Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

preventivka

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
cokolad
2. Stupeň Varování
Příspěvky: 84
Registrován: 08 čer 2011 17:58

preventivka

#1 Příspěvek od cokolad »

PC mojej kamaratky..asi bude treba trochu precistit

Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2013-09-04 17:37:23
Systém Microsoft Windows XP Professional Service Pack 3
System drive D: has 23 GB (17%) free of 138 GB
Total RAM: 3327 MB (67% free)

HijackThis download failed

======Scheduled tasks folder======

D:\WINDOWS\tasks\Adobe Flash Player Updater.job
D:\WINDOWS\tasks\AppleSoftwareUpdate.job
D:\WINDOWS\tasks\EPUpdater.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-220523388-839522115-500Core.job
D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-220523388-839522115-500UA.job
D:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-220523388-839522115-500.job
D:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-220523388-839522115-500.job
D:\WINDOWS\tasks\ReclaimerUpdateFiles_Administrator.job
D:\WINDOWS\tasks\ReclaimerUpdateXML_Administrator.job
D:\WINDOWS\tasks\RNUpgradeHelperLogonPrompt_Administrator.job
D:\WINDOWS\tasks\User_Feed_Synchronization-{6845AAD2-5603-411A-9949-CD23FF6D99F2}.job
D:\WINDOWS\tasks\WGASetup.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-01-03 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-10-21 414416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - D:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll [2011-04-11 767280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68F9551E-0411-48E4-9AAF-4BC42A6A46BE}]
EWPBrowseObject Class - D:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll [2006-04-18 34304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - D:\Program Files\Java\jre7\bin\ssv.dll [2013-02-09 461216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{984A9162-8891-4D19-8CFE-17648BB4E1EC}]
GamePlayLabsBHO Class

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}]
Babylon IE plugin

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - D:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-08-18 192592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-08-14 4533120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - D:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll [2013-06-26 1000984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}]
delta Helper Object - D:\Program Files\Delta\delta\1.8.21.5\bh\delta.dll [2013-05-20 295832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c4b22c87-45ef-4f43-89f2-40db2078864e}]
Search Assistant BHO - D:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll [2012-07-09 66960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D496B221-52BB-4DA7-B5E7-4442022F207D}]
MyPlayCity Toolbar BHO - D:\Program Files\MyPlayCity Toolbar\Toolbar.dll [2010-09-08 1499136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{da71fd14-5f7b-46ae-b8b1-44074a38f331}]
Toolbar BHO - D:\PROGRA~1\MYFUNC~1\bar\1.bin\5mbar.dll [2012-07-09 699536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-02-09 170912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{07B18EA9-A523-4961-B6BB-170DE4475CCA}
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - D:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2006-04-18 552960]
{648ADDE1-369B-4868-A419-0B67EBFD8F73} - MyPlayCity Toolbar - D:\Program Files\MyPlayCity Toolbar\Toolbar.dll [2010-09-08 1499136]
{95B7759C-8C7F-4BF1-B163-73684A933233}
{210f1b36-3b7f-41a4-b5da-3eb87f5a56c2} - MyFunCards - D:\Program Files\MyFunCards_5m\bar\1.bin\5mbar.dll [2012-07-09 699536]
{82E1477C-B154-48D3-9891-33D83C26BCD3} - Delta Toolbar - D:\Program Files\Delta\delta\1.8.21.5\deltaTlbr.dll [2013-05-20 284056]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - D:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-08-18 192592]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=D:\WINDOWS\RTHDCPL.EXE [2006-06-28 16248320]
"SkyTel"=D:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
"Alcmtr"=D:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"ATICCC"=D:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2006-01-02 45056]
"snp2std"=D:\WINDOWS\vsnp2std.exe [2006-08-09 675840]
"GrooveMonitor"=D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"Olympus ib"=D:\Program Files\Olympus\ib\olycamdetect.exe [2011-05-20 93360]
"MDS_Menu"=D:\Program Files\Olympus\ib\MUITransfer\MUIStartMenu.exe [2010-07-01 220336]
"TkBellExe"=D:\program files\real\realplayer\update\realsched.exe [2011-10-21 273528]
"HTC Sync Loader"=D:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2011-11-01 593920]
"Adobe Reader Speed Launcher"=D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2012-01-03 37296]
"Adobe ARM"=D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"APSDaemon"=D:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-02-20 59240]
"QuickTime Task"=D:\Program Files\QuickTime\QTTask.exe [2011-10-24 421888]
"iTunesHelper"=D:\Program Files\iTunes\iTunesHelper.exe [2011-12-08 421736]
"MyFunCards Search Scope Monitor"=D:\PROGRA~1\MYFUNC~1\bar\1.bin\5msrchmn.exe [2012-07-09 42552]
"MyFunCards_5m Browser Plugin Loader"=D:\PROGRA~1\MYFUNC~1\bar\1.bin\5mbrmon.exe [2012-07-09 30096]
"avgnt"=D:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2013-09-04 345144]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Google Update"=D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-06-22 136176]
"Akamai NetSession Interface"=D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Akamai\netsession_win.exe [2013-06-05 4489472]
"msnmsgr"=D:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"ICQ"=D:\Program Files\ICQ7M\ICQ.exe [2013-01-22 127040]
"Skype"=D:\Program Files\Skype\Phone\Skype.exe [2013-02-28 18642024]
"swg"=D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2013-06-25 39408]

D:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění
YoWindow.lnk - D:\Program Files\YoWindow\yowindow.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="d:\docume~1\alluse~1\dataap~1\browse~1\261519~1.190\{c16c1~1\browse~1.dll "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
D:\WINDOWS\system32\Ati2evxx.dll [2006-06-07 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\BitComet\BitComet.exe"="D:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet.exe"
"D:\WINDOWS\system32\muzapp.exe"="D:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player"
"D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"D:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="D:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"D:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="D:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"D:\Program Files\Windows Live\Messenger\msnmsgr.exe"="D:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"D:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="D:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"D:\Program Files\MyPlayCity Toolbar\TroubleShooter.exe"="D:\Program Files\MyPlayCity Toolbar\TroubleShooter.exe:*:Enabled:MyPlayCity Toolbar (Helper)"
"D:\Program Files\MyPlayCity Toolbar\ToolbarUpdate.exe"="D:\Program Files\MyPlayCity Toolbar\ToolbarUpdate.exe:*:Enabled:MyPlayCity Toolbar (Update)"
"D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe"="D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
"D:\Program Files\Opera\opera.exe"="D:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"D:\Program Files\Remote Desktop Control 2\apc_host.exe"="D:\Program Files\Remote Desktop Control 2\apc_host.exe:*:Enabled:Remote Desktop Control - Host Module"
"D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Akamai\netsession_win.exe"="D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Akamai\netsession_win.exe:*:Enabled:Akamai NetSession Interface"
"D:\Program Files\Bonjour\mDNSResponder.exe"="D:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"D:\Program Files\iTunes\iTunes.exe"="D:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"D:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="D:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"D:\Program Files\Condition Zero\hl.exe"="D:\Program Files\Condition Zero\hl.exe:*:Disabled:Half-Life Launcher"
"D:\Program Files\DsNET Corp\aTube Catcher 2.0\yct.exe"="D:\Program Files\DsNET Corp\aTube Catcher 2.0\yct.exe:*:Enabled:aTube Catcher to download and convert videos."
"D:\Program Files\ICQ7M\ICQ.exe"="D:\Program Files\ICQ7M\ICQ.exe:*:Enabled:ICQ7M"
"D:\Program Files\Valve\hl.exe"="D:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"D:\Program Files\Skype\Phone\Skype.exe"="D:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"D:\Program Files\AVG\AVG2013\avgnsx.exe"="D:\Program Files\AVG\AVG2013\avgnsx.exe:*:Enabled:Webový štít"
"D:\Program Files\AVG\AVG2013\avgdiagex.exe"="D:\Program Files\AVG\AVG2013\avgdiagex.exe:*:Enabled:AVG Diagnostika 2013"
"D:\Program Files\AVG\AVG2013\avgmfapx.exe"="D:\Program Files\AVG\AVG2013\avgmfapx.exe:*:Enabled:Inštalátor produktu AVG"
"D:\Program Files\AVG\AVG2013\avgemcx.exe"="D:\Program Files\AVG\AVG2013\avgemcx.exe:*:Enabled:Všeobecná kontrola pošty"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\ICQ7.2\aolload.exe"="D:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\Windows Live\Messenger\msnmsgr.exe"="D:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"D:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="D:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"D:\Program Files\ICQ7M\ICQ.exe"="D:\Program Files\ICQ7M\ICQ.exe:*:Enabled:ICQ7M"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8758589f-401a-11e0-9fe0-001617bfa73d}]
shell\AutoRun\command - J:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aa1630ad-b50d-11df-9f09-001617bfa73d}]
shell\AutoRun\command - K:\USBAutoRun.exe


======List of files/folders created in the last 1 months======

2013-09-04 17:37:24 ----D---- D:\Program Files\trend micro
2013-09-04 17:37:23 ----D---- D:\rsit
2013-09-04 17:37:23 ----D---- D:\Documents and Settings\Administrator\Data aplikací\Avira
2013-09-04 17:34:21 ----D---- D:\WINDOWS\system32\NtmsData
2013-09-04 17:31:35 ----D---- D:\Program Files\Avira
2013-09-04 17:31:35 ----D---- D:\Documents and Settings\All Users\Data aplikací\Avira
2013-09-04 17:19:08 ----D---- D:\Program Files\CCleaner
2013-09-01 19:59:43 ----D---- D:\Documents and Settings\Administrator\Data aplikací\AVG
2013-09-01 19:59:13 ----D---- D:\Documents and Settings\All Users\Data aplikací\AVG
2013-09-01 19:58:57 ----SHD---- D:\Documents and Settings\All Users\Data aplikací\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-09-01 18:15:01 ----HDC---- D:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2013-08-18 22:28:58 ----D---- D:\WINDOWS\system32\MRT
2013-08-18 22:27:59 ----HDC---- D:\WINDOWS\$NtUninstallKB2850869$
2013-08-18 22:27:49 ----HDC---- D:\WINDOWS\$NtUninstallKB2859537$
2013-08-18 22:27:42 ----HDC---- D:\WINDOWS\$NtUninstallKB2863058$
2013-08-18 22:27:35 ----HDC---- D:\WINDOWS\$NtUninstallKB2849470$
2013-08-10 13:10:11 ----D---- D:\Documents and Settings\Administrator\Data aplikací\AVG2013
2013-08-10 13:07:01 ----D---- D:\Documents and Settings\Administrator\Data aplikací\TuneUp Software
2013-08-10 13:04:55 ----D---- D:\Documents and Settings\All Users\Data aplikací\AVG2013

======List of files/folders modified in the last 1 months======

2013-09-04 17:37:24 ----RD---- D:\Program Files
2013-09-04 17:37:02 ----D---- D:\WINDOWS\Temp
2013-09-04 17:34:24 ----HD---- D:\WINDOWS\inf
2013-09-04 17:34:24 ----D---- D:\WINDOWS
2013-09-04 17:34:21 ----D---- D:\WINDOWS\system32
2013-09-04 17:34:21 ----D---- D:\WINDOWS\repair
2013-09-04 17:34:18 ----D---- D:\WINDOWS\Registration
2013-09-04 17:32:12 ----D---- D:\WINDOWS\Prefetch
2013-09-04 17:31:45 ----D---- D:\WINDOWS\system32\CatRoot2
2013-09-04 17:31:37 ----D---- D:\WINDOWS\system32\drivers
2013-09-04 17:27:25 ----D---- D:\Program Files\DAEMON Tools Toolbar
2013-09-04 17:26:58 ----D---- D:\Program Files\Spybot - Search & Destroy
2013-09-04 17:26:58 ----D---- D:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2013-09-04 17:26:33 ----SD---- D:\WINDOWS\Tasks
2013-09-04 17:26:32 ----SHD---- D:\WINDOWS\Installer
2013-09-04 17:26:27 ----SHD---- D:\Config.Msi
2013-09-04 17:23:56 ----D---- D:\Documents and Settings\Administrator\Data aplikací\DAEMON Tools Lite
2013-09-04 17:23:55 ----D---- D:\Documents and Settings\Administrator\Data aplikací\Media Player Classic
2013-09-04 17:23:52 ----D---- D:\Documents and Settings\Administrator\Data aplikací\Skype
2013-09-04 17:23:42 ----D---- D:\WINDOWS\Minidump
2013-09-04 17:23:42 ----D---- D:\WINDOWS\Logs
2013-09-04 17:23:42 ----D---- D:\WINDOWS\Debug
2013-09-04 17:16:22 ----D---- D:\Program Files\AVG
2013-09-04 17:05:00 ----D---- D:\Program Files\Common Files\Akamai
2013-09-04 17:02:12 ----N---- D:\WINDOWS\SchedLgU.Txt
2013-09-04 17:01:37 ----D---- D:\Documents and Settings\All Users\Data aplikací\MFAData
2013-09-03 11:15:47 ----A---- D:\WINDOWS\NeroDigital.ini
2013-09-01 20:00:00 ----D---- D:\WINDOWS\system32\config
2013-08-30 20:09:56 ----D---- D:\Program Files\Opera
2013-08-24 21:44:12 ----D---- D:\WINDOWS\Microsoft.NET
2013-08-24 21:43:50 ----RSD---- D:\WINDOWS\assembly
2013-08-24 21:25:36 ----D---- D:\Documents and Settings\All Users\Data aplikací\Skype
2013-08-24 21:25:27 ----RD---- D:\Program Files\Skype
2013-08-18 22:33:29 ----RSHDC---- D:\WINDOWS\system32\dllcache
2013-08-18 22:33:22 ----D---- D:\Program Files\Internet Explorer
2013-08-18 22:33:15 ----D---- D:\WINDOWS\ie8updates
2013-08-18 22:28:54 ----A---- D:\WINDOWS\system32\MRT.exe
2013-08-18 22:28:49 ----D---- D:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2013-08-18 22:26:50 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2013-08-18 22:26:26 ----D---- D:\WINDOWS\WinSxS
2013-08-14 22:03:51 ----D---- D:\WINDOWS\system32\cache
2013-08-10 13:09:41 ----HD---- D:\$AVG
2013-08-10 11:18:10 ----D---- D:\Documents and Settings\All Users\Data aplikací\BrowserDefender
2013-08-05 15:52:28 ----D---- D:\Program Files\Google

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; D:\WINDOWS\System32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 avgtp;avgtp; \??\D:\WINDOWS\system32\drivers\avgtpx86.sys []
R1 avipbb;avipbb; D:\WINDOWS\system32\DRIVERS\avipbb.sys [2013-09-04 135136]
R1 avkmgr;avkmgr; D:\WINDOWS\system32\DRIVERS\avkmgr.sys [2013-09-04 37352]
R1 SCDEmu;SCDEmu; D:\WINDOWS\system32\drivers\SCDEmu.sys [2007-04-09 31548]
R2 avgntflt;avgntflt; D:\WINDOWS\system32\DRIVERS\avgntflt.sys [2013-09-04 84744]
R2 irda;Protokol IrDA; D:\WINDOWS\System32\DRIVERS\irda.sys [2008-04-13 88192]
R2 npf;NetGroup Packet Filter Driver; D:\WINDOWS\system32\drivers\npf.sys [2009-11-16 50704]
R3 ati2mtag;ati2mtag; D:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2006-06-07 1580544]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; D:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2010-04-12 15664]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; D:\WINDOWS\System32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Ovladač třídy standardu HID; D:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); D:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-06-28 4304384]
R3 irsir;Microsoft Serial Infrared Driver; D:\WINDOWS\System32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 LgBttPort;LGE Bluetooth TransPort; D:\WINDOWS\system32\DRIVERS\lgbtport.sys [2009-09-29 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator; D:\WINDOWS\system32\DRIVERS\lgbtbus.sys [2009-09-29 10496]
R3 LGVMODEM;LGE Virtual Modem; D:\WINDOWS\system32\DRIVERS\lgvmodem.sys [2009-09-29 12928]
R3 mouhid;Ovladač myši standardu HID; D:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; D:\WINDOWS\System32\DRIVERS\NVENETFD.sys [2006-03-22 52736]
R3 nvnetbus;NVIDIA Network Bus Enumerator; D:\WINDOWS\System32\DRIVERS\nvnetbus.sys [2006-03-22 18944]
R3 Rasirda;WAN Miniport (IrDA); D:\WINDOWS\System32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 SNP2STD;USB2.0 PC Camera (SNP2STD); D:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2006-08-11 11985920]
R3 usbaudio;Ovladač zvukové karty USB (WDM); D:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; D:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; D:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; D:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-13 17152]
S1 AVGIDSShim;AVGIDSShim; D:\WINDOWS\system32\DRIVERS\avgidsshimx.sys []
S1 ssmdrv;ssmdrv; D:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2013-09-04 28520]
S3 aayelp7y;aayelp7y; D:\WINDOWS\system32\drivers\aayelp7y.sys []
S3 CCDECODE;Dekodér Closed Caption; D:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 cpuz132;cpuz132; \??\D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys []
S3 FlashUSB;FlashUSB; D:\WINDOWS\system32\DRIVERS\FlashUSB.sys [2009-05-12 16896]
S3 GMSIPCI;GMSIPCI; \??\H:\INSTALL\GMSIPCI.SYS []
S3 hamachi;Hamachi Network Interface; D:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-09-17 25280]
S3 HTCAND32;HTC Device Driver; D:\WINDOWS\System32\Drivers\ANDROIDUSB.sys [2009-06-10 24576]
S3 htcnprot;HTC NDIS Protocol Driver; D:\WINDOWS\system32\DRIVERS\htcnprot.sys [2010-06-22 21248]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; D:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; D:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 SLIP;BDA Slip De-Framer; D:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; D:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usb_rndisx;Adaptér USB RNDIS; D:\WINDOWS\system32\DRIVERS\usb8023x.sys [2013-02-12 12928]
S3 USBAAPL;Apple Mobile USB Driver; D:\WINDOWS\System32\Drivers\usbaapl.sys [2012-02-15 43520]
S3 usbbus;LGE Mobile Composite USB Device; D:\WINDOWS\system32\DRIVERS\lgusbbus.sys [2008-11-19 13056]
S3 UsbDiag;LGE Mobile USB Serial Port; D:\WINDOWS\system32\DRIVERS\lgusbdiag.sys [2008-11-19 19968]
S3 USBModem;LGE Mobile USB Modem; D:\WINDOWS\system32\DRIVERS\lgusbmodem.sys [2008-11-19 24832]
S3 usbprint;Třída USB Printer; D:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; D:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; D:\WINDOWS\System32\Drivers\wdf01000.sys [2008-01-19 503144]
S3 WpdUsb;WpdUsb; D:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; D:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; D:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; D:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2008-10-27 759072]
R2 Akamai;Akamai NetSession Interface; D:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 AntiVirService;Avira Real-Time Protection; D:\Program Files\Avira\AntiVir Desktop\avguard.exe [2013-09-04 108088]
R2 AntiVirSchedulerService;Avira Scheduler; D:\Program Files\Avira\AntiVir Desktop\sched.exe [2013-09-04 84024]
R2 Apache2;Apache2; D:\Program Files\PHP Home Edition 2\Apache2\bin\Apache.exe [2004-06-29 20541]
R2 Apple Mobile Device;Apple Mobile Device; D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-02-27 55144]
R2 Ati HotKey Poller;Ati HotKey Poller; D:\WINDOWS\System32\Ati2evxx.exe [2006-06-07 409600]
R2 Bonjour Service;Bonjour Service; D:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 390504]
R2 BrowserDefendert;BrowserDefendert; D:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [2013-07-26 2847696]
R2 Irmon;Sledování infračerveného přenosu; D:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre7\bin\jqs.exe [2013-02-09 170912]
R2 MySql;MySql; D:/PROGRA~1/PHPHOM~1/mysql/bin/mysqld-nt.exe []
R2 PassThru Service;Internet Pass-Through Service; D:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [2011-08-12 87040]
R2 PSI_SVC_2;Protexis Licensing V2; d:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
R2 RDC-Host;RDC-Host; D:\Program Files\Remote Desktop Control 2\apc_host.exe [2010-04-09 510464]
R2 Skype C2C Service;Skype C2C Service; D:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-08-14 3291008]
R2 vToolbarUpdater15.5.0;vToolbarUpdater15.5.0; D:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [2013-08-14 1643184]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; D:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 iPod Service;iPod Service; D:\Program Files\iPod\bin\iPodService.exe [2011-12-08 821608]
S2 ATI Smart;ATI Smart; D:\WINDOWS\system32\ati2sgag.exe [2006-06-07 520192]
S2 gupdate;Služba Google Update (gupdate); D:\Program Files\Google\Update\GoogleUpdate.exe [2010-12-04 136176]
S2 MyFunCards_5mService;MyFunCardsService; D:\PROGRA~1\MYFUNC~1\bar\1.bin\5mbarsvc.exe [2012-07-09 42528]
S2 SkypeUpdate;Skype Updater; D:\Program Files\Skype\Updater\Updater.exe [2013-02-28 161384]
S3 Adobe LM Service;Adobe LM Service; D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-08-26 72704]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; D:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-12 253656]
S3 aspnet_state;ASP.NET State Service; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; d:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); D:\Program Files\Google\Update\GoogleUpdate.exe [2010-12-04 136176]
S3 gusvc;Google Software Updater; D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-06-25 194032]
S3 idsvc;Windows CardSpace; d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; D:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; D:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; D:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 AntiVirWebService;Avira Web Protection; D:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2013-09-04 589368]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

cokolad
2. Stupeň Varování
Příspěvky: 84
Registrován: 08 čer 2011 17:58

Re: preventivka

#2 Příspěvek od cokolad »

hmm nezabudli ste na mna? :cry:

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: preventivka

#3 Příspěvek od Márty84 »

cokolad píše:hmm nezabudli ste na mna? :cry:
Nezabudli. Je treba vydrzet. Jsme tu ve svem volnem case a toho bohuzel neni tolik, kolik bychom si vsichni prali. Pokud potrebujete urgentni pomoc, budete muset navstivit servis :42:


:arrow: Mate starou verzi RSIT. Stahnete novou a dejte log http://forum.viry.cz/viewtopic.php?f=24&t=130784


:arrow: Udelejte !!!kompletni!!! kontrolu s MBAM http://forum.viry.cz/viewtopic.php?f=29&t=115222 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

cokolad
2. Stupeň Varování
Příspěvky: 84
Registrován: 08 čer 2011 17:58

Re: preventivka

#4 Příspěvek od cokolad »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Administrator at 2013-09-09 16:06:19
Systém Microsoft Windows XP Professional Service Pack 3
System drive D: has 23 GB (16%) free of 138 GB
Total RAM: 3327 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:06:36, on 9.9.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\System32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Avira\AntiVir Desktop\sched.exe
D:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Avira\AntiVir Desktop\avguard.exe
D:\Program Files\PHP Home Edition 2\Apache2\bin\Apache.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
D:\Program Files\PHP Home Edition 2\Apache2\bin\Apache.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe
D:\Program Files\Java\jre7\bin\jqs.exe
D:\PROGRA~1\PHPHOM~1\mysql\bin\mysqld-nt.exe
D:\Program Files\Google\Update\GoogleUpdate.exe
D:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe
D:\Program Files\Google\Update\GoogleUpdate.exe
D:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
d:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
D:\Program Files\Remote Desktop Control 2\apc_host.exe
D:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Avira\AntiVir Desktop\avshadow.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe
D:\WINDOWS\RTHDCPL.EXE
D:\Program Files\ATI Technologies\ATI.ACE\cli.exe
D:\WINDOWS\vsnp2std.exe
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Program Files\Olympus\ib\olycamdetect.exe
D:\program files\real\realplayer\update\realsched.exe
D:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\PROGRA~1\MYFUNC~1\bar\1.bin\5msrchmn.exe
D:\PROGRA~1\MYFUNC~1\bar\1.bin\5mbrmon.exe
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\1.3.21.153\GoogleCrashHandler.exe
D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Akamai\netsession_win.exe
D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Akamai\netsession_win.exe
D:\Program Files\Windows Live\Messenger\msnmsgr.exe
D:\Program Files\ICQ7M\ICQ.exe
D:\Program Files\Skype\Phone\Skype.exe
D:\Program Files\YoWindow\yowindow.exe
D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Program Files\ATI Technologies\ATI.ACE\cli.exe
D:\Program Files\ATI Technologies\ATI.ACE\cli.exe
D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Administrator\Plocha\RSIT.exe
D:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.mywebsearch.com/index.jhtml ... E6494&si=5
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;127.0.0.1:9421;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: FCToolbarURLSearchHook Class - {3a750e59-9048-456b-a7f9-4d22dcb583f3} - D:\Program Files\MyPlayCity Toolbar\Helper.dll
R3 - URLSearchHook: (no name) - {f4c28532-b9d0-4950-a2df-e83f9929242b} - D:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll
O1 - Hosts: 127.0.0.0 pokec.sk
O1 - Hosts: 127.0.0.0 www.pokec.sk
O1 - Hosts: 127.0.0.0 moje.azet.sk
O1 - Hosts: 127.0.0.0 www.moje.azet.sk
O1 - Hosts: 127.0.0.0 azet.sk
O1 - Hosts: 127.0.0.0 www.azet.sk
O1 - Hosts: 127.0.0.0 pokec.azet.sk
O1 - Hosts: 127.0.0.0 www.pokec.azet.sk
O1 - Hosts: 127.0.0.0 www.sex.cz
O1 - Hosts: 127.0.0.0 sex.cz
O1 - Hosts: 127.0.0.0 divky.cz
O1 - Hosts: 127.0.0.0 www.divky.cz
O1 - Hosts: 127.0.0.0 sexosky.sk
O1 - Hosts: 127.0.0.0 www.sexosky.sk
O1 - Hosts: 127.0.0.0 www.sex-link.cz
O1 - Hosts: 127.0.0.0 sex-link.cz
O1 - Hosts: 127.0.0.0 sex-list.cz
O1 - Hosts: 127.0.0.0 www.sex-list.cz
O1 - Hosts: 127.0.0.0 www.sexparty.jex.cz
O1 - Hosts: 127.0.0.0 sexparty.jex.cz
O1 - Hosts: 127.0.0.0 fmg.sk
O1 - Hosts: 127.0.0.0 www.fmg.sk
O1 - Hosts: 127.0.0.0 www.bomba.sk
O1 - Hosts: 127.0.0.0 bomba.sk
O1 - Hosts: 127.0.0.0 ceske-divky.cz
O1 - Hosts: 127.0.0.0 www.ceske-divky.cz
O1 - Hosts: 127.0.0.0 www.sexus.cz
O1 - Hosts: 127.0.0.0 sexus.cz
O1 - Hosts: 127.0.0.0 pornhub.com
O1 - Hosts: 127.0.0.0 www.pornhub.com
O1 - Hosts: 127.0.0.0 www.18plusworld.com
O1 - Hosts: 127.0.0.0 18plusworld.com
O1 - Hosts: 127.0.0.0 babepussies.com
O1 - Hosts: 127.0.0.0 www.babepussies.com
O1 - Hosts: 127.0.0.0 megateengirls.com
O1 - Hosts: 127.0.0.0 www.megateengirls.com
O1 - Hosts: 127.0.0.0 kiwiteens.com
O1 - Hosts: 127.0.0.0 www.kiwiteens.com
O1 - Hosts: 127.0.0.0 inthecrack.com
O1 - Hosts: 127.0.0.0 www.inthecrack.com
O1 - Hosts: 127.0.0.0 idealpanties.com
O1 - Hosts: 127.0.0.0 www.idealpanties.com
O1 - Hosts: 127.0.0.0 ideal-tens.com
O1 - Hosts: 127.0.0.0 www.ideal-teens.com
O1 - Hosts: 127.0.0.0 gallys.rk.com
O1 - Hosts: 127.0.0.0 www.gallys.rk.com
O1 - Hosts: 127.0.0.0 gallys.realitykings.com
O1 - Hosts: 127.0.0.0 www.gallys.realitykings.com
O1 - Hosts: 127.0.0.0 glamcuties.com
O1 - Hosts: 127.0.0.0 www.glamcuties.com
O1 - Hosts: 127.0.0.0 chicpussy.com
O1 - Hosts: 127.0.0.0 www.chicpussy.com
O1 - Hosts: 127.0.0.0 galeries2.ftvcash.com
O1 - Hosts: 127.0.0.0 www.galeries2.ftvcash.com
O1 - Hosts: 127.0.0.0 galleries.penthouse.com
O1 - Hosts: 127.0.0.0 www.galleries.penthouse.com
O1 - Hosts: 127.0.0.0 galleries.paperstreetcash.com
O1 - Hosts: 127.0.0.0 www.galleries.paperstreetcash.com
O1 - Hosts: 127.0.0.0 galleries.muffx.com
O1 - Hosts: 127.0.0.0 www.galleries.muffx.com
O1 - Hosts: 127.0.0.0 fantasticnudes.com
O1 - Hosts: 127.0.0.0 www.fantasticnudes.com
O1 - Hosts: 127.0.0.0 famouspornstars.com
O1 - Hosts: 127.0.0.0 www.famouspornstars.com
O1 - Hosts: 127.0.0.0 digitaldesirebabes.com
O1 - Hosts: 127.0.0.0 www.digitaldesirebabes.com
O1 - Hosts: 127.0.0.0 babesxworld.com
O1 - Hosts: 127.0.0.0 www.babesxworld.com
O1 - Hosts: 127.0.0.0 bitcast-a.v1.fra1.bitgravity.com
O1 - Hosts: 127.0.0.0 www.bitcast-a.v1.fra1.bitgravity.com
O1 - Hosts: 127.0.0.0 babesoftwistys.com
O1 - Hosts: 127.0.0.0 www.babesoftwistys.com
O1 - Hosts: 127.0.0.0 babesboom.com
O1 - Hosts: 127.0.0.0 www.babesboom.com
O1 - Hosts: 127.0.0.0 babepussies.com
O1 - Hosts: 127.0.0.0 www.babepussies.com
O1 - Hosts: 127.0.0.0 alexpix.com
O1 - Hosts: 127.0.0.0 www.alexpix.com
O1 - Hosts: 127.0.0.0 1bydaybabes.com
O1 - Hosts: 127.0.0.0 www.1bydaybabes.com
O1 - Hosts: 127.0.0.0 1cdn.ddstatic.com
O1 - Hosts: 127.0.0.0 www.1cdn.ddstatic.com
O1 - Hosts: 127.0.0.0 0.cdn.ddstatic.com
O1 - Hosts: 127.0.0.0 www.0.cdn.ddstatic.com
O1 - Hosts: 127.0.0.0 fhg.bcash4you.com
O1 - Hosts: 127.0.0.0 www.fhg.bcash4you.com
O1 - Hosts: 127.0.0.0 fhg.digitaldesire.com
O1 - Hosts: 127.0.0.0 www.fhg.digitaldesire.com
O1 - Hosts: 127.0.0.0 girlstwistys.com
O1 - Hosts: 127.0.0.0 www.girlstwistys.com
O1 - Hosts: 127.0.0.0 hosted.metmodels.com
O1 - Hosts: 127.0.0.0 www.hosted.metmodels.com
O1 - Hosts: 127.0.0.0 hosted.met-art.com
O1 - Hosts: 127.0.0.0 www.hosted.met--art.com
O1 - Hosts: 127.0.0.0 hosted.goldinaraw.com
O1 - Hosts: 127.0.0.0 www.hosted.goldinaraw.com
O1 - Hosts: 127.0.0.0 media.inthecrack.com
O1 - Hosts: 127.0.0.0 www.media.inthecrack.com
O1 - Hosts: 127.0.0.0 megateengirls.com
O1 - Hosts: 127.0.0.0 www.megateengirls.com
O1 - Hosts: 127.0.0.0 nakedanatomy.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - D:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O2 - BHO: GamePlayLabsBHO - {984A9162-8891-4D19-8CFE-17648BB4E1EC} - (no file)
O2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - (no file)
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - D:\Program Files\Delta\delta\1.8.21.5\bh\delta.dll
O2 - BHO: Search Assistant BHO - {c4b22c87-45ef-4f43-89f2-40db2078864e} - D:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll
O2 - BHO: FCTBPos00Pos - {D496B221-52BB-4DA7-B5E7-4442022F207D} - D:\Program Files\MyPlayCity Toolbar\Toolbar.dll
O2 - BHO: Toolbar BHO - {da71fd14-5f7b-46ae-b8b1-44074a38f331} - D:\PROGRA~1\MYFUNC~1\bar\1.bin\5mbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - D:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: MyPlayCity Toolbar - {648ADDE1-369B-4868-A419-0B67EBFD8F73} - D:\Program Files\MyPlayCity Toolbar\Toolbar.dll
O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O3 - Toolbar: MyFunCards - {210f1b36-3b7f-41a4-b5da-3eb87f5a56c2} - D:\Program Files\MyFunCards_5m\bar\1.bin\5mbar.dll
O3 - Toolbar: Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - D:\Program Files\Delta\delta\1.8.21.5\deltaTlbr.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ATICCC] "D:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [snp2std] D:\WINDOWS\vsnp2std.exe
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Olympus ib] "D:\Program Files\Olympus\ib\olycamdetect.exe" /Startup
O4 - HKLM\..\Run: [MDS_Menu] "D:\Program Files\Olympus\ib\MUITransfer\MUIStartMenu.exe" "D:\Program Files\Olympus\ib" UpdateWithCreateOnce "Software\OLYMPUS\ib\1.0"
O4 - HKLM\..\Run: [TkBellExe] "D:\program files\real\realplayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [HTC Sync Loader] "D:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [APSDaemon] "D:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MyFunCards Search Scope Monitor] "D:\PROGRA~1\MYFUNC~1\bar\1.bin\5msrchmn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [MyFunCards_5m Browser Plugin Loader] D:\PROGRA~1\MYFUNC~1\bar\1.bin\5mbrmon.exe
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Akamai NetSession Interface] "D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ICQ] "D:\Program Files\ICQ7M\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: YoWindow.lnk = D:\Program Files\YoWindow\yowindow.exe
O8 - Extra context menu item: &Search - http://tbedits.myfuncards.com/one-toolb ... 70903&cv=1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://D:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Download all links using BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download link using &BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint - Náhled - res://D:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint - Přidat na seznam k tisku - res://D:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint - Tisk - res://D:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint - Vysokorychlostní tisk - res://D:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://D:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://D:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: Pridať do blogu - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - D:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Pridať do blogu v programe Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - D:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - D:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - D:\Program Files\ICQ7M\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://D:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - D:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (file missing)
O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - D:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - D:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.5.0\ViProtocol.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\System32\browseui.dll
O23 - Service: ABBYY FineReader 9.0 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - D:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - D:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - D:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - D:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apache2 - Apache Software Foundation - D:\Program Files\PHP Home Edition 2\Apache2\bin\Apache.exe
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrowserDefendert - Unknown owner - D:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - D:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: MyFunCardsService (MyFunCards_5mService) - COMPANYVERS_NAME - D:\PROGRA~1\MYFUNC~1\bar\1.bin\5mbarsvc.exe
O23 - Service: MySql - Unknown owner - D:/PROGRA~1/PHPHOM~1/mysql/bin/mysqld-nt.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - D:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - d:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: RDC-Host - AQUATRA, Inc. - D:\Program Files\Remote Desktop Control 2\apc_host.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - D:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - D:\Program Files\Skype\Updater\Updater.exe
O23 - Service: vToolbarUpdater15.5.0 - Unknown owner - D:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe

--
End of file - 22046 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\Adobe Flash Player Updater.job
D:\WINDOWS\tasks\AppleSoftwareUpdate.job
D:\WINDOWS\tasks\EPUpdater.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-220523388-839522115-500Core.job
D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-220523388-839522115-500UA.job
D:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-220523388-839522115-500.job
D:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-220523388-839522115-500.job
D:\WINDOWS\tasks\ReclaimerUpdateFiles_Administrator.job
D:\WINDOWS\tasks\ReclaimerUpdateXML_Administrator.job
D:\WINDOWS\tasks\RNUpgradeHelperLogonPrompt_Administrator.job
D:\WINDOWS\tasks\User_Feed_Synchronization-{6845AAD2-5603-411A-9949-CD23FF6D99F2}.job
D:\WINDOWS\tasks\WGASetup.job

=========Mozilla firefox=========

ProfilePath - D:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\lt6989do.default

"{20a82645-c095-46ed-80e3-08825760534b}"=d:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"m3ffxtbr@mywebsearch.com"=D:\Program Files\MyWebSearch\bar\1.bin
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"=D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
"avg@toolbar"=D:\Documents and Settings\All Users\Data aplikací\AVG Secure Search\FireFoxExt\15.5.0.2
"5mffxtbr@MyFunCards_5m.com"=D:\Program Files\MyFunCards_5m\bar\1.bin


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.6.602.180 Plugin
"Path"=D:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=D:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin]
"Description"=
"Path"=D:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.5.0\\npsitesafety.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Web Player
"Path"=D:\Program Files\DivX\DivX Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0]
"Description"=DivX® Player Plugin for VOD Content
"Path"=D:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=D:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=D:\Program Files\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.13.2]
"Description"=Java™ Deployment Toolkit
"Path"=D:\WINDOWS\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=D:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=D:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709]
"Description"=WLPG Install MIME type
"Path"=D:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=D:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@MyFunCards_5m.com/Plugin]
"Description"=MyFunCards Plugin
"Path"=D:\Program Files\MyFunCards_5m\bar\1.bin\NP5mStub.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@mywebsearch.com/Plugin]
"Description"=My Web Search Plugin
"Path"=D:\Program Files\MyWebSearch\bar\1.bin\NPMyWebS.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=12.0.1.669]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=d:\program files\real\realplayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprjplug;version=12.0.1.669]
"Description"=RealJukebox Netscape Plugin
"Path"=d:\program files\real\realplayer\Netscape6\nprjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.669]
"Description"=RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In
"Path"=D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.669]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.669]
"Description"=12.0.1.669
"Path"=d:\program files\real\realplayer\Netscape6\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=D:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=D:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.4]
"Description"=VLC Multimedia Plugin
"Path"=D:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=D:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

D:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

D:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsIBitCometAgent.xpt
nsIQTScriptablePlugin.xpt
nsjsrealplayerplugin.xpt

D:\Program Files\Mozilla Firefox\plugins\
npBitCometAgent.dll

D:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

D:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\lt6989do.default\extensions\
5mffxtbr@MyFunCards_5m.com
ffxtlbr@babylon.com
ffxtlbr@delta.com
{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}

D:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\lt6989do.default\searchplugins\
askcom.xml
babylon.xml
BrowserDefender.xml
delta.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-01-03 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - D:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-10-21 414416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - D:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll [2011-04-11 767280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68F9551E-0411-48E4-9AAF-4BC42A6A46BE}]
EWPBrowseObject Class - D:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll [2006-04-18 34304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - D:\Program Files\Java\jre7\bin\ssv.dll [2013-02-09 461216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{984A9162-8891-4D19-8CFE-17648BB4E1EC}]
GamePlayLabsBHO Class

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}]
Babylon IE plugin

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-08-14 4533120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}]
delta Helper Object - D:\Program Files\Delta\delta\1.8.21.5\bh\delta.dll [2013-05-20 295832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c4b22c87-45ef-4f43-89f2-40db2078864e}]
Search Assistant BHO - D:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll [2012-07-09 66960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D496B221-52BB-4DA7-B5E7-4442022F207D}]
MyPlayCity Toolbar BHO - D:\Program Files\MyPlayCity Toolbar\Toolbar.dll [2010-09-08 1499136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{da71fd14-5f7b-46ae-b8b1-44074a38f331}]
Toolbar BHO - D:\PROGRA~1\MYFUNC~1\bar\1.bin\5mbar.dll [2012-07-09 699536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-02-09 170912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{07B18EA9-A523-4961-B6BB-170DE4475CCA}
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - D:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2006-04-18 552960]
{648ADDE1-369B-4868-A419-0B67EBFD8F73} - MyPlayCity Toolbar - D:\Program Files\MyPlayCity Toolbar\Toolbar.dll [2010-09-08 1499136]
{95B7759C-8C7F-4BF1-B163-73684A933233}
{210f1b36-3b7f-41a4-b5da-3eb87f5a56c2} - MyFunCards - D:\Program Files\MyFunCards_5m\bar\1.bin\5mbar.dll [2012-07-09 699536]
{82E1477C-B154-48D3-9891-33D83C26BCD3} - Delta Toolbar - D:\Program Files\Delta\delta\1.8.21.5\deltaTlbr.dll [2013-05-20 284056]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=D:\WINDOWS\RTHDCPL.EXE [2006-06-28 16248320]
"SkyTel"=D:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
"Alcmtr"=D:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"ATICCC"=D:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2006-01-02 45056]
"snp2std"=D:\WINDOWS\vsnp2std.exe [2006-08-09 675840]
"GrooveMonitor"=D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"Olympus ib"=D:\Program Files\Olympus\ib\olycamdetect.exe [2011-05-20 93360]
"MDS_Menu"=D:\Program Files\Olympus\ib\MUITransfer\MUIStartMenu.exe [2010-07-01 220336]
"TkBellExe"=D:\program files\real\realplayer\update\realsched.exe [2011-10-21 273528]
"HTC Sync Loader"=D:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2011-11-01 593920]
"Adobe Reader Speed Launcher"=D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2012-01-03 37296]
"Adobe ARM"=D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"APSDaemon"=D:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-02-20 59240]
"QuickTime Task"=D:\Program Files\QuickTime\QTTask.exe [2011-10-24 421888]
"iTunesHelper"=D:\Program Files\iTunes\iTunesHelper.exe [2011-12-08 421736]
"MyFunCards Search Scope Monitor"=D:\PROGRA~1\MYFUNC~1\bar\1.bin\5msrchmn.exe [2012-07-09 42552]
"MyFunCards_5m Browser Plugin Loader"=D:\PROGRA~1\MYFUNC~1\bar\1.bin\5mbrmon.exe [2012-07-09 30096]
"avgnt"=D:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2013-09-08 347192]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Google Update"=D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-06-22 136176]
"Akamai NetSession Interface"=D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Akamai\netsession_win.exe [2013-06-05 4489472]
"msnmsgr"=D:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"ICQ"=D:\Program Files\ICQ7M\ICQ.exe [2013-01-22 127040]
"Skype"=D:\Program Files\Skype\Phone\Skype.exe [2013-02-28 18642024]

D:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění
YoWindow.lnk - D:\Program Files\YoWindow\yowindow.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
D:\WINDOWS\system32\Ati2evxx.dll [2006-06-07 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\BitComet\BitComet.exe"="D:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet.exe"
"D:\WINDOWS\system32\muzapp.exe"="D:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player"
"D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"D:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="D:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"D:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="D:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"D:\Program Files\Windows Live\Messenger\msnmsgr.exe"="D:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"D:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="D:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"D:\Program Files\MyPlayCity Toolbar\TroubleShooter.exe"="D:\Program Files\MyPlayCity Toolbar\TroubleShooter.exe:*:Enabled:MyPlayCity Toolbar (Helper)"
"D:\Program Files\MyPlayCity Toolbar\ToolbarUpdate.exe"="D:\Program Files\MyPlayCity Toolbar\ToolbarUpdate.exe:*:Enabled:MyPlayCity Toolbar (Update)"
"D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe"="D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
"D:\Program Files\Opera\opera.exe"="D:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"D:\Program Files\Remote Desktop Control 2\apc_host.exe"="D:\Program Files\Remote Desktop Control 2\apc_host.exe:*:Enabled:Remote Desktop Control - Host Module"
"D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Akamai\netsession_win.exe"="D:\Documents and Settings\Administrator\Local Settings\Data aplikací\Akamai\netsession_win.exe:*:Enabled:Akamai NetSession Interface"
"D:\Program Files\Bonjour\mDNSResponder.exe"="D:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"D:\Program Files\iTunes\iTunes.exe"="D:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"D:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="D:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"D:\Program Files\Condition Zero\hl.exe"="D:\Program Files\Condition Zero\hl.exe:*:Disabled:Half-Life Launcher"
"D:\Program Files\DsNET Corp\aTube Catcher 2.0\yct.exe"="D:\Program Files\DsNET Corp\aTube Catcher 2.0\yct.exe:*:Enabled:aTube Catcher to download and convert videos."
"D:\Program Files\ICQ7M\ICQ.exe"="D:\Program Files\ICQ7M\ICQ.exe:*:Enabled:ICQ7M"
"D:\Program Files\Valve\hl.exe"="D:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"D:\Program Files\Skype\Phone\Skype.exe"="D:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"D:\Program Files\AVG\AVG2013\avgnsx.exe"="D:\Program Files\AVG\AVG2013\avgnsx.exe:*:Enabled:Webový štít"
"D:\Program Files\AVG\AVG2013\avgdiagex.exe"="D:\Program Files\AVG\AVG2013\avgdiagex.exe:*:Enabled:AVG Diagnostika 2013"
"D:\Program Files\AVG\AVG2013\avgmfapx.exe"="D:\Program Files\AVG\AVG2013\avgmfapx.exe:*:Enabled:Inštalátor produktu AVG"
"D:\Program Files\AVG\AVG2013\avgemcx.exe"="D:\Program Files\AVG\AVG2013\avgemcx.exe:*:Enabled:Všeobecná kontrola pošty"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\ICQ7.2\aolload.exe"="D:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\Windows Live\Messenger\msnmsgr.exe"="D:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"D:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="D:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"D:\Program Files\ICQ7M\ICQ.exe"="D:\Program Files\ICQ7M\ICQ.exe:*:Enabled:ICQ7M"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=i420vfw.dll
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.l3acm"=D:\WINDOWS\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.divxa32"=msaud32_divx.acm
"msacm.siren"=sirenacm.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"vidc.DIVX"=DivX.dll
"vidc.tscc"=D:\PROGRA~1\MpcStar\Codecs\tscc\tsccvid.dll
"vidc.VP60"=D:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=D:\WINDOWS\system32\vp6vfw.dll
"vidc.yv12"=yv12vfw.dll
"VIDC.FMVC"=fmcodec.dll

======List of files/folders created in the last 1 month======

2013-09-04 17:37:24 ----D---- D:\Program Files\trend micro
2013-09-04 17:37:23 ----D---- D:\rsit
2013-09-04 17:37:23 ----D---- D:\Documents and Settings\Administrator\Data aplikací\Avira
2013-09-04 17:34:21 ----D---- D:\WINDOWS\system32\NtmsData
2013-09-04 17:31:37 ----A---- D:\WINDOWS\system32\drivers\ssmdrv.sys
2013-09-04 17:31:36 ----A---- D:\WINDOWS\system32\drivers\avkmgr.sys
2013-09-04 17:31:36 ----A---- D:\WINDOWS\system32\drivers\avipbb.sys
2013-09-04 17:31:36 ----A---- D:\WINDOWS\system32\drivers\avgntflt.sys
2013-09-04 17:31:35 ----D---- D:\Program Files\Avira
2013-09-04 17:31:35 ----D---- D:\Documents and Settings\All Users\Data aplikací\Avira
2013-09-04 17:19:08 ----D---- D:\Program Files\CCleaner
2013-09-01 19:59:43 ----D---- D:\Documents and Settings\Administrator\Data aplikací\AVG
2013-09-01 19:59:13 ----D---- D:\Documents and Settings\All Users\Data aplikací\AVG
2013-09-01 19:58:57 ----SHD---- D:\Documents and Settings\All Users\Data aplikací\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-09-01 18:15:01 ----HDC---- D:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2013-08-18 22:28:58 ----D---- D:\WINDOWS\system32\MRT
2013-08-18 22:27:59 ----HDC---- D:\WINDOWS\$NtUninstallKB2850869$
2013-08-18 22:27:49 ----HDC---- D:\WINDOWS\$NtUninstallKB2859537$
2013-08-18 22:27:42 ----HDC---- D:\WINDOWS\$NtUninstallKB2863058$
2013-08-18 22:27:35 ----HDC---- D:\WINDOWS\$NtUninstallKB2849470$
2013-08-10 13:10:11 ----D---- D:\Documents and Settings\Administrator\Data aplikací\AVG2013
2013-08-10 13:07:01 ----D---- D:\Documents and Settings\Administrator\Data aplikací\TuneUp Software
2013-08-10 13:04:55 ----D---- D:\Documents and Settings\All Users\Data aplikací\AVG2013

======List of files/folders modified in the last 1 month======

2013-09-09 16:06:24 ----D---- D:\WINDOWS\Temp
2013-09-09 16:05:15 ----D---- D:\WINDOWS
2013-09-09 16:04:36 ----D---- D:\Documents and Settings\Administrator\Data aplikací\Skype
2013-09-09 16:03:51 ----D---- D:\WINDOWS\system32
2013-09-09 16:02:23 ----D---- D:\Program Files\Common Files\Akamai
2013-09-09 16:02:03 ----D---- D:\Program Files\Google
2013-09-08 17:43:46 ----A---- D:\WINDOWS\SchedLgU.Txt
2013-09-08 17:29:20 ----A---- D:\WINDOWS\NeroDigital.ini
2013-09-08 17:12:13 ----SD---- D:\WINDOWS\Tasks
2013-09-08 17:12:07 ----SHD---- D:\WINDOWS\Installer
2013-09-08 17:05:26 ----D---- D:\WINDOWS\Registration
2013-09-08 16:43:34 ----D---- D:\WINDOWS\system32\CatRoot2
2013-09-08 16:32:47 ----D---- D:\Program Files\Spybot - Search & Destroy
2013-09-04 17:37:24 ----RD---- D:\Program Files
2013-09-04 17:34:24 ----HD---- D:\WINDOWS\inf
2013-09-04 17:34:21 ----D---- D:\WINDOWS\repair
2013-09-04 17:32:12 ----D---- D:\WINDOWS\Prefetch
2013-09-04 17:31:37 ----D---- D:\WINDOWS\system32\drivers
2013-09-04 17:27:25 ----D---- D:\Program Files\DAEMON Tools Toolbar
2013-09-04 17:26:58 ----D---- D:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2013-09-04 17:26:27 ----SHD---- D:\Config.Msi
2013-09-04 17:23:56 ----D---- D:\Documents and Settings\Administrator\Data aplikací\DAEMON Tools Lite
2013-09-04 17:23:55 ----D---- D:\Documents and Settings\Administrator\Data aplikací\Media Player Classic
2013-09-04 17:23:42 ----D---- D:\WINDOWS\Minidump
2013-09-04 17:23:42 ----D---- D:\WINDOWS\Logs
2013-09-04 17:23:42 ----D---- D:\WINDOWS\Debug
2013-09-04 17:16:22 ----D---- D:\Program Files\AVG
2013-09-04 17:01:37 ----D---- D:\Documents and Settings\All Users\Data aplikací\MFAData
2013-09-01 20:00:00 ----D---- D:\WINDOWS\system32\config
2013-08-30 20:09:56 ----D---- D:\Program Files\Opera
2013-08-24 21:44:12 ----D---- D:\WINDOWS\Microsoft.NET
2013-08-24 21:43:50 ----RSD---- D:\WINDOWS\assembly
2013-08-24 21:25:36 ----D---- D:\Documents and Settings\All Users\Data aplikací\Skype
2013-08-24 21:25:27 ----RD---- D:\Program Files\Skype
2013-08-18 22:33:29 ----RSHDC---- D:\WINDOWS\system32\dllcache
2013-08-18 22:33:22 ----D---- D:\Program Files\Internet Explorer
2013-08-18 22:33:15 ----D---- D:\WINDOWS\ie8updates
2013-08-18 22:28:54 ----A---- D:\WINDOWS\system32\MRT.exe
2013-08-18 22:28:49 ----D---- D:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2013-08-18 22:26:50 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2013-08-18 22:26:26 ----D---- D:\WINDOWS\WinSxS
2013-08-14 22:03:51 ----D---- D:\WINDOWS\system32\cache
2013-08-10 13:09:41 ----HD---- D:\$AVG
2013-08-10 11:18:10 ----D---- D:\Documents and Settings\All Users\Data aplikací\BrowserDefender

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 Avglogx;AVG Logging Driver; D:\WINDOWS\system32\DRIVERS\avglogx.sys [2013-07-20 246072]
R0 nvata;nvata; D:\WINDOWS\System32\DRIVERS\nvata.sys [2006-04-24 100736]
R0 PxHelp20;PxHelp20; D:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 sptd;sptd; D:\WINDOWS\System32\Drivers\sptd.sys [2010-08-08 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; D:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 AmdK8;AMD Processor Driver; D:\WINDOWS\System32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 avgtp;avgtp; \??\D:\WINDOWS\system32\drivers\avgtpx86.sys []
R1 avipbb;avipbb; D:\WINDOWS\system32\DRIVERS\avipbb.sys [2013-09-08 136672]
R1 avkmgr;avkmgr; D:\WINDOWS\system32\DRIVERS\avkmgr.sys [2013-09-04 37352]
R1 SCDEmu;SCDEmu; D:\WINDOWS\system32\drivers\SCDEmu.sys [2007-04-09 31548]
R1 ssmdrv;ssmdrv; D:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2013-09-04 28520]
R2 avgntflt;avgntflt; D:\WINDOWS\system32\DRIVERS\avgntflt.sys [2013-09-08 88840]
R2 irda;Protokol IrDA; D:\WINDOWS\System32\DRIVERS\irda.sys [2008-04-13 88192]
R2 npf;NetGroup Packet Filter Driver; D:\WINDOWS\system32\drivers\npf.sys [2009-11-16 50704]
R3 ati2mtag;ati2mtag; D:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2006-06-07 1580544]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; D:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2010-04-12 15664]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; D:\WINDOWS\System32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Ovladač třídy standardu HID; D:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); D:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-06-28 4304384]
R3 irsir;Microsoft Serial Infrared Driver; D:\WINDOWS\System32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 LgBttPort;LGE Bluetooth TransPort; D:\WINDOWS\system32\DRIVERS\lgbtport.sys [2009-09-29 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator; D:\WINDOWS\system32\DRIVERS\lgbtbus.sys [2009-09-29 10496]
R3 LGVMODEM;LGE Virtual Modem; D:\WINDOWS\system32\DRIVERS\lgvmodem.sys [2009-09-29 12928]
R3 mouhid;Ovladač myši standardu HID; D:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; D:\WINDOWS\System32\DRIVERS\NVENETFD.sys [2006-03-22 52736]
R3 nvnetbus;NVIDIA Network Bus Enumerator; D:\WINDOWS\System32\DRIVERS\nvnetbus.sys [2006-03-22 18944]
R3 Rasirda;WAN Miniport (IrDA); D:\WINDOWS\System32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 SNP2STD;USB2.0 PC Camera (SNP2STD); D:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2006-08-11 11985920]
R3 usbaudio;Ovladač zvukové karty USB (WDM); D:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S0 AVGIDSHX;AVGIDSHX; D:\WINDOWS\system32\DRIVERS\avgidshx.sys []
S1 AVGIDSShim;AVGIDSShim; D:\WINDOWS\system32\DRIVERS\avgidsshimx.sys []
S3 ajvtbykg;ajvtbykg; D:\WINDOWS\system32\drivers\ajvtbykg.sys []
S3 CCDECODE;Dekodér Closed Caption; D:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 cpuz132;cpuz132; \??\D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys []
S3 FlashUSB;FlashUSB; D:\WINDOWS\system32\DRIVERS\FlashUSB.sys [2009-05-12 16896]
S3 GMSIPCI;GMSIPCI; \??\H:\INSTALL\GMSIPCI.SYS []
S3 hamachi;Hamachi Network Interface; D:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-09-17 25280]
S3 HTCAND32;HTC Device Driver; D:\WINDOWS\System32\Drivers\ANDROIDUSB.sys [2009-06-10 24576]
S3 htcnprot;HTC NDIS Protocol Driver; D:\WINDOWS\system32\DRIVERS\htcnprot.sys [2010-06-22 21248]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; D:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; D:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 SLIP;BDA Slip De-Framer; D:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; D:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usb_rndisx;Adaptér USB RNDIS; D:\WINDOWS\system32\DRIVERS\usb8023x.sys [2013-02-12 12928]
S3 USBAAPL;Apple Mobile USB Driver; D:\WINDOWS\System32\Drivers\usbaapl.sys [2012-02-15 43520]
S3 usbbus;LGE Mobile Composite USB Device; D:\WINDOWS\system32\DRIVERS\lgusbbus.sys [2008-11-19 13056]
S3 UsbDiag;LGE Mobile USB Serial Port; D:\WINDOWS\system32\DRIVERS\lgusbdiag.sys [2008-11-19 19968]
S3 USBModem;LGE Mobile USB Modem; D:\WINDOWS\system32\DRIVERS\lgusbmodem.sys [2008-11-19 24832]
S3 usbprint;Třída USB Printer; D:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; D:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; D:\WINDOWS\System32\Drivers\wdf01000.sys [2008-01-19 503144]
S3 WpdUsb;WpdUsb; D:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; D:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; D:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2008-10-27 759072]
R2 Akamai;Akamai NetSession Interface; D:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 AntiVirService;Avira Real-Time Protection; D:\Program Files\Avira\AntiVir Desktop\avguard.exe [2013-09-08 108088]
R2 AntiVirSchedulerService;Avira Scheduler; D:\Program Files\Avira\AntiVir Desktop\sched.exe [2013-09-08 84024]
R2 Apache2;Apache2; D:\Program Files\PHP Home Edition 2\Apache2\bin\Apache.exe [2004-06-29 20541]
R2 Apple Mobile Device;Apple Mobile Device; D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-02-27 55144]
R2 Ati HotKey Poller;Ati HotKey Poller; D:\WINDOWS\System32\Ati2evxx.exe [2006-06-07 409600]
R2 Bonjour Service;Bonjour Service; D:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 390504]
R2 BrowserDefendert;BrowserDefendert; D:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [2013-07-26 2847696]
R2 Irmon;Sledování infračerveného přenosu; D:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre7\bin\jqs.exe [2013-02-09 170912]
R2 MySql;MySql; D:/PROGRA~1/PHPHOM~1/mysql/bin/mysqld-nt.exe []
R2 PassThru Service;Internet Pass-Through Service; D:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [2011-08-12 87040]
R2 PSI_SVC_2;Protexis Licensing V2; d:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
R2 RDC-Host;RDC-Host; D:\Program Files\Remote Desktop Control 2\apc_host.exe [2010-04-09 510464]
R2 Skype C2C Service;Skype C2C Service; D:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-08-14 3291008]
R2 vToolbarUpdater15.5.0;vToolbarUpdater15.5.0; D:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [2013-08-14 1643184]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; D:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 iPod Service;iPod Service; D:\Program Files\iPod\bin\iPodService.exe [2011-12-08 821608]
S2 ATI Smart;ATI Smart; D:\WINDOWS\system32\ati2sgag.exe [2006-06-07 520192]
S2 gupdate;Služba Google Update (gupdate); D:\Program Files\Google\Update\GoogleUpdate.exe [2010-12-04 136176]
S2 MyFunCards_5mService;MyFunCardsService; D:\PROGRA~1\MYFUNC~1\bar\1.bin\5mbarsvc.exe [2012-07-09 42528]
S2 SkypeUpdate;Skype Updater; D:\Program Files\Skype\Updater\Updater.exe [2013-02-28 161384]
S3 Adobe LM Service;Adobe LM Service; D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-08-26 72704]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; D:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-12 253656]
S3 aspnet_state;ASP.NET State Service; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; d:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); D:\Program Files\Google\Update\GoogleUpdate.exe [2010-12-04 136176]
S3 gusvc;Google Software Updater; D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-06-25 194032]
S3 idsvc;Windows CardSpace; d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; D:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; D:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; D:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 AntiVirWebService;Avira Web Protection; D:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2013-09-08 815160]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

cokolad
2. Stupeň Varování
Příspěvky: 84
Registrován: 08 čer 2011 17:58

Re: preventivka

#5 Příspěvek od cokolad »

pekna zbierka..vsetkovymazat?

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2013.09.09.05

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Administrator :: STJAMI [administrátor]

9.9.2013 16:12:36
MBAM-log-2013-09-09 (19-03-39).txt

Typ: Kompletní kontrola (C:\|D:\|E:\|F:\|G:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 462592
Uplynulý čas: 2 hodin, 47 minut, 48 sekund

Nalezené procesy v paměti: 2
D:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe (PUP.Optional.PerformerSoft.A) -> 2316 -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe (PUP.Optional.PerformerSoft.A) -> 3608 -> Nebyla provedena žádná instrukce.

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 31
HKCR\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE} (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
HKCR\escort.escortIEPane.1 (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
HKCR\escort.escortIEPane (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
HKCR\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
HKCR\delta.deltaHlpr.1 (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
HKCR\delta.deltaHlpr (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> Nebyla provedena žádná instrukce.
HKCR\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8} (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
HKCR\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D} (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
HKCR\esrv.deltaESrvc.1 (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
HKCR\esrv.deltaESrvc (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
HKCR\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Nebyla provedena žádná instrukce.
HKCR\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} (PUP.Optional.Delta.A) -> Nebyla provedena žádná instrukce.
HKCR\delta.deltadskBnd.1 (PUP.Optional.Delta.A) -> Nebyla provedena žádná instrukce.
HKCR\delta.deltadskBnd (PUP.Optional.Delta.A) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Nebyla provedena žádná instrukce.
HKCR\Typelib\{4599D05A-D545-4069-BB42-5895B4EAE05B} (PUP.Optional.Delta.A) -> Nebyla provedena žádná instrukce.
HKCR\Interface\{1231839B-064E-4788-B865-465A1B5266FD} (PUP.Optional.Delta.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85} (PUP.Optional.Delta.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693} (PUP.Optional.PerformerSoft.A) -> Nebyla provedena žádná instrukce.
HKCU\Software\DataMngr (PUP.Optional.DataMngr) -> Nebyla provedena žádná instrukce.
HKCU\Software\BabSolution\Updater (PUP.Optional.Babylon.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{984A9162-8891-4D19-8CFE-17648BB4E1EC} (Spyware.GamePlayLabs) -> Nebyla provedena žádná instrukce.
HKCR\CLSID\{984A9162-8891-4D19-8CFE-17648BB4E1EC} (Spyware.GamePlayLabs) -> Nebyla provedena žádná instrukce.
HKCR\BHO.GamePlayLabsBHO.1 (Spyware.GamePlayLabs) -> Nebyla provedena žádná instrukce.
HKCR\BHO.GamePlayLabsBHO (Spyware.GamePlayLabs) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{984A9162-8891-4D19-8CFE-17648BB4E1EC} (Spyware.GamePlayLabs) -> Nebyla provedena žádná instrukce.

Nalezené hodnoty v registru: 3
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Data: Delta Toolbar -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Data: -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs|bProtectTabs (PUP.Optional.BrowserProtect.A) -> Data: http://www.delta-search.com/?babsrc=NT_ ... 2&tsp=4921 -> Nebyla provedena žádná instrukce.

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 11
D:\Documents and Settings\Administrator\Data aplikací\Babylon (PUP.Optional.Babylon.A) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1519.190 (PUP.Optional.BrowserDefender.A) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8} (PUP.Optional.BrowserDefender.A) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\BabSolution (PUP.Optional.BabSolution.A) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\BabSolution\CR (PUP.Optional.BabSolution.A) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\BabSolution\Shared (PUP.Optional.BabSolution.A) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\OpenCandy (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\OpenCandy\26458FC460B244D6B7ED7F4E6165F747 (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\OpenCandy\442AF3631A0A4326AE79BA310BF8E30D (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\OpenCandy\OpenCandy_26458FC460B244D6B7ED7F4E6165F747 (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\OpenCandy\OpenCandy_442AF3631A0A4326AE79BA310BF8E30D (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.

Nalezené soubory: 42
D:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe (PUP.Optional.PerformerSoft.A) -> Nebyla provedena žádná instrukce.
D:\Program Files\Delta\delta\1.8.21.5\bh\delta.dll (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
D:\Program Files\Delta\delta\1.8.21.5\deltasrv.exe (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
D:\Program Files\Delta\delta\1.8.21.5\deltaTlbr.dll (PUP.Optional.Delta.A) -> Nebyla provedena žádná instrukce.
C:\keygen.exe (Riskware.Tool.CK) -> Nebyla provedena žádná instrukce.
C:\YoutubeDownloaderSetup.exe (PUP.Dealio.TB) -> Nebyla provedena žádná instrukce.
C:\daemon4091-x86.exe (Adware.WhenU) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{CCB5F715-4432-420F-87AD-CC8362BF64C6}\RP244\A0044961.exe (Adware.WhenU) -> Nebyla provedena žádná instrukce.
C:\Macromedia Flash Pro 8 + Key [App][www.zonatorrent.com]\Macromedia Flash Pro 8 + Key [App][www.zonatorrent.com]\keygen.exe (Riskware.Tool.CK) -> Nebyla provedena žádná instrukce.
C:\USB\Alcohol120_1.9.6.5429_Retail_Incl_Loader\Alcohol120_1.9.6.5429_Retail_Incl_Loader\Loader\Alcohol.exe (Trojan.Agent) -> Nebyla provedena žádná instrukce.
C:\USB\ostatne\keygen.exe (Riskware.Tool.CK) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\BabSolution\Shared\BabMaint.exe (PUP.Optional.Babylon.A) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\BabSolution\Shared\BUSolution.dll (PUP.Optional.BabSolution.A) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\OpenCandy\OpenCandy_26458FC460B244D6B7ED7F4E6165F747\LatestDLMgr.exe (PUP.Optional.OpenCandy.A) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Dokumenty\Downloads\aTube_Catcher (1).exe (PUP.Optional.AskToolbar) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Dokumenty\Downloads\aTube_Catcher (2).exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Dokumenty\Downloads\aTube_Catcher (3).exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Dokumenty\Downloads\aTube_Catcher.exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Dokumenty\Downloads\weapon_closet.zip (Joke.Stressreducer) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Dokumenty\Downloads\winamp5601_full_emusic-7plus_all.exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Dokumenty\Downloads\yosetup (1).exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Dokumenty\Downloads\yosetup.exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Dokumenty\Downloads\weapon_closet\stress reducers.exe (Joke.Stressreducer) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Plocha\stare USB\regvissetupv2.exe (Rogue.FreeRegistryCleanerForVista) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\uninstall.exe (PUP.Optional.PerformerSoft.A) -> Nebyla provedena žádná instrukce.
D:\System Volume Information\_restore{D7A7EC89-DE28-48AA-98B4-53083FD91F80}\RP870\A0131764.dll (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
D:\System Volume Information\_restore{D7A7EC89-DE28-48AA-98B4-53083FD91F80}\RP870\A0131765.dll (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
D:\System Volume Information\_restore{D7A7EC89-DE28-48AA-98B4-53083FD91F80}\RP870\A0131766.dll (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
D:\System Volume Information\_restore{D7A7EC89-DE28-48AA-98B4-53083FD91F80}\RP870\A0131769.exe (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
D:\System Volume Information\_restore{D7A7EC89-DE28-48AA-98B4-53083FD91F80}\RP870\A0131767.dll (PUP.Optional.Delta) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Nebyla provedena žádná instrukce.
D:\WINDOWS\Tasks\EPUpdater.job (PUP.Optional.Babylon.A) -> Nebyla provedena žádná instrukce.
D:\WINDOWS\system32\roboot.exe (PUP.Optional.PCPerformer.A) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\All Users\Data aplikací\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.settings (PUP.Optional.BrowserDefender.A) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\BabSolution\Shared\chu.js (PUP.Optional.BabSolution.A) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\BabSolution\Shared\Delta.ico (PUP.Optional.BabSolution.A) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\BabSolution\Shared\GUninstaller.exe (PUP.Optional.BabSolution.A) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\BabSolution\Shared\SetupParams.ini (PUP.Optional.BabSolution.A) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\BabSolution\Shared\sqlite3.dll (PUP.Optional.BabSolution.A) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\OpenCandy\26458FC460B244D6B7ED7F4E6165F747\5879.ico (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\OpenCandy\26458FC460B244D6B7ED7F4E6165F747\PasswordBoxCHSTORE_p1v0.exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
D:\Documents and Settings\Administrator\Data aplikací\OpenCandy\442AF3631A0A4326AE79BA310BF8E30D\pcspeedup_oc.exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.

(konec)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: preventivka

#6 Příspěvek od Márty84 »

No fuj :arcisit:

Vsechno smazat a jelikoz je havet i v bodech obnovy, vymazte je http://forum.viry.cz/viewtopic.php?f=46&t=47040
Po restartu test zopakujte, abychom vedeli, jestli se to nevraci. Oznamte vysledek, v pripade nalezu dejte zase log



3.11. pro neaktivitu :lock: http://forum.viry.cz/viewtopic.php?f=12&t=123975
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Zamčeno