ComboFix 10-01-11.04 - pepa 12.01.2010 17:50:45.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7100.0.1250.420.1033.18.768.101 [GMT 1:00]
Spuštěný z: c:\users\pepa\Desktop\ComboFix.exe
SP: Spyware Terminator *disabled* (Updated) {55EE49A8-16BE-4601-BBE6-607B7F7317DE}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2942910762-2898075542-3732425671-1001
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-12-12 do 2010-01-12 )))))))))))))))))))))))))))))))
.
2010-01-12 16:59 . 2010-01-12 16:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-12 16:49 . 2010-01-12 16:49 -------- d-----w- C:\32788R22FWJFW
2010-01-12 12:39 . 2010-01-12 16:48 -------- d-----w- c:\users\pepa\AppData\Roaming\Tor
2010-01-12 12:39 . 2010-01-12 16:48 -------- d-----w- c:\users\pepa\AppData\Roaming\Vidalia
2010-01-12 12:39 . 2010-01-12 12:40 -------- d-----w- c:\program files\Vidalia Bundle
2010-01-12 12:18 . 2010-01-12 12:18 -------- d-----w- c:\program files\WinPcap
2010-01-10 19:41 . 2010-01-10 19:41 -------- d-----w- c:\users\pepa\DoctorWeb
2010-01-10 18:41 . 2010-01-10 18:57 -------- d-----w- c:\programdata\SysMon
2010-01-10 17:21 . 2010-01-10 17:34 -------- d-----w- c:\program files\AntiFirewall
2010-01-10 17:13 . 2010-01-11 19:44 -------- d-----w- c:\program files\Active Data Recovery Software
2010-01-10 16:59 . 2010-01-10 16:59 -------- d-----w- c:\users\pepa\AppData\Local\Stardock
2010-01-10 12:24 . 2010-01-10 12:26 -------- d-----w- c:\program files\Yahoo!
2010-01-09 17:37 . 2010-01-09 17:37 -------- d-----w- c:\program files\CCleaner
2010-01-04 12:58 . 2010-01-04 12:58 -------- d-----w- c:\windows\system32\RTCOM
2010-01-02 18:18 . 2010-01-02 18:18 -------- d-----w- c:\program files\Sierra
2010-01-02 12:12 . 2010-01-02 12:12 290816 ----a-w- c:\users\pepa\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_4.dll
2010-01-02 12:12 . 2010-01-02 12:12 290816 ----a-w- c:\users\pepa\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_3.dll
2010-01-02 12:12 . 2010-01-02 12:12 290816 ----a-w- c:\users\pepa\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_2.dll
2010-01-02 12:12 . 2010-01-02 12:12 290816 ----a-w- c:\users\pepa\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_1.dll
2010-01-01 18:49 . 2010-01-02 12:13 -------- d-----w- c:\program files\SystemRequirementsLab
2010-01-01 18:49 . 2010-01-02 12:13 -------- d-----w- c:\users\pepa\AppData\Roaming\SystemRequirementsLab
2010-01-01 18:49 . 2010-01-01 18:49 138240 ----a-w- c:\users\pepa\AppData\Roaming\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_d.dll
2010-01-01 18:49 . 2010-01-01 18:49 138240 ----a-w- c:\users\pepa\AppData\Roaming\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_c.dll
2010-01-01 18:49 . 2010-01-01 18:49 138240 ----a-w- c:\users\pepa\AppData\Roaming\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_b.dll
2010-01-01 18:49 . 2010-01-01 18:49 138240 ----a-w- c:\users\pepa\AppData\Roaming\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_a.dll
2009-12-28 17:13 . 2009-12-28 17:13 6144 ----a-w- c:\programdata\Spyware Terminator\sp_rsdel.exe
2009-12-28 17:13 . 2009-12-28 17:13 5632 ----a-w- c:\programdata\Spyware Terminator\fileobjinfo.sys
2009-12-28 17:13 . 2009-12-28 17:13 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2009-12-28 17:13 . 2010-01-11 19:37 -------- d-----w- c:\users\pepa\AppData\Roaming\Spyware Terminator
2009-12-28 17:13 . 2010-01-12 11:14 -------- d-----w- c:\programdata\Spyware Terminator
2009-12-28 17:13 . 2010-01-11 19:43 -------- d-----w- c:\program files\Spyware Terminator
2009-12-26 22:28 . 2009-12-26 22:28 -------- d-----w- c:\program files\Ask.com
2009-12-26 22:26 . 2009-12-26 22:26 -------- d-----w- c:\program files\The KMPlayer
2009-12-26 12:06 . 2009-12-26 12:06 -------- d-----w- c:\program files\Softnik Technologies
2009-12-26 12:04 . 2009-12-26 12:04 -------- d-----w- c:\users\pepa\AppData\Local\Shawn_Rakowski
2009-12-26 12:03 . 2009-12-26 12:03 -------- d-----w- c:\program files\KeyTracker
2009-12-24 19:55 . 2009-12-24 19:55 -------- d-----w- c:\program files\RivaTuner v2.24
2009-12-24 18:57 . 2009-12-24 18:57 -------- d-----w- c:\program files\GameTop.com
2009-12-24 18:29 . 2009-12-24 18:29 2238 ----a-r- c:\users\pepa\AppData\Roaming\Microsoft\Installer\{B797E40F-E96C-4929-AA1B-D6759C10DEC8}\_1e7476e8.exe
2009-12-24 18:29 . 2009-12-24 18:29 2238 ----a-r- c:\users\pepa\AppData\Roaming\Microsoft\Installer\{B797E40F-E96C-4929-AA1B-D6759C10DEC8}\_1615c26.exe
2009-12-24 18:29 . 2009-12-24 18:29 -------- d-----w- c:\program files\ICQ FORCE
2009-12-24 14:55 . 2009-12-24 14:55 467120 ----a-w- c:\programdata\Microsoft\Windows Defender\LocalCopy\{EB5874A0-979C-45F2-7460-67400CE1587A}-AstroburnLite.exe
2009-12-24 14:44 . 2009-12-24 14:44 -------- d-----w- c:\program files\AstroburnBar
2009-12-24 14:44 . 2009-12-24 14:45 -------- d-----w- c:\program files\Astroburn Lite
2009-12-24 14:44 . 2009-12-24 14:44 -------- d-----w- c:\users\pepa\AppData\Roaming\Astroburn Lite
2009-12-24 14:44 . 2009-12-24 15:32 -------- d-----w- c:\programdata\Astroburn Lite
2009-12-24 13:18 . 2009-12-24 15:35 -------- d-----w- c:\program files\Seznam.cz
2009-12-23 10:42 . 2009-12-23 10:42 -------- d-----w- c:\users\pepa\AppData\Roaming\Nero
2009-12-23 10:34 . 2009-12-23 10:34 -------- d-----w- c:\program files\Nero
2009-12-23 10:34 . 2009-12-23 10:34 -------- d-----w- c:\programdata\Nero
2009-12-23 10:34 . 2009-12-23 10:35 -------- d-----w- c:\program files\Common Files\Nero
2009-12-22 17:36 . 2009-12-22 17:36 -------- d-----w- c:\program files\Kodek CZ
2009-12-22 13:49 . 2009-12-22 13:49 -------- d-----w- c:\program files\Mystik Media
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-12 16:57 . 2009-11-30 21:02 -------- d-----w- c:\users\pepa\AppData\Roaming\Free Download Manager
2010-01-12 16:48 . 2009-11-30 21:02 -------- d-----w- c:\users\pepa\AppData\Roaming\Software Informer
2010-01-12 16:48 . 2009-09-30 08:15 -------- d-----w- c:\programdata\NVIDIA
2010-01-12 14:56 . 2009-09-23 12:00 -------- d-----w- c:\users\pepa\AppData\Roaming\ICQ
2010-01-11 22:04 . 2009-09-14 15:50 622022 ----a-w- c:\windows\system32\perfh005.dat
2010-01-11 22:04 . 2009-09-14 15:50 118356 ----a-w- c:\windows\system32\perfc005.dat
2010-01-10 19:46 . 2009-11-08 11:34 -------- d-----w- c:\program files\Rockstar Games
2010-01-10 12:28 . 2009-11-26 20:52 -------- d-----w- c:\program files\BS_Player
2010-01-08 17:19 . 2009-11-15 12:04 -------- d-----w- c:\program files\Lavalys
2010-01-07 12:39 . 2009-09-30 08:21 -------- d-----w- c:\program files\Alien IP
2010-01-04 12:59 . 2010-01-04 12:57 -------- d--h--w- c:\program files\Temp
2009-12-02 17:36 . 2009-09-15 09:35 109216 ----a-w- c:\users\pepa\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-01 04:30 . 2009-11-27 07:17 -------- d-----w- c:\program files\Common Files\Ulead Systems
2009-12-01 04:30 . 2009-11-26 07:46 -------- d-----w- c:\program files\NOS
2009-12-01 04:30 . 2009-11-27 07:17 -------- d-----w- c:\programdata\Ulead Systems
2009-12-01 04:30 . 2009-11-27 16:40 -------- d-----w- c:\users\pepa\AppData\Roaming\Ulead Systems
2009-11-30 21:02 . 2009-11-30 21:02 -------- d-----w- c:\program files\Free Download Manager
2009-11-30 21:02 . 2009-11-30 21:02 -------- d-----w- c:\program files\Software Informer
2009-11-30 21:02 . 2009-11-30 21:02 -------- d-----w- c:\programdata\FreeDownloadManager.ORG
2009-11-30 20:54 . 2009-11-30 20:54 -------- d-----w- c:\program files\usd
2009-11-30 19:31 . 2009-11-26 07:46 -------- d-----w- c:\programdata\NOS
2009-11-27 07:19 . 2009-11-27 07:19 -------- d-----w- c:\programdata\InterVideo
2009-11-27 07:14 . 2009-11-27 07:14 -------- d-----w- c:\program files\Corel
2009-11-26 21:36 . 2009-11-26 20:52 -------- d-----w- c:\users\pepa\AppData\Roaming\BSplayer
2009-11-26 20:52 . 2009-11-26 20:52 -------- d-----w- c:\users\pepa\AppData\Roaming\BSplayer Pro
2009-11-26 20:45 . 2009-11-26 20:41 -------- d-----w- c:\program files\AVI ReComp
2009-11-26 20:45 . 2009-11-26 20:45 -------- d-----w- c:\program files\Gabest
2009-11-26 20:45 . 2009-11-26 20:45 -------- d-----w- c:\program files\Xvid
2009-11-26 20:44 . 2009-11-26 20:44 -------- d-----w- c:\program files\AviSynth 2.5
2009-11-26 20:36 . 2009-11-26 20:36 -------- d-----w- c:\program files\Codec Pack - All In 1
2009-11-26 20:35 . 2009-11-26 20:36 737280 ----a-w- c:\windows\iun6002.exe
2009-11-24 16:40 . 2010-01-04 12:57 838176 ----a-w- c:\windows\RtlExUpd.dll
2009-11-24 08:55 . 2010-01-04 12:57 345328 ----a-w- c:\windows\system32\SRSTSXT.dll
2009-11-24 08:55 . 2010-01-04 12:57 185584 ----a-w- c:\windows\system32\SRSTSHD.dll
2009-11-24 08:55 . 2010-01-04 12:57 173296 ----a-w- c:\windows\system32\SRSHP360.dll
2009-11-24 08:55 . 2010-01-04 12:57 140528 ----a-w- c:\windows\system32\SRSWOW.dll
2009-11-24 02:05 . 2009-11-22 12:39 -------- d-----w- c:\program files\Microsoft Works
2009-11-23 10:44 . 2009-09-21 15:24 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-11-23 10:42 . 2009-10-18 09:39 -------- d-----w- c:\users\pepa\AppData\Roaming\DivX
2009-11-23 10:38 . 2009-11-23 10:38 -------- d-----w- c:\users\pepa\AppData\Roaming\AVS4YOU
2009-11-23 10:38 . 2009-11-23 10:38 -------- d-----w- c:\programdata\AVS4YOU
2009-11-23 10:38 . 2009-11-23 10:36 -------- d-----w- c:\program files\AVS4YOU
2009-11-23 10:37 . 2009-11-23 10:37 -------- d-----w- c:\program files\Common Files\AVSMedia
2009-11-23 10:23 . 2009-10-18 09:33 -------- d-----w- c:\program files\DivX
2009-11-23 09:21 . 2009-11-23 09:21 -------- d-----w- c:\program files\MP4 Converter
2009-11-22 12:38 . 2009-04-22 08:55 -------- d-----w- c:\program files\MSBuild
2009-11-22 12:36 . 2009-11-22 12:36 -------- d-----w- c:\program files\Microsoft.NET
2009-11-22 12:34 . 2009-11-22 12:34 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-11-19 21:31 . 2009-11-19 18:59 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-19 09:05 . 2009-11-08 08:17 -------- d-----w- c:\users\pepa\AppData\Roaming\TeamViewer
2009-11-19 08:47 . 2009-11-19 08:47 -------- d-----w- c:\program files\TeamViewer3
2009-11-18 17:42 . 2010-01-04 12:57 1783056 ----a-w- c:\windows\system32\WavesLib.dll
2009-11-18 17:42 . 2010-01-04 12:57 311568 ----a-w- c:\windows\system32\MaxxAudioAPO20.dll
2009-11-18 17:42 . 2010-01-04 12:57 1938704 ----a-w- c:\windows\system32\MaxxAudioEQ.dll
2009-11-18 07:34 . 2009-11-18 07:34 -------- d-----w- c:\program files\Team JPN
2009-11-17 17:13 . 2010-01-04 12:57 96160 ----a-w- c:\windows\system32\AERTARen.dll
2009-11-17 17:10 . 2010-01-04 12:57 146336 ----a-w- c:\windows\system32\AERTACap.dll
2009-11-17 13:12 . 2009-11-17 13:12 905216 ----a-w- c:\programdata\SysMon\ASK_KILL.exe
2009-11-17 05:20 . 2009-11-17 05:20 -------- d-----w- c:\programdata\McAfee
2009-11-16 22:01 . 2009-11-16 17:11 -------- d-----w- c:\users\pepa\AppData\Roaming\DAEMON Tools Lite
2009-11-16 17:22 . 2009-11-16 17:11 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-11-16 17:21 . 2009-09-16 11:56 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-11-16 17:11 . 2009-11-16 17:11 -------- d-----w- c:\programdata\DAEMON Tools Lite
2009-11-15 21:55 . 2009-11-15 21:55 -------- d--h--r- c:\users\pepa\AppData\Roaming\SecuROM
2009-11-15 13:13 . 2009-11-15 13:12 -------- d-----w- c:\program files\Dzuso
2009-11-15 05:19 . 2009-11-15 05:19 -------- d-----w- c:\programdata\McAfee Security Scan
2009-11-13 14:16 . 2010-01-04 12:57 73216 ----a-w- c:\windows\system32\RTEEL32A.dll
2009-11-13 14:16 . 2010-01-04 12:57 59392 ----a-w- c:\windows\system32\RTEEG32A.dll
2009-11-13 14:16 . 2010-01-04 12:57 348160 ----a-w- c:\windows\system32\RTEEP32A.dll
2009-11-13 14:16 . 2010-01-04 12:57 165376 ----a-w- c:\windows\system32\RTEED32A.dll
2009-11-11 15:18 . 2009-11-11 15:18 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2009-11-11 15:18 . 2009-11-11 15:18 515832 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2009-11-07 09:56 . 2009-11-07 09:56 61440 ----a-w- c:\windows\system32\pwlshell.dll
2009-11-06 08:20 . 2009-11-26 07:46 34112 ----a-w- c:\users\pepa\AppData\Roaming\Mozilla\Firefox\Profiles\0oeq67pi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-11-06 08:20 . 2009-11-26 07:46 32448 ----a-w- c:\users\pepa\AppData\Roaming\Mozilla\Firefox\Profiles\0oeq67pi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-11-06 08:20 . 2009-11-26 07:46 22352 ----a-w- c:\users\pepa\AppData\Roaming\Mozilla\Firefox\Profiles\0oeq67pi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-11-03 20:22 . 2009-11-03 20:22 87552 ----a-w- c:\users\pepa\AppData\Local\bootinst.exe
2009-11-02 19:42 . 2009-11-10 20:15 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-30 11:10 . 2009-10-30 11:10 1183176 ----a-w- c:\users\pepa\AppData\Roaming\Mozilla\Firefox\Profiles\0oeq67pi.default\extensions\
DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
2009-10-19 05:40 . 2009-10-19 05:40 6576 ------w- C:\bootsqm.dat
2009-10-16 08:51 . 2009-10-11 10:24 48 --sh--w- c:\windows\SE64C37CD.tmp
2009-03-27 04:24 . 2009-04-22 05:58 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-04-22 05:19 . 2009-04-22 03:40 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7100.0_none_624b25e9a4cb0444\WinMail.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "c:\program files\free-downloads.net\tbfree.dll" [2009-03-10 2079256]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\tbBS_1.dll" [2010-01-10 2166296]
"{E802027B-1F2B-40BD-B307-0BD96D036835}"= "c:\program files\AstroburnBar\tbAstr.dll" [2009-11-09 2331672]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
[HKEY_CLASSES_ROOT\clsid\{e802027b-1f2b-40bd-b307-0bd96d036835}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-07-10 16:28 1174920 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e802027b-1f2b-40bd-b307-0bd96d036835}]
2009-11-09 17:38 2331672 ----a-w- c:\program files\AstroburnBar\tbAstr.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
2009-03-10 09:47 2079256 ----a-w- c:\program files\free-downloads.net\tbfree.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2010-01-10 12:28 2166296 ----a-w- c:\program files\BS_Player\tbBS_1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfree.dll" [2009-03-10 2079256]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_1.dll" [2010-01-10 2166296]
"{e802027b-1f2b-40bd-b307-0bd96d036835}"= "c:\program files\AstroburnBar\tbAstr.dll" [2009-11-09 2331672]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
[HKEY_CLASSES_ROOT\clsid\{e802027b-1f2b-40bd-b307-0bd96d036835}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "c:\program files\free-downloads.net\tbfree.dll" [2009-03-10 2079256]
"{E802027B-1F2B-40BD-B307-0BD96D036835}"= "c:\program files\AstroburnBar\tbAstr.dll" [2009-11-09 2331672]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\tbBS_1.dll" [2010-01-10 2166296]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CLASSES_ROOT\clsid\{e802027b-1f2b-40bd-b307-0bd96d036835}]
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SharingPrivate]
@="{08244EE6-92F0-47f2-9FC9-929BAA2E7235}"
[HKEY_CLASSES_ROOT\CLSID\{08244EE6-92F0-47f2-9FC9-929BAA2E7235}]
2009-04-22 05:21 441856 ----a-w- c:\windows\System32\ntshrui.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-22 1174016]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2009-01-02 3399727]
"Software Informer"="c:\program files\Software Informer\softinfo.exe" [2009-01-01 1654853]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2009-12-28 3037696]
"Vidalia"="c:\program files\Vidalia Bundle\Vidalia\vidalia.exe" [2009-11-20 5262834]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-12-28 2166784]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-12-10 8120864]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
UberIcon Manager.lnk - c:\program files\WinMatrix\Matrix Skin Pack\UberIcon\UberIcon Manager.exe [2009-11-8 151552]
YzShadow.lnk - c:\program files\WinMatrix\Matrix Skin Pack\YzShadow\YzShadow.exe [2009-11-8 139264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" silent
"ares"="c:\program files\Ares\Ares.exe" -h
"uTorrent"="c:\program files\uTorrent\uTorrent.exe"
"Seznam Postak"="c:\program files\Seznam.cz\postak.exe" -s
R0 amdxata;amdxata;c:\windows\System32\drivers\amdxata.sys [22.4.2009 3:07 23120]
R0 CLFS;Systém souborů CLFS;c:\windows\System32\clfs.sys [22.4.2009 4:08 249424]
R0 CNG;CNG;c:\windows\System32\drivers\cng.sys [22.4.2009 4:31 369056]
R0 FileInfo;File Information FS MiniFilter;c:\windows\System32\drivers\fileinfo.sys [22.4.2009 4:19 58448]
R0 fvevol;Ovladač filtru nástroje Bitlocker Drive Encryption;c:\windows\System32\drivers\fvevol.sys [22.4.2009 4:10 194488]
R0 hwpolicy;Hardware Policy Driver;c:\windows\System32\drivers\hwpolicy.sys [22.4.2009 4:08 13904]
R0 KSecPkg;KSecPkg;c:\windows\System32\drivers\ksecpkg.sys [22.4.2009 4:32 133200]
R0 msisadrv;msisadrv;c:\windows\System32\drivers\msisadrv.sys [22.4.2009 4:08 13904]
R0 nvstor;nvstor;c:\windows\System32\drivers\nvstor.sys [15.4.2009 3:30 142416]
R0 pcw;Performance Counters for Windows Driver;c:\windows\System32\drivers\pcw.sys [22.4.2009 4:08 42576]
R0 rdyboost;ReadyBoost;c:\windows\System32\drivers\rdyboost.sys [22.4.2009 4:19 173648]
R0 spldr;Security Processor Loader Driver;c:\windows\System32\drivers\spldr.sys [22.4.2009 1:36 17488]
R0 storflt;Diskový ovladač filtru akcelerace sběrnice virtuálního počítače;c:\windows\System32\drivers\vmstorfl.sys [22.4.2009 11:23 40912]
R0 vdrvroot;Microsoft Virtual Drive Enumerator Driver;c:\windows\System32\drivers\vdrvroot.sys [22.4.2009 4:44 32848]
R0 volmgr;Volume Manager Driver;c:\windows\System32\drivers\volmgr.sys [22.4.2009 4:08 52304]
R0 volmgrx;Správce dynamických svazků;c:\windows\System32\drivers\volmgrx.sys [22.4.2009 4:09 297040]
R1 blbdrive;blbdrive;c:\windows\System32\drivers\blbdrive.sys [22.4.2009 4:20 35328]
R1 CSC;Ovladač souborů pro režim offline;c:\windows\System32\drivers\csc.sys [22.4.2009 4:12 387584]
R1 DfsC;DFS Namespace Client Driver;c:\windows\System32\drivers\dfsc.sys [22.4.2009 4:11 78336]
R1 discache;System Attribute Cache;c:\windows\System32\drivers\discache.sys [22.4.2009 4:21 32768]
R1 nsiproxy;NSI proxy service driver.;c:\windows\System32\drivers\nsiproxy.sys [22.4.2009 4:09 16896]
R1 RDPENCDD;RDP Encoder Mirror Driver;c:\windows\System32\drivers\RDPENCDD.sys [22.4.2009 5:00 6656]
R1 RDPREFMP;Reflector Display Driver used to gain access to graphics data;c:\windows\System32\drivers\RDPREFMP.sys [22.4.2009 5:00 7168]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\System32\drivers\sp_rsdrv2.sys [28.12.2009 18:13 142592]
R1 tdx;Ovladač pro podporu zastaralého rozhraní TDI NetIO;c:\windows\System32\drivers\tdx.sys [22.4.2009 4:09 74240]
R1 VBoxDrv;VirtualBox Service;c:\windows\System32\drivers\VBoxDrv.sys [16.9.2009 11:21 115856]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\System32\drivers\VBoxUSBMon.sys [16.9.2009 11:21 41424]
R1 Wanarpv6;Ovladač pro vzdálený přístup IPv6 ARP;c:\windows\System32\drivers\wanarp.sys [22.4.2009 4:53 63488]
R1 WfpLwf;WFP Lightweight Filter;c:\windows\System32\drivers\wfplwf.sys [22.4.2009 4:52 9728]
R2 AudioEndpointBuilder;Koncové vytváření služby Windows Audio;c:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted [22.4.2009 4:16 20992]
R2 BFE;Služba BFE (Base Filtering Engine);c:\windows\system32\svchost.exe -k LocalServiceNoNetwork [22.4.2009 4:16 20992]
R2 CscService;Soubory offline;c:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted [22.4.2009 4:16 20992]
R2 DPS;Služba DPS (Diagnostic Policy Service);c:\windows\System32\svchost.exe -k LocalServiceNoNetwork [22.4.2009 4:16 20992]
R2 FDResPub;Publikování prostředků rozpoznávání funkcí;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [22.4.2009 4:16 20992]
R2 gpsvc;Klient zásad skupiny;c:\windows\system32\svchost.exe -k netsvcs [22.4.2009 4:16 20992]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [23.9.2009 14:30 222968]
R2 iphlpsvc;Pomocná služba protokolu IP;c:\windows\System32\svchost.exe -k NetSvcs [22.4.2009 4:16 20992]
R2 lltdio;Link-Layer Topology Discovery Mapper I/O Driver;c:\windows\System32\drivers\lltdio.sys [22.4.2009 4:51 48128]
R2 luafv;Virtualizace souborů nástroje Řízení uživatelských účtů;c:\windows\System32\drivers\luafv.sys [22.4.2009 4:13 86528]
R2 MpsSvc;Brána Windows Firewall;c:\windows\system32\svchost.exe -k LocalServiceNoNetwork [22.4.2009 4:16 20992]
R2 NlaSvc;Sledování umístění v síti (NLA);c:\windows\System32\svchost.exe -k NetworkService [22.4.2009 4:16 20992]
R2 nsi;Služba rozhraní síťového úložiště;c:\windows\system32\svchost.exe -k LocalService [22.4.2009 4:16 20992]
R2 PEAUTH;PEAUTH;c:\windows\System32\drivers\PEAuth.sys [22.4.2009 4:33 586752]
R2 Power;Napájení;c:\windows\system32\svchost.exe -k DcomLaunch [22.4.2009 4:16 20992]
R2 ProfSvc;Služba Profil uživatele;c:\windows\system32\svchost.exe -k netsvcs [22.4.2009 4:16 20992]
R2 RpcEptMapper;Mapovač koncových bodů protokolu RPC;c:\windows\system32\svchost.exe -k RPCSS [22.4.2009 4:16 20992]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\windows\System32\nvSCPAPISvr.exe [10.6.2009 5:33 232960]
R2 SysMain;Superfetch;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [22.4.2009 4:16 20992]
R2 tcpipreg;TCP/IP Registry Compatibility;c:\windows\System32\drivers\tcpipreg.sys [22.4.2009 4:52 34816]
R2 UxSms;Správce relací správce oken plochy;c:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted [22.4.2009 4:16 20992]
R2 WinDefend;Windows Defender;c:\windows\System32\svchost.exe -k secsvcs [22.4.2009 4:16 20992]
R3 1394ohci;1394 OHCI Compliant Host Controller;c:\windows\System32\drivers\1394ohci.sys [22.4.2009 4:50 162816]
R3 Appinfo;Informace o aplikaci;c:\windows\system32\svchost.exe -k netsvcs [22.4.2009 4:16 20992]
R3 bowser;Ovladač podpory prohlížeče;c:\windows\System32\drivers\bowser.sys [22.4.2009 4:11 69632]
R3 CompositeBus;Composite Bus Enumerator Driver;c:\windows\System32\drivers\CompositeBus.sys [22.4.2009 4:43 31232]
R3 DXGKrnl;LDDM Graphics Subsystem;c:\windows\System32\drivers\dxgkrnl.sys [22.4.2009 4:23 720384]
R3 fdPHost;Hostitel poskytovatele rozpoznávání funkce;c:\windows\system32\svchost.exe -k LocalService [22.4.2009 4:16 20992]
R3 HomeGroupListener;Naslouchací proces domácí skupiny;c:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted [22.4.2009 4:16 20992]
R3 HomeGroupProvider;Zprostředkovatel domácích skupin;c:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted [22.4.2009 4:16 20992]
R3 KeyIso;Izolace klíče CNG;c:\windows\System32\lsass.exe [22.4.2009 4:09 22528]
R3 monitor;Microsoft Monitor Class Function Driver Service;c:\windows\System32\drivers\monitor.sys [22.4.2009 4:23 23552]
R3 mpsdrv;Ovladač ověření brány Windows Firewall;c:\windows\System32\drivers\mpsdrv.sys [22.4.2009 4:51 60416]
R3 mrxsmb10;Mini-přesměrovač SMB 1.x;c:\windows\System32\drivers\mrxsmb10.sys [22.4.2009 4:11 220672]
R3 mrxsmb20;Mini-přesměrovač SMB 2.0;c:\windows\System32\drivers\mrxsmb20.sys [22.4.2009 4:11 94720]
R3 netprofm;Služba seznamu sítí;c:\windows\System32\svchost.exe -k LocalService [22.4.2009 4:16 20992]
R3 PcaSvc;Program Compatibility Assistant Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [22.4.2009 4:16 20992]
R3 Ph3xIB32;Philips 713x VU PCI TV Card;c:\windows\System32\drivers\Ph3xIB32.sys [20.3.2009 16:22 1131264]
R3 RasAgileVpn;WAN Miniport (IKEv2);c:\windows\System32\drivers\agilevpn.sys [22.4.2009 4:53 49152]
R3 rdpbus;Remote Desktop Device Redirector Bus Driver;c:\windows\System32\drivers\rdpbus.sys [22.4.2009 5:01 18432]
R3 srv2;Ovladač pro server SMB 2.xxx;c:\windows\System32\drivers\srv2.sys [12.11.2009 3:00 306688]
R3 srvnet;srvnet;c:\windows\System32\drivers\srvnet.sys [22.4.2009 4:12 113664]
R3 tunnel;Microsoft Tunnel Miniport Adapter Driver;c:\windows\System32\drivers\tunnel.sys [22.4.2009 4:52 108032]
R3 umbus;UMBus Enumerator Driver;c:\windows\System32\drivers\umbus.sys [22.4.2009 4:50 39936]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\System32\drivers\VBoxNetAdp.sys [30.6.2009 12:46 91408]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\System32\drivers\VBoxNetFlt.sys [30.6.2009 12:46 99472]
R3 WdiServiceHost;Hostitel diagnostické služby;c:\windows\System32\svchost.exe -k LocalService [22.4.2009 4:16 20992]
R3 WdiSystemHost;Hostitel diagnostického systému;c:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted [22.4.2009 4:16 20992]
R3 WPDBusEnum;Služba Výčet přenosných zařízení;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [22.4.2009 4:16 20992]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\System32\drivers\yk62x86.sys [28.9.2009 9:22 315392]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [16.9.2009 12:56 691696]
S2 gupdate1ca65dd45f55420;Služba Google Update (gupdate1ca65dd45f55420);c:\program files\Google\Update\GoogleUpdate.exe [15.11.2009 11:20 133104]
S2 MMCSS;Služba Plánovač multimédií;c:\windows\system32\svchost.exe -k netsvcs [22.4.2009 4:16 20992]
S2 sppsvc;Ochrana před softwarem;c:\windows\System32\sppsvc.exe [22.4.2009 5:44 3179520]
S3 AcpiPmi;ACPI Power Meter Driver;c:\windows\System32\drivers\acpipmi.sys [22.4.2009 4:13 9728]
S3 adp94xx;adp94xx;c:\windows\System32\drivers\adp94xx.sys [20.3.2009 16:22 422992]
S3 adpahci;adpahci;c:\windows\System32\drivers\adpahci.sys [22.4.2009 3:07 297552]
S3 amdsata;amdsata;c:\windows\System32\drivers\amdsata.sys [20.3.2009 16:23 77904]
S3 amdsbs;amdsbs;c:\windows\System32\drivers\amdsbs.sys [28.3.2009 5:45 159312]
S3 AppID;Ovladač AppID;c:\windows\System32\drivers\appid.sys [22.4.2009 4:35 50176]
S3 AppIDSvc;Identita aplikace;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [22.4.2009 4:16 20992]
S3 arcsas;arcsas;c:\windows\System32\drivers\arcsas.sys [22.4.2009 3:07 86608]
S3 b06bdrv;Broadcom NetXtreme II VBD;c:\windows\System32\drivers\bxvbdx.sys [20.3.2009 16:22 430080]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [22.4.2009 3:01 229888]
S3 BDESVC;Služba BitLocker Drive Encryption;c:\windows\System32\svchost.exe -k netsvcs [22.4.2009 4:16 20992]
S3 BrFiltLo;Brother USB Mass-Storage Lower Filter Driver;c:\windows\System32\drivers\BrFiltLo.sys [22.4.2009 5:55 13568]
S3 BrFiltUp;Brother USB Mass-Storage Upper Filter Driver;c:\windows\System32\drivers\BrFiltUp.sys [22.4.2009 5:56 5248]
S3 Brserid;Brother MFC Serial Port Interface Driver (WDM);c:\windows\System32\drivers\BrSerId.sys [22.4.2009 5:53 272128]
S3 BrSerWdm;Brother WDM Serial driver;c:\windows\System32\drivers\BrSerWdm.sys [22.4.2009 5:55 62336]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;c:\windows\System32\drivers\BrUsbMdm.sys [22.4.2009 5:55 12160]
S3 CertPropSvc;Šíření certifikátů;c:\windows\system32\svchost.exe -k netsvcs [22.4.2009 4:16 20992]
S3 circlass;Consumer IR Devices;c:\windows\System32\drivers\circlass.sys [22.4.2009 4:49 37888]
S3 defragsvc;Defragmentace disku;c:\windows\system32\svchost.exe -k defragsvc [22.4.2009 4:16 20992]
S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD;c:\windows\System32\drivers\evbdx.sys [20.3.2009 16:22 3100160]
S3 elxstor;elxstor;c:\windows\System32\drivers\elxstor.sys [20.3.2009 16:23 453712]
S3 epmntdrv;epmntdrv;c:\windows\System32\epmntdrv.sys [3.11.2009 12:44 9728]
S3 EuGdiDrv;EuGdiDrv;c:\windows\System32\EuGdiDrv.sys [3.11.2009 12:44 3072]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [18.8.2005 7168]
S3 Filetrace;FileTrace;c:\windows\System32\drivers\filetrace.sys [22.4.2009 4:12 28160]
S3 FontCache;Mezipaměť písem Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [22.4.2009 4:16 20992]
S3 FsDepends;File System Dependency Minifilter;c:\windows\System32\drivers\fsdepends.sys [22.4.2009 4:12 45648]
S3 hcw85cir;Hauppauge Consumer Infrared Receiver;c:\windows\System32\drivers\hcw85cir.sys [22.4.2009 3:52 26624]
S3 HpSAMD;HpSAMD;c:\windows\System32\drivers\HpSAMD.sys [22.4.2009 3:07 67152]
S3 iaStorV;iaStorV;c:\windows\System32\drivers\iaStorV.sys [15.4.2009 3:30 332368]
S3 IKEEXT;Služba IKE and AuthIP IPsec Keying Modules;c:\windows\system32\svchost.exe -k netsvcs [22.4.2009 4:16 20992]
S3 IPBusEnum;Rozpoznávací modul sběrnice PnP-X IP;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [22.4.2009 4:16 20992]
S3 IPMIDRV;IPMIDRV;c:\windows\System32\drivers\IPMIDrv.sys [22.4.2009 4:28 65536]
S3 iScsiPrt;iScsiPort Driver;c:\windows\System32\drivers\msiscsi.sys [22.4.2009 4:44 186960]
S3 KtmRm;Služba KTMRM pro koordinátor DTC;c:\windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation [22.4.2009 4:16 20992]
S3 lltdsvc;Mapovač zjišťování topologie linkové vrstvy;c:\windows\System32\svchost.exe -k LocalService [22.4.2009 4:16 20992]
S3 LSI_FC;LSI_FC;c:\windows\System32\drivers\lsi_fc.sys [22.4.2009 3:07 95824]
S3 LSI_SAS;LSI_SAS;c:\windows\System32\drivers\lsi_sas.sys [22.4.2009 3:07 89168]
S3 LSI_SAS2;LSI_SAS2;c:\windows\System32\drivers\lsi_sas2.sys [22.4.2009 3:07 54864]
S3 LSI_SCSI;LSI_SCSI;c:\windows\System32\drivers\lsi_scsi.sys [22.4.2009 3:07 96848]
S3 megasas;megasas;c:\windows\System32\drivers\megasas.sys [20.3.2009 16:23 30800]
S3 mpio;mpio;c:\windows\System32\drivers\mpio.sys [22.4.2009 4:44 130640]
S3 msahci;msahci;c:\windows\System32\drivers\msahci.sys [22.4.2009 4:44 27728]
S3 msdsm;msdsm;c:\windows\System32\drivers\msdsm.sys [22.4.2009 4:44 115792]
S3 mshidkmdf;Pass-through HID to KMDF Filter Driver;c:\windows\System32\drivers\mshidkmdf.sys [22.4.2009 4:49 4096]
S3 MSiSCSI;Služba iniciátoru iSCSI společnosti Microsoft;c:\windows\system32\svchost.exe -k netsvcs [22.4.2009 4:16 20992]
S3 MsRPC;MsRPC;c:\windows\System32\drivers\msrpc.sys [22.4.2009 4:09 162896]
S3 MTConfig;Microsoft Input Configuration Driver;c:\windows\System32\drivers\MTConfig.sys [22.4.2009 4:45 12288]
S3 NativeWifiP;NativeWiFi Filter;c:\windows\System32\drivers\nwifi.sys [22.4.2009 4:50 267264]
S3 NdisCap;NDIS Capture LightWeight Filter;c:\windows\System32\drivers\ndiscap.sys [22.4.2009 4:51 27136]
S3 nfrd960;nfrd960;c:\windows\System32\drivers\nfrd960.sys [22.4.2009 3:07 44624]
S3 PeerDistSvc;BranchCache;c:\windows\System32\svchost.exe -k PeerDist [22.4.2009 4:16 20992]
S3 pla;Výstrahy a protokolování výkonu;c:\windows\System32\svchost.exe -k LocalServiceNoNetwork [22.4.2009 4:16 20992]
S3 PNRPAutoReg;Služba publikování názvu počítače pomocí protokolu PNRP;c:\windows\System32\svchost.exe -k LocalServicePeerNet [22.4.2009 4:16 20992]
S3 ql2300;ql2300;c:\windows\System32\drivers\ql2300.sys [20.3.2009 16:23 1383504]
S3 ql40xx;ql40xx;c:\windows\System32\drivers\ql40xx.sys [22.4.2009 3:07 105552]
S3 s3cap;s3cap;c:\windows\System32\drivers\vms3cap.sys [22.4.2009 11:23 5632]
S3 scfilter;Ovladač filtru čipových karet třídy PnP;c:\windows\System32\drivers\scfilter.sys [22.4.2009 4:32 26624]
S3 SCPolicySvc;Zásady odebrání čipové karty;c:\windows\system32\svchost.exe -k netsvcs [22.4.2009 4:16 20992]
S3 SDRSVC;Windows Zálohování;c:\windows\system32\svchost.exe -k SDRSVC [22.4.2009 4:16 20992]
S3 SensrSvc;Adaptivní jas;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [22.4.2009 4:16 20992]
S3 SessionEnv;Remote Desktop Configuration;c:\windows\System32\svchost.exe -k netsvcs [22.4.2009 4:16 20992]
S3 sffp_mmc;SFF Storage Protocol Driver for MMC;c:\windows\System32\drivers\sffp_mmc.sys [22.4.2009 4:44 12288]
S3 SiSRaid4;SiSRaid4;c:\windows\System32\drivers\sisraid4.sys [22.4.2009 3:07 77904]
S3 Smb;Protokol TCP/IP a TCP/IPv6 orientovaný na zprávy (relace SMB);c:\windows\System32\drivers\smb.sys [22.4.2009 4:52 71168]
S3 sppuinotify;Služba Oznámení platformy SPP;c:\windows\system32\svchost.exe -k LocalService [22.4.2009 4:16 20992]
S3 stexstor;stexstor;c:\windows\System32\drivers\stexstor.sys [22.4.2009 3:07 21072]
S3 storvsc;storvsc;c:\windows\System32\drivers\storvsc.sys [22.4.2009 11:23 28240]
S3 TabletInputService;Služba Vstupní panel počítače Tablet PC;c:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted [22.4.2009 4:16 20992]
S3 TBS;Služba TPM Base Services;c:\windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [22.4.2009 4:16 20992]
S3 THREADORDER;Server pro řazení podprocesů;c:\windows\system32\svchost.exe -k LocalService [22.4.2009 4:16 20992]
S3 TrustedInstaller;Instalační služba modulů systému Windows;c:\windows\servicing\TrustedInstaller.exe [22.4.2009 4:20 204800]
S3 tssecsrv;Remote Desktop Services Security Filter Driver;c:\windows\System32\drivers\tssecsrv.sys [22.4.2009 5:00 30208]
S3 UI0Detect;Zjišťování interaktivních služeb;c:\windows\System32\UI0Detect.exe [22.4.2009 4:35 35840]
S3 uliagpkx;Uli AGP Bus Filter;c:\windows\System32\drivers\ULIAGPKX.SYS [22.4.2009 4:23 57424]
S3 UmRdpService;Přesměrovač portů uživatelského režimu služby Vzdálená plocha;c:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted [22.4.2009 4:16 20992]
S3 usbcir;eHome Infrared Receiver (USBCIR);c:\windows\System32\drivers\usbcir.sys [22.4.2009 4:49 86016]
S3 VaultSvc;Správce pověření;c:\windows\System32\lsass.exe [22.4.2009 4:09 22528]
S3 vhdmp;vhdmp;c:\windows\System32\drivers\vhdmp.sys [22.4.2009 4:44 158288]
S3 ViaC7;VIA C7 Processor Driver;c:\windows\System32\drivers\viac7.sys [22.4.2009 4:08 52736]
S3 vmbus;vmbus;c:\windows\System32\drivers\vmbus.sys [22.4.2009 11:23 175824]
S3 VMBusHID;VMBusHID;c:\windows\System32\drivers\VMBusHID.sys [22.4.2009 11:23 17920]
S3 vsmraid;vsmraid;c:\windows\System32\drivers\vsmraid.sys [20.3.2009 16:23 141904]
S3 vwifibus;Ovladač sběrnice Virtual WiFi;c:\windows\System32\drivers\vwifibus.sys [22.4.2009 4:50 19968]
S3 WacomPen;Wacom Serial Pen HID Driver;c:\windows\System32\drivers\wacompen.sys [22.4.2009 4:45 21632]
S3 wbengine;Služba jádra pro zálohování dat na úrovni bloků;c:\windows\System32\wbengine.exe [22.4.2009 4:21 1203200]
S3 WbioSrvc;Biometrická služba systému Windows;c:\windows\system32\svchost.exe -k WbioSvcGroup [22.4.2009 4:16 20992]
S3 wcncsvc;Technologie Windows Connect Now – Registrátor konfigurací;c:\windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [22.4.2009 4:16 20992]
S3 WcsPlugInService;Windows Color System;c:\windows\system32\svchost.exe -k wcssvc [22.4.2009 4:16 20992]
S3 Wd;Wd;c:\windows\System32\drivers\wd.sys [22.4.2009 4:08 19024]
S3 Wecsvc;Sběr událostí systému Windows;c:\windows\system32\svchost.exe -k NetworkService [22.4.2009 4:16 20992]
S3 wercplsupport;Podpora ovládacího panelu Oznámení a řešení problémů;c:\windows\System32\svchost.exe -k netsvcs [22.4.2009 4:16 20992]
S3 WerSvc;Služba Zasílání zpráv o chybách systému Windows;c:\windows\System32\svchost.exe -k WerSvcGroup [22.4.2009 4:16 20992]
S3 WIMMount;WIMMount;c:\windows\System32\drivers\wimmount.sys [22.4.2009 4:15 19024]
S3 WinRM;Vzdálená správa systému Windows (WS-Management);c:\windows\System32\svchost.exe -k NetworkService [22.4.2009 4:16 20992]
S3 Wlansvc;Automatická konfigurace sítě WLAN;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [22.4.2009 4:16 20992]
S3 WPCSvc;Rodičovská kontrola;c:\windows\system32\svchost.exe -k LocalServiceNetworkRestricted [22.4.2009 4:16 20992]
S3 WwanSvc;Automatická konfigurace sítě WWAN;c:\windows\system32\svchost.exe -k LocalServiceNoNetwork [22.4.2009 4:16 20992]
S4 Mcx2Svc;Služba zařízení Media Center Extender;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [22.4.2009 4:16 20992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
RPCSS REG_MULTI_SZ RpcEptMapper RpcSs
defragsvc REG_MULTI_SZ defragsvc
WerSvcGroup REG_MULTI_SZ wersvc
LocalServiceNoNetwork REG_MULTI_SZ DPS PLA BFE mpssvc WwanSvc
swprv REG_MULTI_SZ swprv
LocalServicePeerNet REG_MULTI_SZ PNRPSvc p2pimsvc p2psvc PnrpAutoReg
NetworkServiceAndNoImpersonation REG_MULTI_SZ KtmRm
regsvc REG_MULTI_SZ RemoteRegistry
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS AppIDSvc FontCache fdrespub QWAVE wcncsvc Mcx2Svc SensrSvc
DcomLaunch REG_MULTI_SZ Power PlugPlay DcomLaunch
NetworkServiceNetworkRestricted REG_MULTI_SZ PolicyAgent
sdrsvc REG_MULTI_SZ sdrsvc
WbioSvcGroup REG_MULTI_SZ WbioSrvc
wcssvc REG_MULTI_SZ WcsPlugInService
secsvcs REG_MULTI_SZ WinDefend
AxInstSVGroup REG_MULTI_SZ AxInstSV
PeerDist REG_MULTI_SZ PeerDistSvc
getPlusHelper REG_MULTI_SZ getPlusHelper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
AeLookupSvc
CertPropSvc
SCPolicySvc
lanmanserver
gpsvc
IKEEXT
AudioSrv
FastUserSwitchingCompatibility
Nla
NWCWorkstation
SRService
Wmi
WmdmPmSp
TermService
wuauserv
BITS
ShellHWDetection
LogonHours
PCAudit
helpsvc
uploadmgr
iphlpsvc
seclogon
AppInfo
msiscsi
MMCSS
EapHost
wercplsupport
ProfSvc
hkmsvc
winmgmt
SessionEnv
schedule
browser
BDESVC
Themes
AppMgmt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalSystemNetworkRestricted
homegrouplistener
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
WdiServiceHost
sppuinotify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetworkService
lanmanworkstation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalServiceNetworkRestricted
BthHFSrv
homegroupprovider
.
Obsah adresáře 'Naplánované úlohy'
2010-01-08 c:\windows\Tasks\1-Click Maintenance.job
- e:\tune up\OneClick.exe [2007-12-21 12:49]
2010-01-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-15 10:20]
2010-01-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-15 10:20]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.yahoo.com
mStart Page = hxxp://
www.yahoo.com
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Stáhnout Free Download Managerem - file://c:\program files\Free Download Manager\dllink.htm
IE: Stáhnout video Free Download Managerem - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Stáhnout vybrané Free Download Managerem - file://c:\program files\Free Download Manager\dlselected.htm
IE: Stáhnout vše Free Download Managerem - file://c:\program files\Free Download Manager\dlall.htm
FF - ProfilePath - c:\users\pepa\AppData\Roaming\Mozilla\Firefox\Profiles\0oeq67pi.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://
www.centrum.cz/
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=PTV&o=15184&locale=en_US&q=
FF - component: c:\program files\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll
FF - component: c:\users\pepa\AppData\Roaming\Mozilla\Firefox\Profiles\0oeq67pi.default\extensions\
DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\users\pepa\AppData\Roaming\Mozilla\Firefox\Profiles\0oeq67pi.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\windows.old\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\windows.old\Program Files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKLM-Run-SysMon - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
SafeBoot-sacsvr
SafeBoot-vmms
MSConfigStartUp-AlcoholAutomount - c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-12 17:59
Windows 6.1.7100 NTFS
detected NTDLL code modification:
ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-12 17:59
Windows 6.1.7100 NTFS
detected NTDLL code modification:
ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-12 17:59
Windows 6.1.7100 NTFS
detected NTDLL code modification:
ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-12 17:59
Windows 6.1.7100 NTFS
detected NTDLL code modification:
ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-12 17:59
Windows 6.1.7100 NTFS
detected NTDLL code modification:
ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-12 17:59
Windows 6.1.7100 NTFS
detected NTDLL code modification:
ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-12 17:59
Windows 6.1.7100 NTFS
detected NTDLL code modification:
ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-12 17:59
Windows 6.1.7100 NTFS
detected NTDLL code modification:
ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-12 17:59
Windows 6.1.7100 NTFS
detected NTDLL code modification:
ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-12 17:59
Windows 6.1.7100 NTFS
detected NTDLL code modification:
ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-12 17:59
Windows 6.1.7100 NTFS
detected NTDLL code modification:
ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory:
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-1232422079-2090965275-3250108306-1001\Software\SecuROM\License information*]
"datasecu"=hex:78,07,5d,f9,b9,7e,ca,95,39,25,c1,ad,64,8c,d4,27,12,dd,84,e5,73,
4f,4d,04,8d,36,23,f2,d1,b7,15,9f,45,d1,66,e8,07,fb,95,6a,c5,51,41,2a,15,eb,\
"rkeysecu"=hex:85,32,f3,85,c0,ec,c3,57,c0,cc,c4,b6,c1,ae,af,81
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'Explorer.exe'(3224)
c:\program files\WinMatrix\Matrix Skin Pack\YzShadow\YzShadow.dll
.
Celkový čas: 2010-01-12 18:01:36
ComboFix-quarantined-files.txt 2010-01-12 17:01
Před spuštěním: Volných bajtů: 16 782 229 504
Po spuštění: Volných bajtů: 16 568 811 520
- - End Of File - - FBB5541FE867F27095F8E989BD9ADFA0