280; [x]
S4 RDSessMgr;Správce relací nápovědy ke vzdálené ploše;c:\windows\system32\sessmgr.exe [2011-11-21 141824]
S4 RemoteAccess;Směrování a vzdálený přístup;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 RemoteRegistry;Vzdálený registr;c:\windows\system32\svchost.exe -k LocalService [2010-1-14 14848]
S4 SCardSvr;Smart Card;c:\windows\system32\scardsvr.exe [2008-4-14 97792]
S4 seclogon;Secondary Logon;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 SharedAccess;Brána Firewall / Sdílení připojení k Internetu (ICS);c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 Schedule;Plánovač úloh;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 Simbad;Simbad; [x]
S4 Sparrow;Sparrow; [x]
S4 SR;Ovladač filtru Obnovy systému;c:\windows\system32\drivers\sr.sys [2011-11-21 73344]
S4 srservice;Služba obnovení systému;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 SSDPSRV;Služba rozpoznávání pomocí protokolu SSDP;c:\windows\system32\svchost.exe -k LocalService [2010-1-14 14848]
S4 SwPrv;MS Software Shadow Copy Provider;c:\windows\system32\dllhost.exe [2008-4-14 5120]
S4 sym_hi;sym_hi; [x]
S4 sym_u3;sym_u3; [x]
S4 symc810;symc810; [x]
S4 symc8xx;symc8xx; [x]
S4 SysmonLog;Výstrahy a protokolování výkonu;c:\windows\system32\smlogsvc.exe [2008-4-14 90112]
S4 TapiSrv;Telefonní subsystém;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 TermService;Terminálová služba;c:\windows\system32\svchost.exe -k DComLaunch [2010-1-14 14848]
S4 TlntSvr;Telnet;c:\windows\system32\tlntsvr.exe [2008-4-14 73728]
S4 TosIde;TosIde; [x]
S4 TrkWks;Klient služby sledování distribuovaných propojení;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 Udfs;Udfs;c:\windows\system32\drivers\udfs.sys [2008-4-14 66048]
S4 ultra;ultra; [x]
S4 upnphost;Hostitel zařízení UPnP;c:\windows\system32\svchost.exe -k LocalService [2010-1-14 14848]
S4 UPS;Nepřerušitelný zdroj napájení (UPS);c:\windows\system32\ups.exe [2008-4-14 18432]
S4 VSS;Stínová kopie svazku;c:\windows\system32\vssvc.exe [2008-4-14 290816]
S4 W32Time;Systémový čas;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 WebClient;Webový klient;c:\windows\system32\svchost.exe -k LocalService [2010-1-14 14848]
S4 WmdmPmSN;Portable Media Serial Number Service;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 WMPNetworkSvc;Služba Windows Media Player Network Sharing;c:\program files\windows media player\wmpnetwk.exe [2011-11-8 913920]
S4 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 wscsvc;Centrum zabezpečení;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 wuauserv;Automatic Updates;c:\windows\system32\svchost.exe -k netsvcs [2010-1-14 14848]
S4 WudfSvc;Windows Driver Foundation - User-mode Driver Framework;c:\windows\system32\svchost.exe -k WudfServiceGroup [2010-1-14 14848]
.
=============== File Associations ===============
.
FileExt: .bat: batfile="%1" %*
FileExt: .cmd: cmdfile="%1" %*
FileExt: .com: ComFile="%1" %*
FileExt: .exe: exefile="%1" %*
FileExt: .pif: piffile="%1" %*
FileExt: .scr: scrfile="%1" /S
FileExt: .reg: regfile=regedit.exe "%1"
FileExt: .txt: txtfile=c:\windows\system32\NOTEPAD.EXE %1
FileExt: .chm: chm.file="c:\windows\hh.exe" %1
FileExt: .ini: inifile=c:\windows\system32\NOTEPAD.EXE %1
FileExt: .inf: inffile=c:\windows\system32\NOTEPAD.EXE %1
ShellExec: AcroRD32.exe: Read="c:\program files\adobe\reader 10.0\reader\AcroRd32.exe" "%1"
ShellExec: Azureus.exe: open="c:\program files\vuze\Azureus.exe" "%1"
ShellExec: chrome.exe: open="c:\documents and settings\jpk\local settings\data aplikací\google\chrome\application\chrome.exe" -- "%1"
ShellExec: DTLite.exe: open="c:\program files\daemon tools lite\DTLite.exe" -shellmount "%1"
ShellExec: iexplore.exe: open="c:\program files\internet explorer\iexplore.exe" %1
ShellExec: IsoBuster.exe: extract="c:\program files\smart projects\isobuster\IsoBuster.exe" "/ef:" "/c" "/nodrives" "%1"
ShellExec: IsoBuster.exe: open="c:\program files\smart projects\isobuster\IsoBuster.exe" "%1"
ShellExec: i_view32.exe: open="c:\program files\irfanview\i_view32.exe" "%1"
ShellExec: moviemk.exe: Open="c:\program files\movie maker\moviemk.exe" %1
ShellExec: mplayerc.exe: open="c:\program files\xp codec pack\mpc\mplayerc.exe" "%1"
ShellExec: msiexec.exe: Open="c:\windows\system32\msiexec.exe" /i "%1" %*
ShellExec: msiexec.exe: Repair="c:\windows\system32\msiexec.exe" /f "%1" %*
ShellExec: msiexec.exe: Uninstall="c:\windows\system32\msiexec.exe" /x "%1" %*
ShellExec: MSOXMLED.EXE: edit="c:\program files\common files\microsoft shared\office11\MSOXMLED.EXE" /verb edit "%1"
ShellExec: MSOXMLED.EXE: open="c:\program files\common files\microsoft shared\office11\MSOXMLED.EXE" /verb open "%1"
ShellExec: mspaint.exe: edit="c:\windows\system32\mspaint.exe" "%1"
ShellExec: notepad.exe: edit=c:\windows\system32\NOTEPAD.EXE %1
ShellExec: notepad.exe: open=c:\windows\system32\NOTEPAD.EXE %1
ShellExec: ois.exe: Edit=c:\progra~1\micros~1\office11\OIS.EXE /shellEdit "%1"
ShellExec: ois.exe: Open=c:\progra~1\micros~1\office11\OIS.EXE /shellOpen "%1"
ShellExec: ois.exe: Preview=c:\progra~1\micros~1\office11\OIS.EXE /shellPreview "%1"
ShellExec: shimgvw.dll: open=rundll32.exe c:\windows\system32\shimgvw.dll,ImageView_Fullscreen %1
ShellExec: shimgvw.dll: print=rundll32.exe c:\windows\system32\shimgvw.dll,ImageView_Fullscreen %1
ShellExec: uTorrent.exe: open="c:\program files\utorrent\uTorrent.exe" "%1"
ShellExec: WinRAR.exe: open="c:\program files\winrar\WinRAR.exe" "%1"
ShellExec: Winword.exe: edit="c:\program files\microsoft office\office11\WINWORD.EXE" /n /dde
ShellExec: wmplayer.exe: open=c:\program files\windows media player\wmplayer.exe /Open "%L"
ShellExec: wmplayer.exe: play=c:\program files\windows media player\wmplayer.exe /Play "%L"
ShellExec: wordpad.exe: open="c:\program files\windows nt\accessories\WORDPAD.EXE" "%1"
ShellExec: WUD.exe: open=c:\program files\windows updates downloader\WUD.exe -install "%1"
.
=============== Created Last 60 ================
.
2013-01-21 15:20:12 -------- d--h--r- c:\documents and settings\jpk\Recent
2013-01-21 15:12:18 -------- d-----w- C:\$WIN_NT$.~BT
2013-01-21 15:12:16 -------- d-----w- c:\windows\setup.pss
2013-01-21 15:12:02 -------- d-----w- c:\windows\setupupd
2013-01-21 14:12:38 -------- d-----w- c:\windows\nview
2013-01-21 14:12:37 208896 ----a-w- c:\windows\system32\nvudisp.exe
2013-01-21 14:12:12 208896 ----a-w- c:\windows\system32\NVUNINST.EXE
2013-01-21 13:41:11 -------- d-----w- c:\program files\AnalogX
2013-01-21 12:12:52 31744 -c--a-w- c:\windows\system32\dllcache\pid.dll
2013-01-21 12:12:52 12288 ----a-w- c:\windows\system32\ksolay.ax
2013-01-21 12:00:22 794408 ----a-w- c:\windows\system32\pbsvc2.exe
2013-01-21 09:10:16 -------- d-----w- c:\program files\xp-AntiSpy
2013-01-20 22:23:39 -------- d-----w- c:\windows\nvidia icons
2013-01-20 20:48:33 -------- d-----w- c:\documents and settings\jpk\data aplikací\flashInstall
2013-01-20 19:07:41 361032 ------w- c:\windows\system32\drivers\aswSP.sys
2013-01-20 19:07:41 21256 ------w- c:\windows\system32\drivers\aswFsBlk.sys
2013-01-20 19:07:36 35928 ------w- c:\windows\system32\drivers\aswRdr.sys
2013-01-20 19:07:35 54232 ------w- c:\windows\system32\drivers\aswTdi.sys
2013-01-20 19:07:33 738504 ------w- c:\windows\system32\drivers\aswSnx.sys
2013-01-20 19:07:32 97608 ------w- c:\windows\system32\drivers\aswmon2.sys
2013-01-20 19:07:32 89752 ------w- c:\windows\system32\drivers\aswmon.sys
2013-01-20 19:07:32 25256 ------w- c:\windows\system32\drivers\aavmker4.sys
2013-01-20 19:07:05 41224 ------w- c:\windows\avastSS.scr
2013-01-20 19:07:04 227648 ------w- c:\windows\system32\aswBoot.exe
2013-01-20 19:05:53 -------- d-----w- c:\program files\AVAST Software
2013-01-20 17:19:17 6016 ----a-r- c:\windows\system32\ntsim.sys
2013-01-20 17:03:04 965120 ----a-w- c:\windows\system32\ac3filter.acm
2013-01-20 17:02:51 -------- d-----w- c:\program files\XP Codec Pack
2013-01-20 16:37:11 -------- d-----w- c:\program files\Total Uninstall 6
2013-01-20 15:21:57 -------- d-----w- c:\program files\trend micro
2013-01-20 15:21:52 -------- d-----w- C:\rsit
2013-01-20 14:47:43 -------- d-----w- c:\program files\CCleaner
2013-01-19 16:34:38 -------- d-----w- c:\windows\system32\SoftwareDistribution
2013-01-19 16:32:12 -------- d-sh--w- C:\RECYCLER
2013-01-19 16:27:10 -------- d-----w- c:\program files\xerox
2013-01-19 15:57:48 -------- d-sha-r- C:\cmdcons
2013-01-19 15:55:03 98816 ----a-w- c:\windows\sed.exe
2013-01-19 15:55:03 80412 ----a-w- c:\windows\grep.exe
2013-01-19 15:55:03 68096 ----a-w- c:\windows\zip.exe
2013-01-19 15:55:03 60416 ----a-w- c:\windows\NIRCMD.exe
2013-01-19 15:55:03 518144 ----a-w- c:\windows\SWREG.exe
2013-01-19 15:55:03 406528 ----a-w- c:\windows\SWSC.exe
2013-01-19 15:55:03 256000 ----a-w- c:\windows\PEV.exe
2013-01-19 15:55:03 212480 ----a-w- c:\windows\SWXCACLS.exe
2013-01-19 15:55:03 208896 ----a-w- c:\windows\MBR.exe
2013-01-19 15:54:10 -------- d-----w- c:\documents and settings\all users.windows\Oblíbené položky
2013-01-19 15:53:43 -------- d-----w- c:\windows\erdnt
2013-01-18 19:29:28 -------- d-----w- c:\documents and settings\jpk\data aplikací\TuneUp Software
2013-01-18 19:26:50 -------- d-----w- C:\$AVG
2013-01-17 09:48:23 511328 ----a-w- c:\windows\capicom.dll
2013-01-17 09:47:31 1461992 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2013-01-17 09:31:26 -------- d-----w- c:\documents and settings\jpk\data aplikací\QuickScan
2013-01-17 08:56:46 -------- d-----w- c:\program files\common files\Bitdefender
2013-01-15 21:56:18 -------- d-----w- c:\program files\SCi
2013-01-15 21:56:01 212992 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ILog.dll
2013-01-15 19:24:49 -------- d-----w- c:\documents and settings\jpk\data aplikací\Enki Games
2013-01-15 15:46:00 -------- d-----w- c:\documents and settings\jpk\data aplikací\Alawar
2012-12-13 14:47:20 -------- d-----w- c:\documents and settings\jpk\data aplikací\Rovio
2012-12-09 11:06:25 -------- d-----w- c:\program files\common files\DirectX
2012-12-02 15:02:48 -------- d-----w- c:\documents and settings\jpk\data aplikací\PunkBuster
.
==================== Find6M ====================
.
2013-01-21 15:46:01 214520 ----a-w- c:\windows\system32\PnkBstrB.xtr
2013-01-21 15:46:01 214520 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-01-21 15:18:22 139152 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-01-21 15:18:22 139152 ----a-w- c:\documents and settings\jpk\data aplikací\PnkBstrK.sys
2013-01-21 15:17:59 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2013-01-21 10:10:56 794408 ----a-w- c:\windows\system32\pbsvc.exe
2012-12-16 16:03:38 65273848 ----a-w- c:\windows\system32\MRT.exe
2012-12-16 12:31:02 290560 ----a-w- c:\windows\system32\atmfd.dll
2012-11-13 11:56:25 1875456 ----a-w- c:\windows\system32\win32k.sys
2012-11-12 19:51:35 6010880 ----a-w- c:\windows\system32\mshtml.dll
2012-11-10 00:39:07 46080 ----a-w- c:\windows\system32\tzchange.exe
2012-11-08 10:29:12 1402312 ----a-w- c:\windows\system32\msxml4.dll
2012-11-06 02:00:18 1446912 ----a-w- c:\windows\system32\msxml6.dll
2012-11-02 02:03:56 375296 ----a-w- c:\windows\system32\dpnet.dll
2012-10-31 23:39:49 174080 ----a-w- c:\windows\system32\ie4uinit.exe
2012-10-31 23:39:31 385024 ----a-w- c:\windows\system32\html.iec
2012-10-12 18:09:40 22400 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-10-03 04:57:28 990208 ----a-w- c:\windows\system32\kernel32.dll
2012-10-02 18:04:39 58368 ----a-w- c:\windows\system32\synceng.dll
2012-09-01 06:44:57 477240 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-08-28 20:26:48 25200 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2012-08-28 20:26:47 12400 ----a-w- c:\windows\system32\drivers\ggflt.sys
2012-08-24 13:53:00 178176 ----a-w- c:\windows\system32\wintrust.dll
2012-08-23 10:56:14 2071808 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-23 06:26:12 2195200 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-15 22:02:52 1290240 ----a-w- c:\windows\system32\VSFilter.dll
2012-08-15 22:02:50 549888 ----a-w- c:\windows\system32\MatroskaSplitter.ax
2012-08-15 22:02:38 664576 ----a-w- c:\windows\system32\RealMediaSplitter.ax
2012-08-15 22:02:30 490496 ----a-w- c:\windows\system32\oggsplitter.ax
2012-08-15 22:02:20 477696 ----a-w- c:\windows\system32\AviSplitter.ax
.
============= FINISH: 17:09:23,59 ===============

Dik za další nápady.

Re: Zamrzající PC, díkec za kontrolu.

Napsal: 21 led 2013 17:32
od kamzl
A zde ten LOG z GMERu(jen doufám že co jeden řádek tak to neznamená nějakej pruser) :


a se ještě omlouvám za to odmazání příspěvku včera.


GMER 2.0.18444 - http://www.gmer.net
Rootkit scan 2013-01-21 17:29:04
Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17 ST3160215ACE rev.3.ACF 149,05GB
Running: gmer.exe; Driver: C:\DOCUME~1\jpk\LOCALS~1\Temp\kgpcaaog.sys


---- System - GMER 2.0 ----

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0xB80B04BA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0xB815DC22]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAssignProcessToJobObject [0xB80B0ED6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwClose [0xB80F2811]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0xB80BBFA8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0xB80BBFF4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0xB80BC176]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateKey [0xB80F21C5]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0xB80BBF16]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0xB80BC038]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0xB80BBF5E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateThread [0xB80B111C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0xB80BC130]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDebugActiveProcess [0xB80B193E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0xB80B0508]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteKey [0xB80F2ED7]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteValueKey [0xB80F318D]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDuplicateObject [0xB80B51C2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateKey [0xB80F2D42]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateValueKey [0xB80F2BAD]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0xB815DCEA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0xB80B0170]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0xB80B0556]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0xB80B5534]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0xB80B23A6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0xB80BBFD2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0xB80BC016]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0xB80BC19A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenKey [0xB80F2521]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0xB80BBF3C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenProcess [0xB80B4C3E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0xB80BC0BA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0xB80BBF86]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenThread [0xB80B4F14]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0xB80BC154]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0xB815DE4A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryKey [0xB80F2A28]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0xB80B2272]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryValueKey [0xB80F287A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueueApcThread [0xB80B1DD4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRenameKey [0xB816A7D2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwRestoreKey [0xB80F1838]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0xB80B05A4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0xB80B05F2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetContextThread [0xB80B17BE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0xB80B01FA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0xB80B03AA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetValueKey [0xB80F2FDE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0xB80B0350]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSuspendProcess [0xB80B1AF8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSuspendThread [0xB80B1C54]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0xB80B041A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwTerminateProcess [0xB80B14D4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwTerminateThread [0xB80B1636]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwUnloadDriver [0xB815C41C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0xB80B0640]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwWriteVirtualMemory [0xB80B0F1A]

INT 0x3A ? 89A37F00
INT 0x3A ? 89A37F00
INT 0x3A ? 89A37F00
INT 0x3B ? 89F5CCB8
INT 0x3B ? 89A37F00
INT 0x3B ? 89A37F00
INT 0x3B ? 89F5CCB8
INT 0x3E ? 89F15CB8
INT 0x3F ? 89F15CB8

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0xB8176E56]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject

---- Kernel code sections - GMER 2.0 ----

.text ntoskrnl.exe!_abnormal_termination + 198 804E2804 4 Bytes [EA, DC, 15, B8]
.text ntoskrnl.exe!_abnormal_termination + 398 804E2A04 12 Bytes [A4, 05, 0B, B8, F2, 05, 0B, ...] {MOVSB ; ADD EAX, 0x5f2b80b; OR EDI, [EAX-0x47f4e842]}
.text ntoskrnl.exe!_abnormal_termination + 440 804E2AAC 12 Bytes [F8, 1A, 0B, B8, 54, 1C, 0B, ...]
PAGE ntoskrnl.exe!ObInsertObject 8056513A 5 Bytes JMP B8175810 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntoskrnl.exe!ZwReplyWaitReceivePortEx + 3CC 8056BB88 4 Bytes CALL B80B2A77 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntoskrnl.exe!ZwCreateProcessEx 8058304C 7 Bytes JMP B8176E5A \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntoskrnl.exe!ObMakeTemporaryObject 8059EA42 5 Bytes JMP B8173CF6 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
.sptd1 C:\WINDOWS\system32\drivers\sptd.sys entry point in ".sptd1" section [0xF75B2B2E]
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB9804360, 0x24BB1D, 0xE8000020]
.text USBPORT.SYS!DllUnload B97408EC 5 Bytes JMP 89A37410
? C:\WINDOWS\System32\Drivers\at3zar9s.SYS suspicious PE modification
.text win32k.sys!EngFreeUserMem + 674 BF8098F2 5 Bytes JMP B80B6B4C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngFreeUserMem + 35D0 BF80C84E 5 Bytes JMP B80B6A3C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngDeleteSurface + 45 BF8138E6 5 Bytes JMP B80B69F6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!BRUSHOBJ_pvAllocRbrush + 322E BF81E59B 5 Bytes JMP B80B5688 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngMulDiv + 197D BF820CA8 5 Bytes JMP B80B60A8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngPaint + 11A6 BF82D4A6 5 Bytes JMP B80B57C4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngLockSurface + C09 BF82E624 5 Bytes JMP B80B6CB6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngUnmapFontFileFD + 654A BF83D89B 5 Bytes JMP B80B6EBE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngUnmapFontFileFD + BEF8 BF843249 5 Bytes JMP B80B68FC \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngUnmapFontFileFD + DB5F BF844EB0 5 Bytes JMP B80B5834 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!FONTOBJ_pxoGetXform + B0E8 BF864F60 5 Bytes JMP B80B6090 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + 350F BF8700AD 5 Bytes JMP B80B616A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + 5807 BF8723A5 5 Bytes JMP B80B5C1E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + 5892 BF872430 5 Bytes JMP B80B5EE4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + 6468 BF873006 5 Bytes JMP B80B5670 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + B846 BF8783E4 5 Bytes JMP B80B6A86 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngUnicodeToMultiByteN + 67E7 BF87F607 5 Bytes JMP B80B6BFE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGetCurrentCodePage + 3651 BF898924 5 Bytes JMP B80B5CDE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGetCurrentCodePage + 418E BF899461 5 Bytes JMP B80B5E9E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGetLastError + 1606 BF8B6552 5 Bytes JMP B80B6182 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGradientFill + 2862 BF8B9C70 5 Bytes JMP B80B6E1C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngAlphaBlend + 1A3D BF8C1C1C 5 Bytes JMP B80B5944 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngFillPath + 1517 BF8CA0AD 5 Bytes JMP B80B5A1C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngFillPath + 1797 BF8CA32D 5 Bytes JMP B80B5B48 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngDeleteSemaphore + 3B3E BF8EBCE7 5 Bytes JMP B80B556A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngDeleteSemaphore + CB45 BF8F4CEE 5 Bytes JMP B80B60C0 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateClip + 1A40 BF914536 5 Bytes JMP B80B5760 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateClip + 2614 BF91510A 5 Bytes JMP B80B58F0 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateClip + 4F8D BF917A83 5 Bytes JMP B80B5FFE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngPlgBlt + 192A BF947D12 5 Bytes JMP B80B6D74 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
? C:\DOCUME~1\jpk\LOCALS~1\Temp\mbr.sys Systém nemůže nalézt uvedený soubor. !

---- User code sections - GMER 2.0 ----

.text C:\Program Files\AVAST Software\Avast\avastUI.exe[424] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\Program Files\AVAST Software\Avast\avastUI.exe[424] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\system32\RUNDLL32.EXE[536] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\system32\RUNDLL32.EXE[536] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\system32\ctfmon.exe[576] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\system32\ctfmon.exe[576] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\System32\smss.exe[684] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!LdrLoadDll 7C915C35 5 Bytes JMP 006001F8
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ntdll.dll!LdrUnloadDll 7C916AD5 5 Bytes JMP 006003FC
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] KERNEL32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 01121014
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 01120804
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 01120A08
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 01120C0C
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 01120E10
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 011201F8
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 011203FC
.text C:\Program Files\Comodo\Dragon\dragon.exe[744] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 01120600
.text C:\WINDOWS\system32\csrss.exe[756] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\system32\csrss.exe[756] KERNEL32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\system32\winlogon.exe[780] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\system32\winlogon.exe[780] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\system32\services.exe[824] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\system32\services.exe[824] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\system32\lsass.exe[836] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\system32\lsass.exe[836] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1000] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1000] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1064] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1064] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\System32\svchost.exe[1160] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\System32\svchost.exe[1160] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1248] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1248] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1460] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1460] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1696] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1696] kernel32.dll!SetUnhandledExceptionFilter 7C8449B5 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1696] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\Explorer.EXE[1704] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\Explorer.EXE[1704] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\system32\spoolsv.exe[1780] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\system32\spoolsv.exe[1780] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\system32\nvsvc32.exe[1896] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\system32\nvsvc32.exe[1896] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\system32\PnkBstrA.exe[1932] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\system32\PnkBstrA.exe[1932] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\system32\PnkBstrB.exe[1988] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\system32\PnkBstrB.exe[1988] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[2028] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[2028] kernel32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\WINDOWS\system32\NOTEPAD.EXE[3684] ntdll.dll!LdrLoadDll 7C915C35 5 Bytes JMP 003201F8
.text C:\WINDOWS\system32\NOTEPAD.EXE[3684] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\WINDOWS\system32\NOTEPAD.EXE[3684] ntdll.dll!LdrUnloadDll 7C916AD5 5 Bytes JMP 003203FC
.text C:\WINDOWS\system32\NOTEPAD.EXE[3684] KERNEL32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] ntdll.dll!LdrLoadDll 7C915C35 5 Bytes JMP 003D01F8
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] ntdll.dll!LdrUnloadDll 7C916AD5 5 Bytes JMP 003D03FC
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] KERNEL32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 009E1014
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 009E0804
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 009E0A08
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 009E0C0C
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 009E0E10
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 009E01F8
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 009E03FC
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 009E0600
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 009F0804
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 009F0A08
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 009F0600
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 009F01F8
.text C:\DOCUME~1\jpk\LOCALS~1\Temp\Rar$EXa0.408\gmer.exe[3796] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 009F03FC
.text C:\Program Files\Comodo\Dragon\dragon.exe[3896] ntdll.dll!LdrLoadDll 7C915C35 5 Bytes JMP 003D01F8
.text C:\Program Files\Comodo\Dragon\dragon.exe[3896] ntdll.dll!RtlDosSearchPath_U + 186 7C91616D 1 Byte [62]
.text C:\Program Files\Comodo\Dragon\dragon.exe[3896] ntdll.dll!LdrUnloadDll 7C916AD5 5 Bytes JMP 003D03FC
.text C:\Program Files\Comodo\Dragon\dragon.exe[3896] KERNEL32.dll!GetBinaryTypeW + 80 7C8693DC 1 Byte [62]
.text C:\Program Files\Comodo\Dragon\dragon.exe[3896] ADVAPI32.dll!SetServiceObjectSecurity 77E26D89 5 Bytes JMP 01B61014
.text C:\Program Files\Comodo\Dragon\dragon.exe[3896] ADVAPI32.dll!ChangeServiceConfigA 77E26E71 5 Bytes JMP 01B60804
.text C:\Program Files\Comodo\Dragon\dragon.exe[3896] ADVAPI32.dll!ChangeServiceConfigW 77E27009 5 Bytes JMP 01B60A08
.text C:\Program Files\Comodo\Dragon\dragon.exe[3896] ADVAPI32.dll!ChangeServiceConfig2A 77E27109 5 Bytes JMP 01B60C0C
.text C:\Program Files\Comodo\Dragon\dragon.exe[3896] ADVAPI32.dll!ChangeServiceConfig2W 77E27191 5 Bytes JMP 01B60E10
.text C:\Program Files\Comodo\Dragon\dragon.exe[3896] ADVAPI32.dll!CreateServiceA 77E27219 5 Bytes JMP 01B601F8
.text C:\Program Files\Comodo\Dragon\dragon.exe[3896] ADVAPI32.dll!CreateServiceW 77E273B1 5 Bytes JMP 01B603FC
.text C:\Program Files\Comodo\Dragon\dragon.exe[3896] ADVAPI32.dll!DeleteService 77E274B9 5 Bytes JMP 01B60600

---- Registry - GMER 2.0 ----

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x86 0x26 0x42 0x08 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x79 0xB6 0x8C 0x13 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x2A 0x1E 0x7E 0x7F ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x7A 0x58 0x5C 0x83 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x98 0xDD 0x4C 0x5F ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x79 0xB6 0x8C 0x13 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xA7 0x6F 0x0C 0xA0 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x7A 0x58 0x5C 0x83 ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001bdc0f87f6 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xB5 0x2B 0xA3 0x7A ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x17 0x87 0xEA 0xE7 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x10 0xF2 0x32 0x3A ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x7A 0x58 0x5C 0x83 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001bdc0f87f6
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xB5 0x2B 0xA3 0x7A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x17 0x87 0xEA 0xE7 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x10 0xF2 0x32 0x3A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x7A 0x58 0x5C 0x83 ...
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\001bdc0f87f6 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xB5 0x2B 0xA3 0x7A ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x17 0x87 0xEA 0xE7 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x10 0xF2 0x32 0x3A ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x7A 0x58 0x5C 0x83 ...

---- EOF - GMER 2.0 ----

Re: Zamrzající PC, díkec za kontrolu.

Napsal: 21 led 2013 17:54
od kamzl
Program od kasperskyho to čištění zamrzne taky u souboru rvsp.exe zkoušel sem to několikrát.LOG nedodám :(

Nouzový režim F8 nefunguje taky zamrzne, záhadou mi je proč teda de zbytek. :(

Re: Zamrzající PC, díkec za kontrolu.

Napsal: 21 led 2013 19:21
od kamzl
DO čisté instalace win xp?

Re: Zamrzající PC, díkec za kontrolu.

Napsal: 21 led 2013 19:30
od kamzl
hele a ještě ta plná černá obrazovka plná býlejch smajlíků co se mi škleběj to je nějaká ta havěť?

nemáš nějakej odkaz na dema virů. něco jak bylo tehdá v tom pra avg ve win95? anebo vim že to je hledat jehlu v kupce sena jméno nebo co by to mohlo být nevíš? a jak ho poslat někam?

Re: Zamrzající PC, díkec za kontrolu.

Napsal: 22 led 2013 16:25
od vyosek
Zdravim :)

:arrow: Kolega me poprosim o soucinnost

:arrow: Odkazy kde ziskat viry vam tu nebudeme, to by bylo jaksi proti logice naseho fora

:arrow: Dejte sem novy log z RSIT at se podiva jak to aktualne vypada