Stránka 1 z 2

Spuštěná služba" na pozadí systému - nezjištná bestie - ?

Napsal: 04 bře 2016 13:11
od Miroslav1
Zdravím,

Před 3-4 dny, jsem si stáhl programy na úpravu videa a dva, vypalovací programy.
Programů, na úpravu videí, jsem se zbavil.Ponecháno 2x vypalovací soft.Všechny programy, jsou free, volně ke stažení.
Bohužel, nějaký z těchto programů, si natáhl, prohlížeč Operu.Stahování, bylo viditelné v tray.Nešlo to zastavit.Operu, jsem poté smazal i její složky / co jsem našel /
Bohužel, teď se, při načítání antiviru do tray, objevuje i nemastná neslaná ikonka, která bohužel zmizí, po 3-4 vteřinách a já nevím, co to jako má bejt.Děsí mě to..
Je možné, se dopídit?
Měl bych, ikonku zkusit vyfotit? je to mžik :(
Snad jen..vypadá to, dle pár vteřin, jako klasická žárovka, vzhůru nohama? je to jen nástřel..
Díky.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Miroslav at 2016-03-04 12:58:40
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 380 GB (95%) free of 400 GB
Total RAM: 2047 MB (28% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:58:47, on 4.3.2016
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozila Firefox 2\firefox.exe
C:\Program Files\Mozila Firefox 2\plugin-container.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Documents and Settings\Miroslav\Plocha\RSIT.exe
C:\Program Files\trend micro\Miroslav.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Stáhnout FDM - file://D:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Stáhnout video FDM - file://D:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Stáhnout vybrané FDM - file://D:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Stáhnout vše FDM - file://D:\Program Files\Free Download Manager\dlall.htm
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 2155487940
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABE43CF2-E11C-4DDE-A279-3ABC01EEACEC}: NameServer = 212.158.128.3
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 4138 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\avast! Emergency Update.job - C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Miroslav\Data aplikací\Mozilla\Firefox\Profiles\wuvh9iy5.default-1433061227875

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "Seznam.cz"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"fdm_ffext@freedownloadmanager.org"=D:\Program Files\Free Download Manager\Firefox\Extension


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.306 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_20_0_0_306.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw_1216156.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.31.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
quickstores@quickstores.de

C:\Documents and Settings\Miroslav\Data aplikací\Mozilla\Firefox\Profiles\wuvh9iy5.default-1433061227875\extensions\
cs@dictionaries.addons.mozilla.org
facefont@mc.com
{394DCBA4-1F92-4f8e-8EC9-8D2CB90CB69B}
{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
{ea614400-e918-4741-9a97-7a972ff7c30b}

C:\Documents and Settings\Miroslav\Data aplikací\Mozilla\Firefox\Profiles\wuvh9iy5.default-1433061227875\searchplugins\
google-peklada.xml
jnpcz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-21 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-21 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-12-09 15691264]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-02-25 7431712]
""= []
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2014-05-20 15717664]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
""= []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2013-05-30 96056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeePass 2 PreLoad]
D:\Program Files\KeePass Password Safe 2\KeePass.exe [2013-04-05 1960448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2014-05-20 377288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2014-05-20 2593056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
D:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE [2013-06-07 774680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=
:\WINDOWS\syste

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoAutoUpdate"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"D:\Program Files\Steam\Steam.exe"="D:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"D:\Program Files\Steam\SteamApps\common\Tidalis\Tidalis.exe"="D:\Program Files\Steam\SteamApps\common\Tidalis\Tidalis.exe:*:Enabled:Tidalis"
"D:\Program Files\Steam\SteamApps\common\Deus Ex - Human Revolution\dxhr.exe"="D:\Program Files\Steam\SteamApps\common\Deus Ex - Human Revolution\dxhr.exe:*:Enabled:Deus Ex: Human Revolution"
"C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\USBSetup.exe"="C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\USBSetup.exe:LocalSubNet:Enabled:Instalace zařízení HP"
"D:\Program Files\Steam\SteamApps\common\left 4 dead\left4dead.exe"="D:\Program Files\Steam\SteamApps\common\left 4 dead\left4dead.exe:*:Enabled:Left 4 Dead"
"D:\Program Files\Steam\SteamApps\common\Alien Swarm\swarm.exe"="D:\Program Files\Steam\SteamApps\common\Alien Swarm\swarm.exe:*:Enabled:Alien Swarm"
"C:\Documents and Settings\Miroslav\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe"="C:\Documents and Settings\Miroslav\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
"D:\Program Files\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe"="D:\Program Files\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe:*:Enabled:Left 4 Dead 2"
"D:\Program Files\Steam\SteamApps\common\Portal 2\portal2.exe"="D:\Program Files\Steam\SteamApps\common\Portal 2\portal2.exe:*:Enabled:Portal 2"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2380\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2380\Agent.exe:*:Enabled:Battle.net Update Agent"
"D:\Program Files\Battle.net\Battle.net.exe"="D:\Program Files\Battle.net\Battle.net.exe:*:Enabled:Battle.net"
"D:\Program Files\Hearthstone\Hearthstone.exe"="D:\Program Files\Hearthstone\Hearthstone.exe:*:Enabled:Hearthstone"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2638\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2638\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2680\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2680\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2689\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2689\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2737\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2737\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2717\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2717\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2753\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2753\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2787\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2787\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2816\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2816\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2880\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2880\Agent.exe:*:Enabled:Battle.net Update Agent"
"D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\duke3d.exe"="D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\duke3d.exe:*:Enabled:Duke Nukem 3D: Megaton Edition"
"D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\build.exe"="D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\build.exe:*:Enabled:Duke Nukem 3D: Megaton Edition"
"D:\Origin\Origin.exe"="D:\Origin\Origin.exe:*:Enabled:Origin"
"D:\Program Files\Steam\bin\steamwebhelper.exe"="D:\Program Files\Steam\bin\steamwebhelper.exe:*:Enabled:Steam Web Helper"
"D:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe"="D:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe:*:Enabled:Render Manager"
"D:\Program Files\Steam\SteamApps\common\PAYDAY The Heist\payday_win32_release.exe"="D:\Program Files\Steam\SteamApps\common\PAYDAY The Heist\payday_win32_release.exe:*:Enabled:PAYDAY: The Heist"
"D:\Program Files\Steam\SteamApps\common\RWR\RWR.exe"="D:\Program Files\Steam\SteamApps\common\RWR\RWR.exe:*:Enabled:Real World Racing"
"D:\Program Files\Steam\SteamApps\common\Grand Theft Auto Vice City\gta-vc.exe"="D:\Program Files\Steam\SteamApps\common\Grand Theft Auto Vice City\gta-vc.exe:*:Enabled:Grand Theft Auto: Vice City"
"C:\Program Files\Google\Chrome\Application\chrome.exe"="C:\Program Files\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome"
"C:\Program Files\Cobian Backup 11\cbInterface.exe"="C:\Program Files\Cobian Backup 11\cbInterface.exe:*:Enabled:cbInterface"
"D:\Program Files\Steam\SteamApps\common\Faerie Solitaire\FaerieSolitaire.exe"="D:\Program Files\Steam\SteamApps\common\Faerie Solitaire\FaerieSolitaire.exe:*:Enabled:Faerie Solitaire"
"D:\Program Files\Origin Games\Bejeweled 3\Bejeweled3.exe"="D:\Program Files\Origin Games\Bejeweled 3\Bejeweled3.exe:*:Enabled:Bejeweled® 3"
"D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\dosbox\dosbox.exe"="D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\dosbox\dosbox.exe:*:Enabled:Duke Nukem 3D: Megaton Edition"
"D:\Program Files\Steam\SteamApps\common\FlatOut2\FlatOut2.exe"="D:\Program Files\Steam\SteamApps\common\FlatOut2\FlatOut2.exe:*:Enabled:FlatOut 2"
"D:\Program Files\Steam\SteamApps\common\swkotor\swkotor.exe"="D:\Program Files\Steam\SteamApps\common\swkotor\swkotor.exe:*:Enabled:Star Wars: Knights of the Old Republic"
"D:\Program Files\Muve\Muve Downloader\Launcher.exe"="D:\Program Files\Muve\Muve Downloader\Launcher.exe:*:Enabled:Muve Downloader"
"D:\Program Files\Muve\Muve Downloader\MuveDownloader.exe"="D:\Program Files\Muve\Muve Downloader\MuveDownloader.exe:*:Enabled:Muve Downloader"
"D:\Program Files\Bethesda Softworks\Fallout 3\FalloutLauncher.exe"="D:\Program Files\Bethesda Softworks\Fallout 3\FalloutLauncher.exe:*:Enabled:Fallout 3"
"D:\Program Files\Steam\SteamApps\common\Quake Live\quakelive_steam.exe"="D:\Program Files\Steam\SteamApps\common\Quake Live\quakelive_steam.exe:*:Enabled:Quake Live"
"D:\Program Files\Steam\SteamApps\common\SS2\Shock2.exe"="D:\Program Files\Steam\SteamApps\common\SS2\Shock2.exe:*:Enabled:System Shock 2"
"D:\Program Files\Steam\SteamApps\common\BridgeConstructor\BridgeConstructor.exe"="D:\Program Files\Steam\SteamApps\common\BridgeConstructor\BridgeConstructor.exe:*:Enabled:Bridge Constructor"
"D:\Program Files\Steam\SteamApps\common\Crysis\Bin32\Crysis.exe"="D:\Program Files\Steam\SteamApps\common\Crysis\Bin32\Crysis.exe:*:Enabled:Crysis"
"D:\Program Files\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_steam.exe"="D:\Program Files\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_steam.exe:*:Enabled:Don't Starve Together Beta"
"D:\Program Files\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_dedicated_server_nullrenderer.exe"="D:\Program Files\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_dedicated_server_nullrenderer.exe:*:Enabled:Don't Starve Together Dedicated Server"
"C:\Program Files\Mozila Firefox 2\firefox.exe"="C:\Program Files\Mozila Firefox 2\firefox.exe:*:Enabled:Firefox (C:\Program Files\Mozila Firefox 2)"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.mpeg"=bdmpegv.dll
"msacm.bdmpeg"=bdmpega.acm
"vidc.XVID"=xvidvfw.dll

======List of files/folders created in the last 1 month======

2016-03-04 07:17:56 ----D---- C:\WINDOWS\pss
2016-02-27 22:21:02 ----D---- C:\Documents and Settings\All Users\Data aplikací\Canneverbe Limited
2016-02-27 22:20:40 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Canneverbe Limited
2016-02-27 22:20:39 ----A---- C:\WINDOWS\system32\drivers\StarOpen.sys
2016-02-27 22:20:38 ----D---- C:\Program Files\CDBurnerXP
2016-02-27 10:33:47 ----D---- C:\Documents and Settings\All Users\Data aplikací\vsosdk
2016-02-26 22:33:03 ----A---- C:\Documents and Settings\Miroslav\Data aplikací\pcouffin.sys
2016-02-26 22:33:03 ----A---- C:\Documents and Settings\Miroslav\Data aplikací\inst.exe
2016-02-26 22:32:49 ----D---- C:\Documents and Settings\All Users\Data aplikací\VSO
2016-02-26 22:09:55 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Shortcut
2016-02-26 21:48:49 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\gtk-2.0
2016-02-26 20:41:27 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Ashampoo
2016-02-26 20:41:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\Ashampoo
2016-02-26 20:41:07 ----D---- C:\Program Files\Ashampoo
2016-02-25 21:28:05 ----A---- C:\WINDOWS\system32\aswBoot.exe
2016-02-25 21:27:37 ----A---- C:\WINDOWS\avastSS.scr
2016-02-21 17:09:24 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Media Player Classic
2016-02-21 17:08:33 ----D---- C:\Program Files\K-Lite Codec Pack
2016-02-12 20:09:18 ----D---- C:\Program Files\Mozila Firefox 2
2016-02-09 14:59:56 ----RHD---- C:\Documents and Settings\Miroslav\Data aplikací\SecuROM
2016-02-09 14:59:54 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2016-02-06 16:55:10 ----D---- C:\Program Files\OpenAL
2016-02-06 16:55:10 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2016-02-06 16:55:10 ----A---- C:\WINDOWS\system32\OpenAL32.dll

======List of files/folders modified in the last 1 month======

2016-03-04 12:58:45 ----D---- C:\Program Files\trend micro
2016-03-04 12:58:38 ----D---- C:\WINDOWS\Prefetch
2016-03-04 12:45:41 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Skype
2016-03-04 07:56:09 ----D---- C:\Program Files
2016-03-04 07:17:56 ----D---- C:\WINDOWS
2016-03-04 06:43:02 ----D---- C:\WINDOWS\system32\Lang
2016-03-04 06:42:47 ----D---- C:\WINDOWS\Temp
2016-03-04 00:25:18 ----A---- C:\WINDOWS\SchedLgU.Txt
2016-03-04 00:24:07 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Free Download Manager
2016-03-03 07:21:04 ----D---- C:\WINDOWS\system32
2016-03-02 18:30:53 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\YouTube Downloader
2016-03-02 14:40:06 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\KeePass
2016-03-02 07:41:36 ----D---- C:\WINDOWS\system32\drivers
2016-03-02 07:38:08 ----SD---- C:\WINDOWS\Tasks
2016-03-01 14:24:45 ----D---- C:\WINDOWS\system32\CatRoot2
2016-02-29 11:16:09 ----SHD---- C:\WINDOWS\Installer
2016-02-29 11:16:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2016-02-29 11:16:09 ----D---- C:\Config.Msi
2016-02-26 16:41:33 ----D---- C:\WINDOWS\system32\Restore
2016-02-25 21:33:35 ----D---- C:\WINDOWS\system32\CatRoot
2016-02-25 21:32:36 ----HD---- C:\WINDOWS\inf
2016-02-15 10:11:30 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2016-02-14 07:52:22 ----D---- C:\Program Files\Mozilla Maintenance Service
2016-02-09 14:58:32 ----D---- C:\WINDOWS\system32\LogFiles
2016-02-09 14:58:30 ----D---- C:\WINDOWS\WinSxS
2016-02-09 14:58:10 ----D---- C:\WINDOWS\system32\DirectX

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2016-02-25 58776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2016-02-25 221368]
R0 iteraid;ITERAID_Service_Install; C:\WINDOWS\system32\DRIVERS\iteraid.sys [2004-10-29 25067]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2016-02-25 64272]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2016-02-25 815792]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2016-02-25 447720]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2016-02-25 32792]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2016-02-25 91168]
R2 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2013-08-25 13120]
R3 aswStmXP;Avast StreamFilter Driver; C:\WINDOWS\system32\drivers\aswStmXP.sys [2016-02-25 187208]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2004-12-06 126720]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-12-09 4123136]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2014-05-20 12692296]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
R3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2009-07-13 91904]
S3 aswTdi;aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [2016-02-25 67088]
S3 GVCplDrv;GVCplDrv; C:\WINDOWS\system32\drivers\GVCplDrv.sys [2004-05-02 23040]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2013-01-23 18560]
S3 nmwcdc;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2013-01-23 23168]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2012-10-17 19072]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2013-01-23 8192]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-07-03 14976]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2013-08-29 26240]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2013-01-23 8192]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2009-07-13 132224]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-02-25 241760]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-02-15 269504]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2016-02-12 146888]
S3 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2014-05-20 158152]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-02-16 107848]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-02-16 107848]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2014-11-18 833728]

-----------------EOF-----------------

Re: Spuštěná služba" na pozadí systému - nezjištná bestie -

Napsal: 04 bře 2016 19:17
od Rudy
Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Spuštěná služba" na pozadí systému - nezjištná bestie -

Napsal: 04 bře 2016 19:37
od Miroslav1
# AdwCleaner v5.037 - Logfile created 04/03/2016 at 19:31:14
# Updated 28/02/2016 by Xplode
# Database : 2016-03-02.1 [Server]
# Operating system : Microsoft Windows XP Service Pack 3 (x86)
# Username : Miroslav - MIROSLAV-323C15
# Running from : C:\Documents and Settings\Miroslav\Plocha\adwcleaner_5.037.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[#] Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\mntemp
[-] Folder Deleted : C:\Documents and Settings\Miroslav\Data aplikací\Mozilla\Firefox\Profiles\wuvh9iy5.default-1433061227875\FoxTab
[-] Folder Deleted : C:\Documents and Settings\Miroslav\Data aplikací\Mozilla\Firefox\Profiles\wuvh9iy5.default-1433061227875\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
[-] Folder Deleted : C:\Documents and Settings\Miroslav\Local Settings\Data aplikací\28050
[-] Folder Deleted : C:\Documents and Settings\Miroslav\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\mnkioblodjcgkdailhejgcocjkkoochj
[-] Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\quickstores@quickstores.de

***** [ Files ] *****

[-] File Deleted : C:\Documents and Settings\Miroslav\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mnkioblodjcgkdailhejgcocjkkoochj_0.localstorage
[-] File Deleted : C:\Documents and Settings\Miroslav\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Local Extension Settings\mnkioblodjcgkdailhejgcocjkkoochj

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0DC81A74-1FBD-4EF6-82B2-DE3FA05E8233}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1B26E4A2-7F09-4365-9AB8-13E6891E42CB}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{21402197-BB5B-476C-AA1D-3FFED8ED813A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{42E8D680-A18B-4CAA-ACE0-18EA05E4A056}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{454A4044-16EC-4D64-9069-C5B8832B7B55}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4FEB1BAD-35AD-4A08-B6EC-E6D832F1ED4D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8F2B3016-17D4-447A-B207-FFA8957A834A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E66B63B0-49F8-47E3-A9BA-799287B59E87}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F8FA5B48-B7A2-4BC6-8389-9587643A4660}
[-] Key Deleted : HKCU\Software\PRODUCTSETUP

***** [ Web browsers ] *****

[-] [C:\Documents and Settings\Miroslav\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : mnkioblodjcgkdailhejgcocjkkoochj

*************************

:: "Tracing" keys removed
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [2882 bytes] - [04/03/2016 19:31:14]
C:\AdwCleaner\AdwCleaner[R0].txt - [2434 bytes] - [23/04/2015 17:07:40]
C:\AdwCleaner\AdwCleaner[R1].txt - [1670 bytes] - [22/10/2015 21:14:25]
C:\AdwCleaner\AdwCleaner[R2].txt - [1727 bytes] - [18/11/2015 20:21:02]
C:\AdwCleaner\AdwCleaner[R3].txt - [2675 bytes] - [07/01/2016 17:47:15]
C:\AdwCleaner\AdwCleaner[S0].txt - [2530 bytes] - [23/04/2015 17:10:31]
C:\AdwCleaner\AdwCleaner[S1].txt - [3196 bytes] - [04/03/2016 19:23:38]
C:\AdwCleaner\AdwCleaner[S2].txt - [3269 bytes] - [04/03/2016 19:28:49]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [3466 bytes] ##########

Neznámá ikona v tray, je stále.Objeví se, zamrká a zmizí.Stihl jsem ji nahrát..můžu doložit https://www.youtube.com/watch?v=buhcSSw ... e=youtu.be
Je to žárovka s tím křížkem.

Re: Spuštěná služba" na pozadí systému - nezjištná bestie -

Napsal: 04 bře 2016 20:37
od Rudy
Dejte nový log RSIT.

Re: Spuštěná služba" na pozadí systému - nezjištná bestie -

Napsal: 04 bře 2016 20:39
od Miroslav1
Logfile of random's system information tool 1.10 (written by random/random)
Run by Miroslav at 2016-03-04 20:39:11
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 379 GB (95%) free of 400 GB
Total RAM: 2047 MB (39% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:39:19, on 4.3.2016
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozila Firefox 2\firefox.exe
C:\Program Files\Mozila Firefox 2\plugin-container.exe
C:\Documents and Settings\Miroslav\Plocha\RSIT.exe
C:\Program Files\trend micro\Miroslav.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Stáhnout FDM - file://D:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Stáhnout video FDM - file://D:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Stáhnout vybrané FDM - file://D:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Stáhnout vše FDM - file://D:\Program Files\Free Download Manager\dlall.htm
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 2155487940
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABE43CF2-E11C-4DDE-A279-3ABC01EEACEC}: NameServer = 212.158.128.3
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 4131 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\avast! Emergency Update.job - C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Miroslav\Data aplikací\Mozilla\Firefox\Profiles\wuvh9iy5.default-1433061227875

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "Seznam.cz"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"fdm_ffext@freedownloadmanager.org"=D:\Program Files\Free Download Manager\Firefox\Extension


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.306 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_20_0_0_306.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw_1216156.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.31.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


C:\Documents and Settings\Miroslav\Data aplikací\Mozilla\Firefox\Profiles\wuvh9iy5.default-1433061227875\extensions\
cs@dictionaries.addons.mozilla.org
facefont@mc.com
{394DCBA4-1F92-4f8e-8EC9-8D2CB90CB69B}
{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
{ea614400-e918-4741-9a97-7a972ff7c30b}

C:\Documents and Settings\Miroslav\Data aplikací\Mozilla\Firefox\Profiles\wuvh9iy5.default-1433061227875\searchplugins\
google-peklada.xml
jnpcz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-21 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-21 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-12-09 15691264]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-02-25 7431712]
""= []
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2014-05-20 15717664]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
""= []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2013-05-30 96056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeePass 2 PreLoad]
D:\Program Files\KeePass Password Safe 2\KeePass.exe [2013-04-05 1960448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2014-05-20 377288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2014-05-20 2593056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
D:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE [2013-06-07 774680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=
:\WINDOWS\syste

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoAutoUpdate"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"D:\Program Files\Steam\Steam.exe"="D:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"D:\Program Files\Steam\SteamApps\common\Tidalis\Tidalis.exe"="D:\Program Files\Steam\SteamApps\common\Tidalis\Tidalis.exe:*:Enabled:Tidalis"
"D:\Program Files\Steam\SteamApps\common\Deus Ex - Human Revolution\dxhr.exe"="D:\Program Files\Steam\SteamApps\common\Deus Ex - Human Revolution\dxhr.exe:*:Enabled:Deus Ex: Human Revolution"
"C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\USBSetup.exe"="C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\USBSetup.exe:LocalSubNet:Enabled:Instalace zařízení HP"
"D:\Program Files\Steam\SteamApps\common\left 4 dead\left4dead.exe"="D:\Program Files\Steam\SteamApps\common\left 4 dead\left4dead.exe:*:Enabled:Left 4 Dead"
"D:\Program Files\Steam\SteamApps\common\Alien Swarm\swarm.exe"="D:\Program Files\Steam\SteamApps\common\Alien Swarm\swarm.exe:*:Enabled:Alien Swarm"
"C:\Documents and Settings\Miroslav\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe"="C:\Documents and Settings\Miroslav\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
"D:\Program Files\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe"="D:\Program Files\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe:*:Enabled:Left 4 Dead 2"
"D:\Program Files\Steam\SteamApps\common\Portal 2\portal2.exe"="D:\Program Files\Steam\SteamApps\common\Portal 2\portal2.exe:*:Enabled:Portal 2"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2380\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2380\Agent.exe:*:Enabled:Battle.net Update Agent"
"D:\Program Files\Battle.net\Battle.net.exe"="D:\Program Files\Battle.net\Battle.net.exe:*:Enabled:Battle.net"
"D:\Program Files\Hearthstone\Hearthstone.exe"="D:\Program Files\Hearthstone\Hearthstone.exe:*:Enabled:Hearthstone"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2638\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2638\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2680\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2680\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2689\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2689\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2737\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2737\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2717\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2717\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2753\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2753\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2787\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2787\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2816\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2816\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2880\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2880\Agent.exe:*:Enabled:Battle.net Update Agent"
"D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\duke3d.exe"="D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\duke3d.exe:*:Enabled:Duke Nukem 3D: Megaton Edition"
"D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\build.exe"="D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\build.exe:*:Enabled:Duke Nukem 3D: Megaton Edition"
"D:\Origin\Origin.exe"="D:\Origin\Origin.exe:*:Enabled:Origin"
"D:\Program Files\Steam\bin\steamwebhelper.exe"="D:\Program Files\Steam\bin\steamwebhelper.exe:*:Enabled:Steam Web Helper"
"D:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe"="D:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe:*:Enabled:Render Manager"
"D:\Program Files\Steam\SteamApps\common\PAYDAY The Heist\payday_win32_release.exe"="D:\Program Files\Steam\SteamApps\common\PAYDAY The Heist\payday_win32_release.exe:*:Enabled:PAYDAY: The Heist"
"D:\Program Files\Steam\SteamApps\common\RWR\RWR.exe"="D:\Program Files\Steam\SteamApps\common\RWR\RWR.exe:*:Enabled:Real World Racing"
"D:\Program Files\Steam\SteamApps\common\Grand Theft Auto Vice City\gta-vc.exe"="D:\Program Files\Steam\SteamApps\common\Grand Theft Auto Vice City\gta-vc.exe:*:Enabled:Grand Theft Auto: Vice City"
"C:\Program Files\Google\Chrome\Application\chrome.exe"="C:\Program Files\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome"
"C:\Program Files\Cobian Backup 11\cbInterface.exe"="C:\Program Files\Cobian Backup 11\cbInterface.exe:*:Enabled:cbInterface"
"D:\Program Files\Steam\SteamApps\common\Faerie Solitaire\FaerieSolitaire.exe"="D:\Program Files\Steam\SteamApps\common\Faerie Solitaire\FaerieSolitaire.exe:*:Enabled:Faerie Solitaire"
"D:\Program Files\Origin Games\Bejeweled 3\Bejeweled3.exe"="D:\Program Files\Origin Games\Bejeweled 3\Bejeweled3.exe:*:Enabled:Bejeweled® 3"
"D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\dosbox\dosbox.exe"="D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\dosbox\dosbox.exe:*:Enabled:Duke Nukem 3D: Megaton Edition"
"D:\Program Files\Steam\SteamApps\common\FlatOut2\FlatOut2.exe"="D:\Program Files\Steam\SteamApps\common\FlatOut2\FlatOut2.exe:*:Enabled:FlatOut 2"
"D:\Program Files\Steam\SteamApps\common\swkotor\swkotor.exe"="D:\Program Files\Steam\SteamApps\common\swkotor\swkotor.exe:*:Enabled:Star Wars: Knights of the Old Republic"
"D:\Program Files\Muve\Muve Downloader\Launcher.exe"="D:\Program Files\Muve\Muve Downloader\Launcher.exe:*:Enabled:Muve Downloader"
"D:\Program Files\Muve\Muve Downloader\MuveDownloader.exe"="D:\Program Files\Muve\Muve Downloader\MuveDownloader.exe:*:Enabled:Muve Downloader"
"D:\Program Files\Bethesda Softworks\Fallout 3\FalloutLauncher.exe"="D:\Program Files\Bethesda Softworks\Fallout 3\FalloutLauncher.exe:*:Enabled:Fallout 3"
"D:\Program Files\Steam\SteamApps\common\Quake Live\quakelive_steam.exe"="D:\Program Files\Steam\SteamApps\common\Quake Live\quakelive_steam.exe:*:Enabled:Quake Live"
"D:\Program Files\Steam\SteamApps\common\SS2\Shock2.exe"="D:\Program Files\Steam\SteamApps\common\SS2\Shock2.exe:*:Enabled:System Shock 2"
"D:\Program Files\Steam\SteamApps\common\BridgeConstructor\BridgeConstructor.exe"="D:\Program Files\Steam\SteamApps\common\BridgeConstructor\BridgeConstructor.exe:*:Enabled:Bridge Constructor"
"D:\Program Files\Steam\SteamApps\common\Crysis\Bin32\Crysis.exe"="D:\Program Files\Steam\SteamApps\common\Crysis\Bin32\Crysis.exe:*:Enabled:Crysis"
"D:\Program Files\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_steam.exe"="D:\Program Files\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_steam.exe:*:Enabled:Don't Starve Together Beta"
"D:\Program Files\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_dedicated_server_nullrenderer.exe"="D:\Program Files\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_dedicated_server_nullrenderer.exe:*:Enabled:Don't Starve Together Dedicated Server"
"C:\Program Files\Mozila Firefox 2\firefox.exe"="C:\Program Files\Mozila Firefox 2\firefox.exe:*:Enabled:Firefox (C:\Program Files\Mozila Firefox 2)"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.mpeg"=bdmpegv.dll
"msacm.bdmpeg"=bdmpega.acm
"vidc.XVID"=xvidvfw.dll

======List of files/folders created in the last 1 month======

2016-03-04 07:17:56 ----D---- C:\WINDOWS\pss
2016-02-27 22:21:02 ----D---- C:\Documents and Settings\All Users\Data aplikací\Canneverbe Limited
2016-02-27 22:20:40 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Canneverbe Limited
2016-02-27 22:20:39 ----A---- C:\WINDOWS\system32\drivers\StarOpen.sys
2016-02-27 22:20:38 ----D---- C:\Program Files\CDBurnerXP
2016-02-27 10:33:47 ----D---- C:\Documents and Settings\All Users\Data aplikací\vsosdk
2016-02-26 22:33:03 ----A---- C:\Documents and Settings\Miroslav\Data aplikací\pcouffin.sys
2016-02-26 22:33:03 ----A---- C:\Documents and Settings\Miroslav\Data aplikací\inst.exe
2016-02-26 22:32:49 ----D---- C:\Documents and Settings\All Users\Data aplikací\VSO
2016-02-26 22:09:55 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Shortcut
2016-02-26 21:48:49 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\gtk-2.0
2016-02-26 20:41:27 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Ashampoo
2016-02-26 20:41:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\Ashampoo
2016-02-26 20:41:07 ----D---- C:\Program Files\Ashampoo
2016-02-25 21:28:05 ----A---- C:\WINDOWS\system32\aswBoot.exe
2016-02-25 21:27:37 ----A---- C:\WINDOWS\avastSS.scr
2016-02-21 17:09:24 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Media Player Classic
2016-02-21 17:08:33 ----D---- C:\Program Files\K-Lite Codec Pack
2016-02-12 20:09:18 ----D---- C:\Program Files\Mozila Firefox 2
2016-02-09 14:59:56 ----RHD---- C:\Documents and Settings\Miroslav\Data aplikací\SecuROM
2016-02-09 14:59:54 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2016-02-06 16:55:10 ----D---- C:\Program Files\OpenAL
2016-02-06 16:55:10 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2016-02-06 16:55:10 ----A---- C:\WINDOWS\system32\OpenAL32.dll

======List of files/folders modified in the last 1 month======

2016-03-04 20:39:15 ----D---- C:\Program Files\trend micro
2016-03-04 20:26:49 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Skype
2016-03-04 19:56:08 ----D---- C:\Program Files
2016-03-04 19:55:18 ----D---- C:\WINDOWS\Prefetch
2016-03-04 19:34:45 ----D---- C:\WINDOWS\Temp
2016-03-04 19:34:10 ----D---- C:\WINDOWS\system32\Lang
2016-03-04 19:32:10 ----A---- C:\WINDOWS\SchedLgU.Txt
2016-03-04 19:31:15 ----D---- C:\AdwCleaner
2016-03-04 07:17:56 ----D---- C:\WINDOWS
2016-03-04 00:24:07 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Free Download Manager
2016-03-03 07:21:04 ----D---- C:\WINDOWS\system32
2016-03-02 18:30:53 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\YouTube Downloader
2016-03-02 14:40:06 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\KeePass
2016-03-02 07:41:36 ----D---- C:\WINDOWS\system32\drivers
2016-03-02 07:38:08 ----SD---- C:\WINDOWS\Tasks
2016-03-01 14:24:45 ----D---- C:\WINDOWS\system32\CatRoot2
2016-02-29 11:16:09 ----SHD---- C:\WINDOWS\Installer
2016-02-29 11:16:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2016-02-29 11:16:09 ----D---- C:\Config.Msi
2016-02-26 16:41:33 ----D---- C:\WINDOWS\system32\Restore
2016-02-25 21:33:35 ----D---- C:\WINDOWS\system32\CatRoot
2016-02-25 21:32:36 ----HD---- C:\WINDOWS\inf
2016-02-15 10:11:30 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2016-02-14 07:52:22 ----D---- C:\Program Files\Mozilla Maintenance Service
2016-02-09 14:58:32 ----D---- C:\WINDOWS\system32\LogFiles
2016-02-09 14:58:30 ----D---- C:\WINDOWS\WinSxS
2016-02-09 14:58:10 ----D---- C:\WINDOWS\system32\DirectX

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2016-02-25 58776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2016-02-25 221368]
R0 iteraid;ITERAID_Service_Install; C:\WINDOWS\system32\DRIVERS\iteraid.sys [2004-10-29 25067]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2016-02-25 64272]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2016-02-25 815792]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2016-02-25 447720]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2016-02-25 32792]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2016-02-25 91168]
R2 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2013-08-25 13120]
R3 aswStmXP;Avast StreamFilter Driver; C:\WINDOWS\system32\drivers\aswStmXP.sys [2016-02-25 187208]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2004-12-06 126720]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-12-09 4123136]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2014-05-20 12692296]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
R3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2009-07-13 91904]
S3 aswTdi;aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [2016-02-25 67088]
S3 GVCplDrv;GVCplDrv; C:\WINDOWS\system32\drivers\GVCplDrv.sys [2004-05-02 23040]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2013-01-23 18560]
S3 nmwcdc;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2013-01-23 23168]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2012-10-17 19072]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2013-01-23 8192]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-07-03 14976]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2013-08-29 26240]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2013-01-23 8192]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2009-07-13 132224]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-02-25 241760]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-02-15 269504]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2016-02-12 146888]
S3 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2014-05-20 158152]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-02-16 107848]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-02-16 107848]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2014-11-18 833728]

-----------------EOF-----------------

Re: Spuštěná služba" na pozadí systému - nezjištná bestie -

Napsal: 04 bře 2016 20:46
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"KernelFaultCheck"=-

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.

Re: Spuštěná služba" na pozadí systému - nezjištná bestie -

Napsal: 04 bře 2016 20:58
od Miroslav1
Logfile of random's system information tool 1.10 (written by random/random)
Run by Miroslav at 2016-03-04 20:54:26
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 380 GB (95%) free of 400 GB
Total RAM: 2047 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:54:30, on 4.3.2016
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Skype\Updater\Updater.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Miroslav\Plocha\RSIT.exe
C:\Program Files\trend micro\Miroslav.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Stáhnout FDM - file://D:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Stáhnout video FDM - file://D:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Stáhnout vybrané FDM - file://D:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Stáhnout vše FDM - file://D:\Program Files\Free Download Manager\dlall.htm
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 2155487940
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABE43CF2-E11C-4DDE-A279-3ABC01EEACEC}: NameServer = 212.158.128.3
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 3990 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\avast! Emergency Update.job - C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Miroslav\Data aplikací\Mozilla\Firefox\Profiles\wuvh9iy5.default-1433061227875

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "Seznam.cz"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"fdm_ffext@freedownloadmanager.org"=D:\Program Files\Free Download Manager\Firefox\Extension


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.306 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_20_0_0_306.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw_1216156.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.31.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


C:\Documents and Settings\Miroslav\Data aplikací\Mozilla\Firefox\Profiles\wuvh9iy5.default-1433061227875\extensions\
cs@dictionaries.addons.mozilla.org
facefont@mc.com
{394DCBA4-1F92-4f8e-8EC9-8D2CB90CB69B}
{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
{ea614400-e918-4741-9a97-7a972ff7c30b}

C:\Documents and Settings\Miroslav\Data aplikací\Mozilla\Firefox\Profiles\wuvh9iy5.default-1433061227875\searchplugins\
google-peklada.xml
jnpcz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-21 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-21 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-12-09 15691264]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-02-25 7431712]
""= []
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2014-05-20 15717664]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
""= []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2013-05-30 96056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeePass 2 PreLoad]
D:\Program Files\KeePass Password Safe 2\KeePass.exe [2013-04-05 1960448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2014-05-20 377288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2014-05-20 2593056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
D:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE [2013-06-07 774680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=
:\WINDOWS\syste

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoAutoUpdate"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"D:\Program Files\Steam\Steam.exe"="D:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"D:\Program Files\Steam\SteamApps\common\Tidalis\Tidalis.exe"="D:\Program Files\Steam\SteamApps\common\Tidalis\Tidalis.exe:*:Enabled:Tidalis"
"D:\Program Files\Steam\SteamApps\common\Deus Ex - Human Revolution\dxhr.exe"="D:\Program Files\Steam\SteamApps\common\Deus Ex - Human Revolution\dxhr.exe:*:Enabled:Deus Ex: Human Revolution"
"C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\USBSetup.exe"="C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\USBSetup.exe:LocalSubNet:Enabled:Instalace zařízení HP"
"D:\Program Files\Steam\SteamApps\common\left 4 dead\left4dead.exe"="D:\Program Files\Steam\SteamApps\common\left 4 dead\left4dead.exe:*:Enabled:Left 4 Dead"
"D:\Program Files\Steam\SteamApps\common\Alien Swarm\swarm.exe"="D:\Program Files\Steam\SteamApps\common\Alien Swarm\swarm.exe:*:Enabled:Alien Swarm"
"C:\Documents and Settings\Miroslav\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe"="C:\Documents and Settings\Miroslav\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
"D:\Program Files\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe"="D:\Program Files\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe:*:Enabled:Left 4 Dead 2"
"D:\Program Files\Steam\SteamApps\common\Portal 2\portal2.exe"="D:\Program Files\Steam\SteamApps\common\Portal 2\portal2.exe:*:Enabled:Portal 2"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2380\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2380\Agent.exe:*:Enabled:Battle.net Update Agent"
"D:\Program Files\Battle.net\Battle.net.exe"="D:\Program Files\Battle.net\Battle.net.exe:*:Enabled:Battle.net"
"D:\Program Files\Hearthstone\Hearthstone.exe"="D:\Program Files\Hearthstone\Hearthstone.exe:*:Enabled:Hearthstone"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2638\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2638\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2680\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2680\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2689\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2689\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2737\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2737\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2717\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2717\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2753\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.beta.2753\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2787\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2787\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2816\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2816\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2880\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.2880\Agent.exe:*:Enabled:Battle.net Update Agent"
"D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\duke3d.exe"="D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\duke3d.exe:*:Enabled:Duke Nukem 3D: Megaton Edition"
"D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\build.exe"="D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\build.exe:*:Enabled:Duke Nukem 3D: Megaton Edition"
"D:\Origin\Origin.exe"="D:\Origin\Origin.exe:*:Enabled:Origin"
"D:\Program Files\Steam\bin\steamwebhelper.exe"="D:\Program Files\Steam\bin\steamwebhelper.exe:*:Enabled:Steam Web Helper"
"D:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe"="D:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe:*:Enabled:Render Manager"
"D:\Program Files\Steam\SteamApps\common\PAYDAY The Heist\payday_win32_release.exe"="D:\Program Files\Steam\SteamApps\common\PAYDAY The Heist\payday_win32_release.exe:*:Enabled:PAYDAY: The Heist"
"D:\Program Files\Steam\SteamApps\common\RWR\RWR.exe"="D:\Program Files\Steam\SteamApps\common\RWR\RWR.exe:*:Enabled:Real World Racing"
"D:\Program Files\Steam\SteamApps\common\Grand Theft Auto Vice City\gta-vc.exe"="D:\Program Files\Steam\SteamApps\common\Grand Theft Auto Vice City\gta-vc.exe:*:Enabled:Grand Theft Auto: Vice City"
"C:\Program Files\Google\Chrome\Application\chrome.exe"="C:\Program Files\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome"
"C:\Program Files\Cobian Backup 11\cbInterface.exe"="C:\Program Files\Cobian Backup 11\cbInterface.exe:*:Enabled:cbInterface"
"D:\Program Files\Steam\SteamApps\common\Faerie Solitaire\FaerieSolitaire.exe"="D:\Program Files\Steam\SteamApps\common\Faerie Solitaire\FaerieSolitaire.exe:*:Enabled:Faerie Solitaire"
"D:\Program Files\Origin Games\Bejeweled 3\Bejeweled3.exe"="D:\Program Files\Origin Games\Bejeweled 3\Bejeweled3.exe:*:Enabled:Bejeweled® 3"
"D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\dosbox\dosbox.exe"="D:\Program Files\Steam\SteamApps\common\Duke Nukem 3D\bin\dosbox\dosbox.exe:*:Enabled:Duke Nukem 3D: Megaton Edition"
"D:\Program Files\Steam\SteamApps\common\FlatOut2\FlatOut2.exe"="D:\Program Files\Steam\SteamApps\common\FlatOut2\FlatOut2.exe:*:Enabled:FlatOut 2"
"D:\Program Files\Steam\SteamApps\common\swkotor\swkotor.exe"="D:\Program Files\Steam\SteamApps\common\swkotor\swkotor.exe:*:Enabled:Star Wars: Knights of the Old Republic"
"D:\Program Files\Muve\Muve Downloader\Launcher.exe"="D:\Program Files\Muve\Muve Downloader\Launcher.exe:*:Enabled:Muve Downloader"
"D:\Program Files\Muve\Muve Downloader\MuveDownloader.exe"="D:\Program Files\Muve\Muve Downloader\MuveDownloader.exe:*:Enabled:Muve Downloader"
"D:\Program Files\Bethesda Softworks\Fallout 3\FalloutLauncher.exe"="D:\Program Files\Bethesda Softworks\Fallout 3\FalloutLauncher.exe:*:Enabled:Fallout 3"
"D:\Program Files\Steam\SteamApps\common\Quake Live\quakelive_steam.exe"="D:\Program Files\Steam\SteamApps\common\Quake Live\quakelive_steam.exe:*:Enabled:Quake Live"
"D:\Program Files\Steam\SteamApps\common\SS2\Shock2.exe"="D:\Program Files\Steam\SteamApps\common\SS2\Shock2.exe:*:Enabled:System Shock 2"
"D:\Program Files\Steam\SteamApps\common\BridgeConstructor\BridgeConstructor.exe"="D:\Program Files\Steam\SteamApps\common\BridgeConstructor\BridgeConstructor.exe:*:Enabled:Bridge Constructor"
"D:\Program Files\Steam\SteamApps\common\Crysis\Bin32\Crysis.exe"="D:\Program Files\Steam\SteamApps\common\Crysis\Bin32\Crysis.exe:*:Enabled:Crysis"
"D:\Program Files\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_steam.exe"="D:\Program Files\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_steam.exe:*:Enabled:Don't Starve Together Beta"
"D:\Program Files\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_dedicated_server_nullrenderer.exe"="D:\Program Files\Steam\SteamApps\common\Don't Starve Together Beta\bin\dontstarve_dedicated_server_nullrenderer.exe:*:Enabled:Don't Starve Together Dedicated Server"
"C:\Program Files\Mozila Firefox 2\firefox.exe"="C:\Program Files\Mozila Firefox 2\firefox.exe:*:Enabled:Firefox (C:\Program Files\Mozila Firefox 2)"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.mpeg"=bdmpegv.dll
"msacm.bdmpeg"=bdmpega.acm
"vidc.XVID"=xvidvfw.dll

======List of files/folders created in the last 1 month======

2016-03-04 20:50:23 ----D---- C:\_OTM
2016-03-04 07:17:56 ----D---- C:\WINDOWS\pss
2016-02-27 22:21:02 ----D---- C:\Documents and Settings\All Users\Data aplikací\Canneverbe Limited
2016-02-27 22:20:40 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Canneverbe Limited
2016-02-27 22:20:39 ----A---- C:\WINDOWS\system32\drivers\StarOpen.sys
2016-02-27 22:20:38 ----D---- C:\Program Files\CDBurnerXP
2016-02-27 10:33:47 ----D---- C:\Documents and Settings\All Users\Data aplikací\vsosdk
2016-02-26 22:33:03 ----A---- C:\Documents and Settings\Miroslav\Data aplikací\pcouffin.sys
2016-02-26 22:33:03 ----A---- C:\Documents and Settings\Miroslav\Data aplikací\inst.exe
2016-02-26 22:32:49 ----D---- C:\Documents and Settings\All Users\Data aplikací\VSO
2016-02-26 22:09:55 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Shortcut
2016-02-26 21:48:49 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\gtk-2.0
2016-02-26 20:41:27 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Ashampoo
2016-02-26 20:41:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\Ashampoo
2016-02-26 20:41:07 ----D---- C:\Program Files\Ashampoo
2016-02-25 21:28:05 ----A---- C:\WINDOWS\system32\aswBoot.exe
2016-02-25 21:27:37 ----A---- C:\WINDOWS\avastSS.scr
2016-02-21 17:09:24 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Media Player Classic
2016-02-21 17:08:33 ----D---- C:\Program Files\K-Lite Codec Pack
2016-02-12 20:09:18 ----D---- C:\Program Files\Mozila Firefox 2
2016-02-09 14:59:56 ----RHD---- C:\Documents and Settings\Miroslav\Data aplikací\SecuROM
2016-02-09 14:59:54 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2016-02-06 16:55:10 ----D---- C:\Program Files\OpenAL
2016-02-06 16:55:10 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2016-02-06 16:55:10 ----A---- C:\WINDOWS\system32\OpenAL32.dll

======List of files/folders modified in the last 1 month======

2016-03-04 20:54:28 ----D---- C:\Program Files\trend micro
2016-03-04 20:54:14 ----D---- C:\WINDOWS\Prefetch
2016-03-04 20:53:55 ----D---- C:\WINDOWS\Temp
2016-03-04 20:53:54 ----D---- C:\WINDOWS\system32\Lang
2016-03-04 20:51:18 ----A---- C:\WINDOWS\SchedLgU.Txt
2016-03-04 20:26:49 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Skype
2016-03-04 19:56:08 ----D---- C:\Program Files
2016-03-04 19:31:15 ----D---- C:\AdwCleaner
2016-03-04 07:17:56 ----D---- C:\WINDOWS
2016-03-04 00:24:07 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\Free Download Manager
2016-03-03 07:21:04 ----D---- C:\WINDOWS\system32
2016-03-02 18:30:53 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\YouTube Downloader
2016-03-02 14:40:06 ----D---- C:\Documents and Settings\Miroslav\Data aplikací\KeePass
2016-03-02 07:41:36 ----D---- C:\WINDOWS\system32\drivers
2016-03-02 07:38:08 ----SD---- C:\WINDOWS\Tasks
2016-03-01 14:24:45 ----D---- C:\WINDOWS\system32\CatRoot2
2016-02-29 11:16:09 ----SHD---- C:\WINDOWS\Installer
2016-02-29 11:16:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2016-02-29 11:16:09 ----D---- C:\Config.Msi
2016-02-26 16:41:33 ----D---- C:\WINDOWS\system32\Restore
2016-02-25 21:33:35 ----D---- C:\WINDOWS\system32\CatRoot
2016-02-25 21:32:36 ----HD---- C:\WINDOWS\inf
2016-02-15 10:11:30 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2016-02-14 07:52:22 ----D---- C:\Program Files\Mozilla Maintenance Service
2016-02-09 14:58:32 ----D---- C:\WINDOWS\system32\LogFiles
2016-02-09 14:58:30 ----D---- C:\WINDOWS\WinSxS
2016-02-09 14:58:10 ----D---- C:\WINDOWS\system32\DirectX

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2016-02-25 58776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2016-02-25 221368]
R0 iteraid;ITERAID_Service_Install; C:\WINDOWS\system32\DRIVERS\iteraid.sys [2004-10-29 25067]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2016-02-25 64272]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2016-02-25 815792]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2016-02-25 447720]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2016-02-25 32792]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2016-02-25 91168]
R2 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2013-08-25 13120]
R3 aswStmXP;Avast StreamFilter Driver; C:\WINDOWS\system32\drivers\aswStmXP.sys [2016-02-25 187208]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2004-12-06 126720]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-12-09 4123136]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2014-05-20 12692296]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
R3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2009-07-13 91904]
S3 aswTdi;aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [2016-02-25 67088]
S3 GVCplDrv;GVCplDrv; C:\WINDOWS\system32\drivers\GVCplDrv.sys [2004-05-02 23040]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2013-01-23 18560]
S3 nmwcdc;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2013-01-23 23168]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2012-10-17 19072]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2013-01-23 8192]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-07-03 14976]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2013-08-29 26240]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2013-01-23 8192]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2009-07-13 132224]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-02-25 241760]
R2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-07-09 327296]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-02-15 269504]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2016-02-12 146888]
S3 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2014-05-20 158152]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-02-16 107848]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-02-16 107848]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2014-11-18 833728]

-----------------EOF-----------------
Wow, tak satan, hoří v pekle :lol:
Co to bylo? či, sám nevíte? nějaký balast?
Vřele, díky.Klaním se. :idea:

Re: Spuštěná služba" na pozadí systému - nezjištná bestie -

Napsal: 04 bře 2016 21:48
od Rudy
Trojáky a AdWary. RSIT dočistil už jen zbytečnosti. Nemáte zač! :)

Re: Spuštěná služba" na pozadí systému - nezjištná bestie -

Napsal: 05 bře 2016 08:36
od Miroslav1
Rudy, tak jsem zpět.Ta potvora, je zpátky.. :roll:
Je to možný?..
Neměl bych, smazat ty vypalovací softy?

Re: Spuštěná služba" na pozadí systému - nezjištná bestie -

Napsal: 05 bře 2016 11:26
od Rudy
Zkuste to a pro jistotu udělejte kompletní sken MBAM: http://filehippo.com/download_malwareby ... are/14815/ a dejte log. Předem nic nemažte. Nabítku na stažení nové verze programu ignorujte, na XP neběží.

Re: Spuštěná služba" na pozadí systému - nezjištná bestie -

Napsal: 05 bře 2016 13:11
od Miroslav1
Malwarebytes Anti-Malware 1.75.0.1300
http://www.malwarebytes.org

Verze: v2013.04.04.07

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Miroslav :: MIROSLAV-323C15 [administrátor]

5.3.2016 11:35:43
mbam-log-2016-03-05 (11-35-43).txt

Typ: Kompletní kontrola (C:\|D:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 365289
Uplynulý čas: 1 hodin, 33 minut, 41 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Nevím, ale asi to bude, nějaký zbytek..?
PC, nevykazuje nějakou zátěž..
Neskáčou, nikde žádný okna, nic se neděje, co by mělo upoutat pozornost.
Chtěl bych, na to ale přijít, co to je zač.. :(
Hlavně, aby to nebralo, přihlašovací údaje do banky a na servery

Re: Spuštěná služba" na pozadí systému - nezjištná bestie -

Napsal: 05 bře 2016 17:17
od Rudy
Toto je OK. Jak se ta služba jmenuje?

Re: Spuštěná služba" na pozadí systému - nezjištná bestie -

Napsal: 05 bře 2016 17:32
od Miroslav1
Tak se mě povedlo, po restartu zjistit, co je to za ikonku / službu. :lol:
Je to Avast Secure line VPN.Mám otevřené okno avastu a je tam nabídka, začít a přeskočit, tutorial.Musím se toho zbavit .. :roll:

Re: Spuštěná služba" na pozadí systému - nezjištná bestie -

Napsal: 05 bře 2016 17:34
od Rudy
To je utilita antiviru: https://www.avast.com/cs-cz/secureline-vpn#pc . Můžete si ji ponechat, nebo odinstalovat. Osobně toto nepoužívám.

Re: Spuštěná služba" na pozadí systému - nezjištná bestie -

Napsal: 05 bře 2016 18:23
od Miroslav1
A je na to, nějaký soft? či jsem nenašel, jak to odstarnit.Akorát, to jde vypnout..