Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosim o kontrolu :)

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
ivankrato
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 77
Registrován: 13 bře 2009 14:08

Prosim o kontrolu :)

#1 Příspěvek od ivankrato »

Zdravim, prosim o preventivni kontrolu logu, dekuji :)

Logfile of random's system information tool 1.08 (written by random/random)
Run by Roman Kratochvíl at 2010-07-28 20:54:17
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 2 GB (4%) free of 50 GB
Total RAM: 3327 MB (70% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:54:26, on 28.7.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dgdersvc.exe
C:\WINDOWS\dnetc.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre6\bin\jqs.exe
K:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
K:\Program Files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\EXPERTool\TBPanel.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\rundll32.exe
K:\Program Files\Microsoft ActiveSync\wcescomm.exe
K:\Program Files\Samsung\Kies\KiesTrayAgent.exe
K:\Program Files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMTray.exe
K:\PROGRA~1\MICROS~2\rapimgr.exe
L:\Program Files\VolumeWatcher\SPUVolumeWatcher.exe
C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
K:\Program Files\ICQ7.1\ICQ.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\Roman Kratochvíl\Local Settings\Data aplikací\Opera\Opera\profile\cache4\temporary_download\RSIT.exe
C:\Program Files\trend micro\Roman Kratochvíl.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: 216.107.250.194 nprotect.lineage2.com
O1 - Hosts: 90.182.221.59 l2authd.lineage2.com
O1 - Hosts: 90.182.221.59 l2testauthd.lineage2.com127.0.0.1 activate.adobe.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\core.2.dll
O2 - BHO: Kwyshell MidpX BHO - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: Kwyshell MidpX - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SteelSeries World of Warcraft MMO Gaming Mouse] K:\Program Files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [GAINWARD] C:\Program Files\EXPERTool\TBPanel.exe /A
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "K:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [KiesTrayAgent] K:\Program Files\Samsung\Kies\/\KiesTrayAgent.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = L:\Program Files\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: thg_clock.exe
O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Link to &MidpX - C:\Program Files\Kwyshell\MidpX\JadInvoker\Extent\jad_wrap.htm
O8 - Extra context menu item: Subscribe in Desktop Sidebar - res://C:\Program Files\Desktop Sidebar\sbhelp.dll/menuhandler.html
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - K:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - K:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - K:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - K:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - K:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{39202F08-1F8C-4236-B51E-00147A0BFA40}: NameServer = 10.255.255.10,10.255.255.20
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dragon Age: Prameny - aktualizace obsahu (DAUpdaterSvc) - BioWare - L:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: Device Error Recovery Service (dgdersvc) - Devguru Co., Ltd. - C:\WINDOWS\system32\dgdersvc.exe
O23 - Service: distributed.net client (dnetc) - Distributed Computing Technologies, Inc. - C:\WINDOWS\dnetc.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - K:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
O23 - Service: mysql - Unknown owner - K:\Downloads\wowcataalpha\Nová.exe (file missing)
O23 - Service: MySQL5 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: MySQL501 - Unknown owner - K:\Program.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Procedure Call (TPM) (RPCT) - Unknown owner - C:\Program Files\Common Files\System\mstinit.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe

--
End of file - 13450 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\OGALogon.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [2003-11-03 54248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45AD732C-2CE2-4666-B366-B2214AD57A49}]
Idea2 SidebarBrowserMonitor Class - C:\Program Files\Desktop Sidebar\sbhelp.dll [2004-09-04 233472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-03-09 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-03-09 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - C:\Program Files\Seznam.cz\core.2.dll [2009-05-18 1039000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EBE9E2B5-B526-48BC-AD46-687263EDCB0E}]
Kwyshell MidpX - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll [2004-12-03 100864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - Kwyshell MidpX - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll [2004-12-03 100864]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CloneCDTray"=C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [2006-09-28 57344]
"PCSuiteTrayApplication"=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe [2007-06-18 271360]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"SteelSeries World of Warcraft MMO Gaming Mouse"=K:\Program Files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe [2009-12-23 415232]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-07-01 1447168]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-06-03 1753192]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-06-07 13902440]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-06-07 110696]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"GAINWARD"=C:\Program Files\EXPERTool\TBPanel.exe [2009-02-03 2181672]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-09-15 1998576]
"H/PC Connection Agent"=K:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
"KiesTrayAgent"=K:\Program Files\Samsung\Kies\/\KiesTrayAgent.exe [2010-03-01 3404600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-02-19 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2007-08-22 80896]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
L:\Program Files\sony ericsson\pcsuite\Application Launcher\Application Launcher.exe [2005-10-26 159744]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2003-05-30 585728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe [2003-05-29 790528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2006-02-19 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Místní vyhledávání.lnk]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Roman Kratochvíl^Nabídka Start^Programy^Po spuštění^nod32.lnk]
[]

C:\Documents and Settings\Roman Kratochvíl\Nabídka Start\Programy\Po spuštění
Picture Motion Browser Media Check Tool.lnk - L:\Program Files\VolumeWatcher\SPUVolumeWatcher.exe
thg_clock.exe
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="wbsys.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
C:\Program Files\Stardock\Object Desktop\ThemeManager\fastload.dll [2001-12-20 24576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoSecCpl"=0
"DisableChangePassword"=0
"DisableLockWorkstation"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoStartMenuPinnedList"=0
"NoStartMenuMFUprogramsList"=0
"NoStartMenuSubFolders"=0
"NoCommonGroups"=0
"NoPrinterTabs"=0
"NoDeletePrinter"=0
"NoAddPrinter"=0
"NoPrinters"=0
"NoFavoritesMenu"=0
"NoDrives"=0
"NoRecentDocsNetHood"=0
"NoChangeAnimation"=0
"NoChangeKeyboardNavigationIndicators"=0
"NoInstrumentation"=1
"NoDriveTypeAutoRun"=323
"MaxRecentDocs"=11
"NoUserNameInStartMenu"=0
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe"="C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe:*:Enabled:Nero Home"
"E:\Program Files\TrackMania United\TmUnited.exe"="E:\Program Files\TrackMania United\TmUnited.exe:*:Enabled:TmUnited"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"L:\Program Files\Rockstar Games\GTA San Andreas\samp-server.exe"="L:\Program Files\Rockstar Games\GTA San Andreas\samp-server.exe:*:Enabled:samp-server"
"C:\Program Files\InterVideo\DVD7\WinDVD.exe"="C:\Program Files\InterVideo\DVD7\WinDVD.exe:*:Enabled:WinDVD"
"E:\Program Files\GOTCHA!\Gotcha.exe"="E:\Program Files\GOTCHA!\Gotcha.exe:*:Enabled:Gotcha!"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe"="C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater"
"C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe"="C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process "
"L:\xampp\apache\bin\apache.exe"="L:\xampp\apache\bin\apache.exe:*:Enabled:Apache HTTP Server"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"L:\Program Files\Azureus\Azureus.exe"="L:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
"K:\Program Files\Unreal Tournament 3\Binaries\UT3.exe"="K:\Program Files\Unreal Tournament 3\Binaries\UT3.exe:*:Enabled:Unreal Tournament 3"
"L:\Program Files\CyberLink\PowerDVD\PowerDVD.exe"="L:\Program Files\CyberLink\PowerDVD\PowerDVD.exe:*:Enabled:CyberLink PowerDVD"
"K:\Team17\Worms2\frontend.exe"="K:\Team17\Worms2\frontend.exe:*:Enabled:Worms 2 Frontend"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"L:\Program Files\Adobe\Adobe Photoshop CS3\dice_game_assets\photoproto.exe"="L:\Program Files\Adobe\Adobe Photoshop CS3\dice_game_assets\photoproto.exe:*:Enabled:Altia PhotoProto Version 8.0.0.5"
"L:\Program Files\Altia\PhotoProto\Runtime Files\photoproto.exe"="L:\Program Files\Altia\PhotoProto\Runtime Files\photoproto.exe:*:Enabled:Altia PhotoProto Version 8.0.0.5"
"L:\Program Files\Altia\PhotoProto\kostky_assets\photoproto.exe"="L:\Program Files\Altia\PhotoProto\kostky_assets\photoproto.exe:*:Enabled:Altia PhotoProto Version 8.0.0.5"
"E:\Program Files\worms 4\Worms 4 Mayhem\WORMS 4 MAYHEM.EXE"="E:\Program Files\worms 4\Worms 4 Mayhem\WORMS 4 MAYHEM.EXE:*:Enabled:Worms 4 Mayhem"
"L:\Program Files\Altia\PhotoProto\Atomovka_assets\photoproto.exe"="L:\Program Files\Altia\PhotoProto\Atomovka_assets\photoproto.exe:*:Enabled:Altia PhotoProto Version 8.0.0.5"
"L:\Program Files\Altia\PhotoProto\Nase_fotoalbum_assets\photoproto.exe"="L:\Program Files\Altia\PhotoProto\Nase_fotoalbum_assets\photoproto.exe:*:Enabled:Altia PhotoProto Version 8.0.0.5"
"L:\Program Files\Altia\PhotoProto\mountfield1_assets\photoproto.exe"="L:\Program Files\Altia\PhotoProto\mountfield1_assets\photoproto.exe:*:Enabled:Altia PhotoProto Version 8.0.0.5"
"K:\Program Files\Warcraft III\Warcraft III.exe"="K:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe"="C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"K:\Program Files\Autodesk\3ds Max 9\3dsmax.exe"="K:\Program Files\Autodesk\3ds Max 9\3dsmax.exe:*:Enabled:Autodesk 3ds Max 9 32-bit"
"C:\Program Files\Autodesk\Backburner\monitor.exe"="C:\Program Files\Autodesk\Backburner\monitor.exe:*:Enabled:backburner 2.3 monitor"
"C:\Program Files\Autodesk\Backburner\manager.exe"="C:\Program Files\Autodesk\Backburner\manager.exe:*:Enabled:backburner 2.3 manager"
"C:\Program Files\Autodesk\Backburner\server.exe"="C:\Program Files\Autodesk\Backburner\server.exe:*:Enabled:backburner 2.3 server"
"E:\Program Files\TmUnitedForever\TmForever.exe"="E:\Program Files\TmUnitedForever\TmForever.exe:*:Enabled:TmForever"
"C:\Program Files\Electronic Arts\EADM\Core.exe"="C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"K:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe"="K:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:*:Enabled:Crysis_32"
"K:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe"="K:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:*:Enabled:CrysisDedicatedServer_32"
"K:\Program Files\Outspark\Project Powder\Run.exe"="K:\Program Files\Outspark\Project Powder\Run.exe:*:Enabled:ProjectPowder"
"L:\Program Files\Gumboy Tournament\Gumboy Tournament.exe"="L:\Program Files\Gumboy Tournament\Gumboy Tournament.exe:*:Enabled:Gumboy Tournament"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"L:\Program Files\Microsoft Games\MechWarrior Vengeance\MW4.ICD"="L:\Program Files\Microsoft Games\MechWarrior Vengeance\MW4.ICD:*:Enabled:MechWarrior IV"
"L:\Program Files\Microsoft Games\MechWarrior Vengeance\mw4.exe"="L:\Program Files\Microsoft Games\MechWarrior Vengeance\mw4.exe:*:Enabled:MechWarrior IV"
"C:\xampp\apache\bin\apache.exe"="C:\xampp\apache\bin\apache.exe:*:Enabled:Apache HTTP Server"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"L:\Program Files\TrackMania Sunrise\TmSunrise.exe"="L:\Program Files\TrackMania Sunrise\TmSunrise.exe:*:Enabled:TmSunrise"
"\\Loznice\l\Program Files\TrackMania Sunrise\TmSunrise.exe"="\\Loznice\l\Program Files\TrackMania Sunrise\TmSunrise.exe:*:Enabled:TmSunrise"
"K:\Program Files\GameSpy\Comrade\Comrade.exe"="K:\Program Files\GameSpy\Comrade\Comrade.exe:*:Enabled:Comrade"
"K:\Program Files\EA Games\Mirror's Edge\Binaries\MirrorsEdge.exe"="K:\Program Files\EA Games\Mirror's Edge\Binaries\MirrorsEdge.exe:*:Enabled:Mirror's Edge™"
"K:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe"="K:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
"K:\Program Files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe"="K:\Program Files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
"K:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe"="K:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe:*:Enabled:Burnout(TM) Paradise The Ultimate Box"
"K:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe"="K:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe:*:Enabled:Burnout(TM) Paradise The Ultimate Box"
"K:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe"="K:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe:*:Enabled:Burnout(TM) Paradise The Ultimate Box"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"K:\Program Files\Activision\Wolfenstein\MP\Wolf2MP.exe"="K:\Program Files\Activision\Wolfenstein\MP\Wolf2MP.exe:*:Enabled:Wolfenstein(TM)"
"K:\Program Files\Activision\Wolfenstein\MP\Wolf2MPLite.exe"="K:\Program Files\Activision\Wolfenstein\MP\Wolf2MPLite.exe:*:Enabled:Wolfenstein(TM)"
"K:\Program Files\Ubisoft\Far Cry 2\bin\FarCry2.exe"="K:\Program Files\Ubisoft\Far Cry 2\bin\FarCry2.exe:*:Enabled:Far Cry 2"
"K:\Program Files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe"="K:\Program Files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe:*:Enabled:Far Cry 2 Updater"
"K:\Program Files\Ubisoft\Far Cry 2\bin\FC2Editor.exe"="K:\Program Files\Ubisoft\Far Cry 2\bin\FC2Editor.exe:*:Enabled:Editor"
"K:\Program Files\Steam\Steam.exe"="K:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"L:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="L:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"K:\Program Files\Microsoft ActiveSync\rapimgr.exe"="K:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"K:\Program Files\Microsoft ActiveSync\wcescomm.exe"="K:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"K:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="K:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"L:\Program Files\Activision\Call of Duty 5 - World at War\CoDWaW.exe"="L:\Program Files\Activision\Call of Duty 5 - World at War\CoDWaW.exe:*:Enabled:Call of Duty(R) - World at War(TM) "
"L:\Program Files\Activision\Call of Duty 5 - World at War\CoDWaWmp.exe"="L:\Program Files\Activision\Call of Duty 5 - World at War\CoDWaWmp.exe:*:Enabled:Call of Duty(R) - World at War(TM) "
"K:\Program Files\Empire Interactive\FlatOut Ultimate Carnage\Fouc.exe"="K:\Program Files\Empire Interactive\FlatOut Ultimate Carnage\Fouc.exe:*:Enabled:FlatOut Ultimate Carnage"
"L:\Program Files\Pinnacle\Studio 11\programs\RM.exe"="L:\Program Files\Pinnacle\Studio 11\programs\RM.exe:*:Enabled:Render Manager"
"L:\Program Files\Pinnacle\Studio 11\programs\Studio.exe"="L:\Program Files\Pinnacle\Studio 11\programs\Studio.exe:*:Enabled:Studio"
"L:\Program Files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe"="L:\Program Files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile"
"L:\Program Files\Pinnacle\Studio 11\programs\umi.exe"="L:\Program Files\Pinnacle\Studio 11\programs\umi.exe:*:Enabled:umi"
"L:\Program Files\Dragon Age\bin_ship\daorigins.exe"="L:\Program Files\Dragon Age\bin_ship\daorigins.exe:*:Enabled:Dragon Age Prameny Hra"
"L:\Program Files\Dragon Age\DAOriginsLauncher.exe"="L:\Program Files\Dragon Age\DAOriginsLauncher.exe:*:Enabled:Dragon Age Prameny Spustit"
"L:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe"="L:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe:*:Enabled:Dragon Age Prameny Aktualizovat"
"K:\Program Files\ICQ7.1\ICQ.exe"="K:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"K:\Program Files\ICQ7.1\aolload.exe"="K:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\WINDOWS\system32\muzapp.exe"="C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"K:\Program Files\Steam\steamapps\common\peggle extreme\PeggleExtreme.exe"="K:\Program Files\Steam\steamapps\common\peggle extreme\PeggleExtreme.exe:*:Enabled:Peggle Extreme"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"K:\Program Files\Microsoft ActiveSync\rapimgr.exe"="K:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"K:\Program Files\Microsoft ActiveSync\wcescomm.exe"="K:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"K:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="K:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"K:\Program Files\ICQ7.1\ICQ.exe"="K:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"K:\Program Files\ICQ7.1\aolload.exe"="K:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

======List of files/folders created in the last 1 months======

2010-07-28 20:54:18 ----D---- C:\Program Files\trend micro
2010-07-28 17:38:17 ----A---- C:\WINDOWS\WPE PRO.INI
2010-07-26 20:39:21 ----D---- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\Hamachi
2010-07-15 23:33:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2010-07-09 21:04:40 ----A---- C:\WINDOWS\system32\xfcodec.dll
2010-07-02 12:38:45 ----A---- C:\WINDOWS\system32\drivers\Mo3Fltr.sys
2010-06-30 22:30:24 ----D---- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\NVIDIA
2010-06-30 22:03:22 ----D---- C:\WINDOWS\D56B0E274A3E46C9B5C1D93D580C099C.TMP
2010-06-30 22:03:00 ----D---- C:\Program Files\Microsoft Chart Controls
2010-06-29 13:20:50 ----A---- C:\WINDOWS\system32\OpenCL.dll
2010-06-29 13:20:48 ----A---- C:\WINDOWS\system32\nvcompiler.dll

======List of files/folders modified in the last 1 months======

2010-07-28 20:54:19 ----D---- C:\WINDOWS\temp
2010-07-28 20:54:18 ----RD---- C:\Program Files
2010-07-28 20:53:28 ----D---- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\Skype
2010-07-28 20:32:14 ----D---- C:\Program Files\Common Files\Akamai
2010-07-28 20:05:50 ----A---- C:\WINDOWS\win.ini
2010-07-28 18:25:40 ----D---- C:\WINDOWS\system32\CatRoot2
2010-07-28 17:43:10 ----A---- C:\WINDOWS\NeroDigital.ini
2010-07-28 17:38:17 ----D---- C:\WINDOWS
2010-07-28 16:57:16 ----D---- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\ICQ
2010-07-28 16:33:23 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-07-28 12:30:59 ----D---- C:\WINDOWS\system32
2010-07-28 12:30:58 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-07-27 23:17:03 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-07-27 16:11:34 ----D---- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\AdobeUM
2010-07-26 13:51:55 ----A---- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\MPQEditor.ini
2010-07-23 20:03:27 ----SHD---- C:\WINDOWS\Installer
2010-07-23 20:03:27 ----HD---- C:\Config.Msi
2010-07-20 23:05:42 ----D---- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\Xfire
2010-07-20 13:01:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\Blizzard Entertainment
2010-07-18 16:33:37 ----A---- C:\WINDOWS\system32\fmod.dll
2010-07-18 16:31:03 ----RSD---- C:\WINDOWS\assembly
2010-07-18 16:30:42 ----D---- C:\Program Files\Microsoft.NET
2010-07-18 16:17:23 ----HD---- C:\WINDOWS\inf
2010-07-16 11:47:19 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2010-07-15 23:33:19 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-07-15 23:32:52 ----HD---- C:\WINDOWS\$hf_mig$
2010-07-02 21:39:05 ----A---- C:\WINDOWS\system32\MRT.exe
2010-07-02 12:39:10 ----D---- C:\WINDOWS\system32\drivers
2010-07-02 12:38:45 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-07-02 12:38:32 ----RSD---- C:\WINDOWS\Fonts
2010-06-30 22:03:08 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-06-30 22:02:30 ----D---- C:\WINDOWS\system32\DirectX
2010-06-30 19:26:51 ----D---- C:\WINDOWS\Minidump
2010-06-29 13:25:50 ----D---- C:\WINDOWS\Help
2010-06-29 13:21:40 ----D---- C:\Program Files\NVIDIA Corporation

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 a347bus;a347bus; C:\WINDOWS\system32\DRIVERS\a347bus.sys [2005-04-25 159616]
R0 a347scsi;a347scsi; C:\WINDOWS\System32\Drivers\a347scsi.sys [2004-04-30 5248]
R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\System32\DRIVERS\agp440.sys [2008-04-14 42368]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 Pnp680r;Silicon Image SiI 0680 Medley Raid Controller; C:\WINDOWS\system32\DRIVERS\pnp680r.sys [2002-05-31 76976]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2008-08-20 44944]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a); C:\WINDOWS\System32\drivers\sfdrv01a.sys [2006-07-05 63352]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2006-06-14 13680]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\WINDOWS\System32\drivers\sfsync02.sys [2006-07-10 27032]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2007-01-12 82296]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-11-28 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-15 76544]
R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-07-01 53256]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2008-07-01 54280]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 PCLEPCI;PCLEPCI; \??\C:\WINDOWS\system32\drivers\pclepci.sys []
R1 prodrv03;Star Force copy protection driver v3; C:\WINDOWS\System32\drivers\prodrv03.sys [2008-03-31 115968]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R1 sf;SFI Service; C:\WINDOWS\system32\drivers\sf.sys [2003-05-09 33248]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B}; \??\L:\Program Files\CyberLink\PowerDVD\000.fcl []
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-07-01 39944]
R2 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2006-12-26 15440]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2008-07-01 71688]
R2 TBPanel;TBPanel; C:\WINDOWS\system32\drivers\TBPanel.sys [2007-03-16 12256]
R3 ASAPIW2k;ASAPIW2K; C:\WINDOWS\system32\drivers\ASAPIW2k.sys [2004-03-10 11264]
R3 dgderdrv;dgderdrv; C:\WINDOWS\System32\drivers\dgderdrv.sys [2010-02-04 18136]
R3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2006-12-26 34760]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2008-07-01 30728]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-05-26 25280]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-10-12 4609024]
R3 Ma730Pt;MA730 Bluetooth VCOM Driver; C:\WINDOWS\system32\DRIVERS\Ma730Pt.sys [2005-12-22 102720]
R3 Ma730Vad;MA730 Bluetooth Audio; C:\WINDOWS\system32\DRIVERS\Ma730Vad.sys [2005-11-22 23376]
R3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2007-01-04 171520]
R3 Mo3Fltr;MMO Mouse; C:\WINDOWS\system32\drivers\Mo3Fltr.sys [2008-04-15 11136]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-06-08 10531200]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2007-05-05 47360]
R3 pepifilter;Volume Adapter; C:\WINDOWS\system32\DRIVERS\lv302af.sys [2004-01-21 5915]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 PID_08A0;Labtec WebCam Pro(PID_08A0); C:\WINDOWS\system32\DRIVERS\LV302AV.SYS [2004-01-21 271360]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-10-12 94592]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 SMBios;Intel (R) System Management BIOS Service; C:\WINDOWS\System32\DRIVERS\SMBios.sys [2003-10-14 36484]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 zebrceb;Sony Ericsson Cable Emulation Bus (WDM); C:\WINDOWS\system32\DRIVERS\zebrceb.sys [2006-02-01 41792]
S1 c4f7eb95;c4f7eb95; C:\WINDOWS\System32\drivers\c4f7eb95.sys []
S3 a3wcwrwy;a3wcwrwy; C:\WINDOWS\system32\drivers\a3wcwrwy.sys []
S3 Ad-Watch Connect Filter;Ad-Watch Connect Kernel Filter; \??\C:\WINDOWS\system32\drivers\NSDriver.sys []
S3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2003-03-14 100224]
S3 AgereSoftModem;Microcom InPorte Home; C:\WINDOWS\system32\DRIVERS\AGRSM.sys []
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 Cardex;Cardex; \??\C:\WINDOWS\system32\drivers\TBPANEL.SYS []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 DCamUSBEMPIA;USB 2861 Video; C:\WINDOWS\system32\DRIVERS\emDevice.sys [2005-10-29 169984]
S3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\System32\DRIVERS\e100b325.sys [2003-03-04 145408]
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 FiltUSBEMPIA;USB Device Lower Filter; C:\WINDOWS\system32\DRIVERS\emFilter.sys [2005-10-29 5248]
S3 GarenaPEngine;GarenaPEngine; \??\C:\DOCUME~1\ROMANK~1\LOCALS~1\Temp\VBU641.tmp []
S3 ggsemc;Sony Ericsson USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsemc.sys [2006-03-01 8704]
S3 GMSIPCI;GMSIPCI; C:\WINDOWS\system32\drivers\GMSIPCI.sys []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-04-12 49664]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-04-12 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-04-12 21568]
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\WINDOWS\system32\DRIVERS\k750bus.sys [2005-06-03 55216]
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\k750mdfl.sys [2005-06-03 6576]
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers; C:\WINDOWS\system32\DRIVERS\k750mdm.sys [2005-06-03 89872]
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers; C:\WINDOWS\system32\DRIVERS\k750mgmt.sys [2005-06-03 81728]
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers; C:\WINDOWS\system32\DRIVERS\k750obex.sys [2005-06-03 79488]
S3 Love01;Love01; \??\E:\Ivan\Love Engine0.3\Engine\Love Engine0.3\Loveliss.sys []
S3 MidiSyn;MidiSyn; C:\WINDOWS\system32\drivers\MidiSyn.sys [2002-09-20 235100]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 MSICPL;MSICPL; C:\WINDOWS\system32\drivers\MSICPL.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2008-09-15 17664]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2008-09-15 22016]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2008-02-01 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2008-02-01 8320]
S3 npkcrypt;npkcrypt; \??\K:\Program Files\Lineage II\system\npkcrypt.sys []
S3 NPPTNT2;NPPTNT2; \??\C:\WINDOWS\system32\npptNT2.sys []
S3 NTACCESS;NTACCESS; C:\WINDOWS\system32\drivers\NTACCESS.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 ScanUSBEMPIA;USB Still Image Capture Device; C:\WINDOWS\system32\DRIVERS\emScan.sys [2005-10-29 5120]
S3 SetupNTGLM7X;SetupNTGLM7X; C:\WINDOWS\system32\drivers\SetupNTGLM7X.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-06-02 578304]
S3 sony_ssm.sys;sony_ssm.sys; C:\WINDOWS\system32\drivers\sony_ssm.sys.sys []
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 SoRa01;SoRa01; \??\E:\Ivan\Love Engine0.3\Engine\SoRa 2.6\SoRa.sys []
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 syscom1;syscom1; \??\E:\Ivan\ostatni\XTK2175\XTK2175.sys []
S3 tap0901_2gm;VPN Anonymizer Adapter; C:\WINDOWS\system32\DRIVERS\tap0901_2gm.sys [2007-06-21 30720]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2008-09-15 8064]
S3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-14 12800]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-14 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2008-09-15 8064]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
S3 XDva098;XDva098; C:\WINDOWS\system32\drivers\XDva098.sys []
S3 XDva143;XDva143; \??\C:\WINDOWS\system32\XDva143.sys []
S3 XDva189;XDva189; \??\C:\WINDOWS\system32\XDva189.sys []
S3 XDva195;XDva195; \??\C:\WINDOWS\system32\XDva195.sys []
S3 XDva207;XDva207; \??\C:\WINDOWS\system32\XDva207.sys []
S3 XDva208;XDva208; \??\C:\WINDOWS\system32\XDva208.sys []
S3 XDva281;XDva281; \??\C:\WINDOWS\system32\XDva281.sys []
S3 XDva344;XDva344; \??\C:\WINDOWS\system32\XDva344.sys []
S3 XDva347;XDva347; \??\C:\WINDOWS\system32\XDva347.sys []
S3 XDva349;XDva349; \??\C:\WINDOWS\system32\XDva349.sys []
S3 XDva351;XDva351; \??\C:\WINDOWS\system32\XDva351.sys []
S3 XDva352;XDva352; \??\C:\WINDOWS\system32\XDva352.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Ad-Aware 2007 Service; C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe [2007-06-05 561152]
R2 Akamai;Akamai NetSession Interface; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-09-10 116040]
R2 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2008-06-03 72704]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 dgdersvc;Device Error Recovery Service; C:\WINDOWS\system32\dgdersvc.exe [2010-02-04 95568]
R2 dnetc;distributed.net client; C:\WINDOWS\dnetc.exe [2006-09-10 539136]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 FsUsbExService;FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [2009-12-22 217088]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-03-09 153376]
R2 mi-raysat_3dsmax9_32;mental ray 3.5 Satellite (32-bit); K:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe [2006-09-29 65536]
R2 MySQL5;MySQL5; C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt --defaults-file=C:\Program Files\MySQL\MySQL Server 5.0\my.ini MySQL5 []
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-06-07 154728]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2006-03-03 69632]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-12-15 75064]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2010-04-30 214520]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-02-07 173616]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 StarWindService;StarWind iSCSI Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe [2005-04-02 217600]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; C:\WINDOWS\System32\TUProgSt.exe [2009-10-09 603904]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2005-01-31 49152]
R2 UserAccess7;SecuROM User Access Service (V7); C:\WINDOWS\system32\UAService7.exe [2007-09-03 122880]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-11-11 620544]
S2 mysql;mysql; K:\Downloads\wowcataalpha\Nová složka\Server\mysql\bin\mysqld-nt --defaults-file=K:\Downloads\wowcataalpha\Nová složka\Server\mysql\bin\my.cnf mysql []
S2 RPCT;Remote Procedure Call (TPM); C:\Program Files\Common Files\System\mstinit.exe []
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; L:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-07-01 19200]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-10-16 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MySQL501;MySQL501; K:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt --defaults-file=K:\Program Files\MySQL\MySQL Server 5.0\my.ini MySQL501 []
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2009-10-09 360192]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119418
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu :)

#2 Příspěvek od Rudy »

Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ivankrato
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 77
Registrován: 13 bře 2009 14:08

Re: Prosim o kontrolu :)

#3 Příspěvek od ivankrato »

Pri aplikovani Combofixu mi to hodilo modrou smrt, mam Combofix zapnout znovu?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119418
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu :)

#4 Příspěvek od Rudy »

Zkuste to znovu, ale v nouz. režimu.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ivankrato
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 77
Registrován: 13 bře 2009 14:08

Re: Prosim o kontrolu :)

#5 Příspěvek od ivankrato »

Here is it :D

ComboFix 10-07-28.03 - Roman Kratochvíl 29.07.2010 16:11:27.9.2 - x86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3327.2774 [GMT 2:00]
Spuštěný z: c:\documents and settings\Roman Kratochvíl\Plocha\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\win32GI
c:\program files\win32GI\klog.dat
c:\windows\My.ini
c:\windows\system32\msconfig.exe
c:\windows\system32\muzapp.exe
c:\windows\system32\prsgrc.dll
c:\windows\system32\system32
c:\windows\system32\system32\cis-2.4.dll
c:\windows\system32\system32\issacapi_bs-2.3.dll
c:\windows\system32\system32\issacapi_pe-2.3.dll
c:\windows\system32\system32\issacapi_se-2.3.dll
c:\windows\system32\system32\MACXMLProto.dll
c:\windows\system32\system32\MaDRM.dll
c:\windows\system32\system32\MaJGUILib.dll
c:\windows\system32\system32\MAMACExtract.dll
c:\windows\system32\system32\MASetupCaller.dll
c:\windows\system32\system32\MASetupCleaner.exe
c:\windows\system32\system32\MaXMLProto.dll
c:\windows\system32\system32\MK_Lyric.dll
c:\windows\system32\system32\MSCLib.dll
c:\windows\system32\system32\MSFLib.dll
c:\windows\system32\system32\MSLUR71.dll
c:\windows\system32\system32\msvcp60.dll
c:\windows\system32\system32\MTTELECHIP.dll
c:\windows\system32\system32\MTXSYNCICON.dll
c:\windows\system32\system32\muzaf1.dll
c:\windows\system32\system32\muzapp.dll
c:\windows\system32\system32\muzapp.exe
c:\windows\system32\system32\muzdecode.ax
c:\windows\system32\system32\muzeffect.ax
c:\windows\system32\system32\muzmp4sp.ax
c:\windows\system32\system32\muzmpgsp.ax
c:\windows\system32\system32\muzoggsp.ax
c:\windows\system32\system32\muzwmts.dll
c:\windows\system32\system32\psapi.dll
c:\windows\wpe pro.INI
L:\install.exe

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-06-28 do 2010-07-29 )))))))))))))))))))))))))))))))
.

2010-07-29 12:29 . 2010-07-29 12:30 -------- d-----w- C:\NST
2010-07-29 12:17 . 2010-07-29 12:17 -------- d-----w- c:\program files\NeoSmart Technologies
2010-07-29 06:55 . 2010-07-17 03:00 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-28 18:54 . 2010-07-28 18:54 -------- d-----w- c:\program files\trend micro
2010-07-15 15:43 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-09 19:04 . 2010-07-09 19:04 41872 ----a-w- c:\windows\system32\xfcodec.dll
2010-07-02 10:38 . 2008-04-15 08:05 11136 ----a-w- c:\windows\system32\drivers\Mo3Fltr.sys
2010-06-30 20:03 . 2010-06-30 20:03 -------- d-----w- c:\windows\D56B0E274A3E46C9B5C1D93D580C099C.TMP
2010-06-30 20:03 . 2010-06-30 20:03 -------- d-----w- c:\program files\Microsoft Chart Controls

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-29 13:52 . 2001-10-25 12:00 67888 ----a-w- c:\windows\system32\perfc005.dat
2010-07-29 13:52 . 2001-10-25 12:00 363120 ----a-w- c:\windows\system32\perfh005.dat
2010-07-29 13:44 . 2010-05-07 19:17 -------- d-----w- c:\program files\Common Files\Akamai
2010-07-29 11:08 . 2009-04-21 16:31 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-07-29 06:55 . 2007-03-02 16:33 -------- d-----w- c:\program files\Common Files\Java
2010-07-29 06:55 . 2007-03-02 16:33 -------- d-----w- c:\program files\Java
2010-07-18 14:33 . 2010-04-28 12:57 162816 ----a-w- c:\windows\system32\fmod.dll
2010-07-18 14:30 . 2007-03-18 18:10 -------- d-----w- c:\program files\Microsoft.NET
2010-07-16 09:47 . 2007-08-27 16:58 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-06-30 20:03 . 2007-11-02 19:08 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-06-29 11:37 . 2010-06-29 11:21 217992 ----a-w- c:\windows\system32\nvdrsdb0.bin
2010-06-29 11:37 . 2010-06-29 11:21 217984 ----a-w- c:\windows\system32\nvdrsdb1.bin
2010-06-29 11:37 . 2010-06-29 11:21 1 ----a-w- c:\windows\system32\nvdrssel.bin
2010-06-29 11:21 . 2009-09-28 17:16 -------- d-----w- c:\program files\NVIDIA Corporation
2010-06-14 14:31 . 2007-02-28 21:49 744448 ----a-w- c:\windows\PCHealth\HelpCtr\Binaries\helpsvc.exe
2010-06-13 11:46 . 2010-06-13 11:46 672 ----a-w- c:\windows\Fonts\N-GAGE__.PFM
2010-06-07 15:35 . 2010-06-07 15:35 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-05-28 10:58 . 2008-02-13 23:09 600680 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-05-26 18:27 . 2007-09-21 17:42 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
2010-05-17 20:13 . 2007-06-23 18:08 251 ----a-w- c:\windows\popcinfot.dat
2010-05-06 10:35 . 2004-08-17 13:49 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 08:09 . 2004-08-17 13:44 1851264 ----a-w- c:\windows\system32\win32k.sys
2008-03-08 19:08 . 2008-03-08 19:08 0 ----a-w- c:\program files\temp01
2007-08-02 10:56 . 2007-08-02 10:56 774144 ----a-w- c:\program files\RngInterstitial.dll
2007-07-26 11:14 . 2007-04-21 08:02 291 ----a-w- c:\program files\img2ozf.ini
2007-04-21 07:59 . 2007-04-21 07:59 1000 ----a-w- c:\program files\unins000.dat
2003-07-08 12:56 . 2003-07-08 12:56 47250 ----a-w- c:\program files\Img2Ozf.chm
2003-06-16 13:35 . 2003-06-16 13:35 1216512 ----a-w- c:\program files\Img2ozf.exe
2003-02-01 22:00 . 2003-02-01 22:00 86356 ----a-w- c:\program files\unins000.exe
2009-02-08 15:17 . 2009-02-08 15:17 56 --sh--r- c:\windows\system32\E6599D5197.sys
2010-03-13 10:44 . 2009-02-08 15:17 2150 --sha-w- c:\windows\system32\KGyGaAvL.sys
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VirtualExpanderFile.1]
@="{E4000AC4-5E5F-4956-807A-C5854405D64F}"
[HKEY_CLASSES_ROOT\CLSID\{E4000AC4-5E5F-4956-807A-C5854405D64F}]
2008-12-24 18:18 73728 ------w- c:\windows\system32\VirtualExpander\VEShellExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KiesTrayAgent"="k:\program files\Samsung\Kies\" [X]
"GAINWARD"="c:\program files\EXPERTool\TBPanel.exe" [2009-02-03 2181672]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-09-15 1998576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 57344]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 271360]
"SteelSeries World of Warcraft MMO Gaming Mouse"="k:\program files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe" [2009-12-23 415232]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-07-01 1447168]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-06-02 1753192]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-06-07 13902440]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-06-07 110696]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088]

c:\documents and settings\Roman Kratochvˇl\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Picture Motion Browser Media Check Tool.lnk - l:\program files\VolumeWatcher\SPUVolumeWatcher.exe [2008-4-19 344064]
thg_clock.exe [2007-11-19 49152]
VirtualExpander.lnk - c:\windows\system32\VirtualExpander\VirtualExpander.exe [2008-12-24 474808]
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCpl"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
"MaxRecentDocs"= 11 (0xb)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\documents and settings\All Users\Data aplikací\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-20 21:34 24576 ----a-w- c:\program files\Stardock\Object Desktop\ThemeManager\fastload.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Místní vyhledávání.lnk]
backup=c:\windows\pss\Místní vyhledávání.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Roman Kratochvíl^Nabídka Start^Programy^Po spuštění^nod32.lnk]
backup=c:\windows\pss\nod32.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 00:41 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
2007-08-22 14:31 80896 ----a-w- c:\program files\HP\Digital Imaging\bin\HpqSRmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 14:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2005-10-26 14:17 159744 ----a-r- l:\program files\sony ericsson\pcsuite\Application Launcher\Application Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
2003-05-30 07:42 585728 ----a-w- c:\program files\Analog Devices\SoundMAX\SMax4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2003-05-29 14:28 790528 ----a-w- c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe"
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"Power2GoExpress"="k:\program files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" -silent
"Seznam Postak"="c:\program files\Seznam.cz\postak.exe" -s
"CamSpace"="k:\program files\CamSpace\CamSpaceAgent.exe"
"DAEMON Tools Lite"="k:\program files\DAEMON Tools Lite\DTLite.exe" -autorun

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_11\bin\jusched.exe"
"PinnacleDriverCheck"=c:\windows\system32\PSDrvCheck.exe -CheckReg
"Recordpad"="c:\program files\NCH Swift Sound\Recordpad\recordpad.exe" -logon
"PCSuiteTrayApplication"=c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"e:\\Program Files\\TrackMania United\\TmUnited.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"l:\\Program Files\\Rockstar Games\\GTA San Andreas\\samp-server.exe"=
"c:\\Program Files\\InterVideo\\DVD7\\WinDVD.exe"=
"e:\\Program Files\\GOTCHA!\\Gotcha.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"l:\\xampp\\apache\\bin\\apache.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"l:\\Program Files\\Azureus\\Azureus.exe"=
"k:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"l:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"k:\\Team17\\Worms2\\frontend.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"l:\\Program Files\\Adobe\\Adobe Photoshop CS3\\dice_game_assets\\photoproto.exe"=
"l:\\Program Files\\Altia\\PhotoProto\\Runtime Files\\photoproto.exe"=
"l:\\Program Files\\Altia\\PhotoProto\\kostky_assets\\photoproto.exe"=
"e:\\Program Files\\worms 4\\Worms 4 Mayhem\\WORMS 4 MAYHEM.EXE"=
"l:\\Program Files\\Altia\\PhotoProto\\Atomovka_assets\\photoproto.exe"=
"l:\\Program Files\\Altia\\PhotoProto\\Nase_fotoalbum_assets\\photoproto.exe"=
"l:\\Program Files\\Altia\\PhotoProto\\mountfield1_assets\\photoproto.exe"=
"k:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"k:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"e:\\Program Files\\TmUnitedForever\\TmForever.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"k:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"k:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"k:\\Program Files\\Outspark\\Project Powder\\Run.exe"=
"l:\\Program Files\\Gumboy Tournament\\Gumboy Tournament.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"l:\\Program Files\\Microsoft Games\\MechWarrior Vengeance\\MW4.ICD"=
"l:\\Program Files\\Microsoft Games\\MechWarrior Vengeance\\mw4.exe"=
"c:\\xampp\\apache\\bin\\apache.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"l:\\Program Files\\TrackMania Sunrise\\TmSunrise.exe"=
"\\\\Loznice\\l\\Program Files\\TrackMania Sunrise\\TmSunrise.exe"=
"k:\\Program Files\\GameSpy\\Comrade\\Comrade.exe"=
"k:\\Program Files\\EA Games\\Mirror's Edge\\Binaries\\MirrorsEdge.exe"=
"k:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"k:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"k:\\Program Files\\Electronic Arts\\Burnout(TM) Paradise The Ultimate Box\\BurnoutLauncher.exe"=
"k:\\Program Files\\Electronic Arts\\Burnout(TM) Paradise The Ultimate Box\\BurnoutConfigTool.exe"=
"k:\\Program Files\\Electronic Arts\\Burnout(TM) Paradise The Ultimate Box\\BurnoutParadise.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"k:\\Program Files\\Activision\\Wolfenstein\\MP\\Wolf2MP.exe"=
"k:\\Program Files\\Activision\\Wolfenstein\\MP\\Wolf2MPLite.exe"=
"k:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"k:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"k:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"k:\\Program Files\\Steam\\Steam.exe"=
"l:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"l:\\Program Files\\Activision\\Call of Duty 5 - World at War\\CoDWaW.exe"=
"l:\\Program Files\\Activision\\Call of Duty 5 - World at War\\CoDWaWmp.exe"=
"k:\\Program Files\\Empire Interactive\\FlatOut Ultimate Carnage\\Fouc.exe"=
"l:\\Program Files\\Pinnacle\\Studio 11\\programs\\RM.exe"=
"l:\\Program Files\\Pinnacle\\Studio 11\\programs\\Studio.exe"=
"l:\\Program Files\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"=
"l:\\Program Files\\Pinnacle\\Studio 11\\programs\\umi.exe"=
"l:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"l:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"l:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"k:\\Program Files\\ICQ7.1\\ICQ.exe"=
"k:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"k:\\Program Files\\Steam\\steamapps\\common\\peggle extreme\\PeggleExtreme.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14174:TCP"= 14174:TCP:BitComet 14174 TCP
"14174:UDP"= 14174:UDP:BitComet 14174 UDP
"2710:TCP"= 2710:TCP:BitComet 2710 TCP
"2710:UDP"= 2710:UDP:BitComet 2710 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"49000:TCP"= 49000:TCP:azures
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"57508:TCP"= 57508:TCP:Pando Media Booster
"57508:UDP"= 57508:UDP:Pando Media Booster
"3306:TCP"= 3306:TCP:MySQL Server
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"1040:TCP"= 1040:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface

R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [1.3.2007 17:56 5248]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 14:46 63352]
R3 Mo3Fltr;MMO Mouse;c:\windows\system32\drivers\Mo3Fltr.sys [2.7.2010 12:38 11136]
S1 c4f7eb95;c4f7eb95;c:\windows\system32\drivers\c4f7eb95.sys --> c:\windows\system32\drivers\c4f7eb95.sys [?]
S1 prodrv03;Star Force copy protection driver v3;c:\windows\system32\drivers\prodrv03.sys [31.3.2008 17:02 115968]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [15.9.2009 11:42 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [15.9.2009 11:42 74480]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [17.8.2004 15:49 14336]
S2 dgdersvc;Device Error Recovery Service;c:\windows\system32\dgdersvc.exe [4.2.2010 13:00 95568]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [21.12.2007 8:21 468224]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [12.5.2010 14:04 217088]
S2 MySQL5;MySQL5;"c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt" --defaults-file="c:\program files\MySQL\MySQL Server 5.0\my.ini" MySQL5 --> c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt [?]
S2 RPCM;Remote Procedure Manager(TPM); [x]
S2 RPCT;Remote Procedure Call (TPM);c:\program files\Common Files\System\mstinit.exe --> c:\program files\Common Files\System\mstinit.exe [?]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu;l:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [12.1.2010 19:34 25832]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [4.2.2010 13:00 18136]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [12.5.2010 14:04 36640]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\ROMANK~1\LOCALS~1\Temp\VBU641.tmp --> c:\docume~1\ROMANK~1\LOCALS~1\Temp\VBU641.tmp [?]
S3 Love01;Love01;\??\e:\ivan\Love Engine0.3\Engine\Love Engine0.3\Loveliss.sys --> e:\ivan\Love Engine0.3\Engine\Love Engine0.3\Loveliss.sys [?]
S3 Ma730Pt;MA730 Bluetooth VCOM Driver;c:\windows\system32\drivers\ma730pt.sys [23.3.2007 20:18 102720]
S3 Ma730Vad;MA730 Bluetooth Audio;c:\windows\system32\drivers\Ma730Vad.sys [23.3.2007 20:18 23376]
S3 MySQL501;MySQL501;"k:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt" --defaults-file="k:\program files\MySQL\MySQL Server 5.0\my.ini" MySQL501 --> k:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt [?]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [1.5.2009 9:29 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [1.5.2009 9:29 8320]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [15.9.2009 11:42 7408]
S3 SetupNTGLM7X;SetupNTGLM7X; [x]
S3 SoRa01;SoRa01;\??\e:\ivan\Love Engine0.3\Engine\SoRa 2.6\SoRa.sys --> e:\ivan\Love Engine0.3\Engine\SoRa 2.6\SoRa.sys [?]
S3 syscom1;syscom1;\??\e:\ivan\ostatni\XTK2175\XTK2175.sys --> e:\ivan\ostatni\XTK2175\XTK2175.sys [?]
S3 tap0901_2gm;VPN Anonymizer Adapter;c:\windows\system32\drivers\tap0901_2gm.sys [21.6.2007 16:21 30720]
S3 XDva098;XDva098; [x]
S3 XDva143;XDva143;\??\c:\windows\system32\XDva143.sys --> c:\windows\system32\XDva143.sys [?]
S3 XDva189;XDva189;\??\c:\windows\system32\XDva189.sys --> c:\windows\system32\XDva189.sys [?]
S3 XDva195;XDva195;\??\c:\windows\system32\XDva195.sys --> c:\windows\system32\XDva195.sys [?]
S3 XDva207;XDva207;\??\c:\windows\system32\XDva207.sys --> c:\windows\system32\XDva207.sys [?]
S3 XDva208;XDva208;\??\c:\windows\system32\XDva208.sys --> c:\windows\system32\XDva208.sys [?]
S3 XDva281;XDva281;\??\c:\windows\system32\XDva281.sys --> c:\windows\system32\XDva281.sys [?]
S3 XDva344;XDva344;\??\c:\windows\system32\XDva344.sys --> c:\windows\system32\XDva344.sys [?]
S3 XDva347;XDva347;\??\c:\windows\system32\XDva347.sys --> c:\windows\system32\XDva347.sys [?]
S3 XDva349;XDva349;\??\c:\windows\system32\XDva349.sys --> c:\windows\system32\XDva349.sys [?]
S3 XDva351;XDva351;\??\c:\windows\system32\XDva351.sys --> c:\windows\system32\XDva351.sys [?]
S3 XDva352;XDva352;\??\c:\windows\system32\XDva352.sys --> c:\windows\system32\XDva352.sys [?]
S4 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [1.3.2007 17:56 159616]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9.3.2009 21:26 691696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'

2010-07-29 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 19:36]

2010-07-29 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 13:07]
.
.
------- Doplňkový sken -------
.
uStart Page = seznam.cz
mWindow Title = Microsoft Internet Explorer
uInternet Settings,ProxyOverride = local;*.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel
IE: Link to &MidpX - c:\program files\Kwyshell\MidpX\JadInvoker\Extent\jad_wrap.htm
IE: Subscribe in Desktop Sidebar - c:\program files\Desktop Sidebar\sbhelp.dll/menuhandler.html
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - k:\program files\ICQ7.1\ICQ.exe
TCP: {39202F08-1F8C-4236-B51E-00147A0BFA40} = 10.255.255.10,10.255.255.20
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

MSConfigStartUp-nwiz - nwiz.exe
AddRemove-01_Simmental - c:\program files\SAMSUNG\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\SAMSUNG\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\SAMSUNG\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\SAMSUNG\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-07_Schorl - c:\program files\SAMSUNG\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-09_Hsp - c:\program files\SAMSUNG\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\SAMSUNG\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-12_Symbian_USB_Download_Driver - c:\program files\SAMSUNG\USB Drivers\12_Symbian_USB_Download_Driver\Uninstall.exe
AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\program files\SAMSUNG\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\SAMSUNG\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-fc08-AT_ORF_MAIN - k:\program files\Football Challenge 2008 (ORF)\uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-29 16:16
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\ROMANK~1\LOCALS~1\Temp\VBU641.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mysql]
"ImagePath"="\"k:\downloads\wowcataalpha\Nová složka\Server\mysql\bin\mysqld-nt\" \"--defaults-file=k:\downloads\wowcataalpha\Nová složka\Server\mysql\bin\my.cnf\" mysql"

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MySQL5]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.0\my.ini\" MySQL5"

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MySQL501]
"ImagePath"="\"k:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"k:\program files\MySQL\MySQL Server 5.0\my.ini\" MySQL501"

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\l:\program files\CyberLink\PowerDVD\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1960408961-1979792683-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1960408961-1979792683-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:06,d5,39,22,1e,1e,a1,73,d1,9e,ee,bc,c5,bb,c5,b1,14,76,bb,7f,bf,88,6a,
93,d7,40,1f,14,32,94,9f,5e,7e,b3,d4,45,25,6f,1b,c1,4c,8c,61,b8,70,b4,23,90,\
"??"=hex:f0,20,e4,8a,f4,16,40,03,25,ec,bd,c9,5e,e6,25,ce

[HKEY_USERS\S-1-5-21-1960408961-1979792683-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:8d,a1,f9,56,69,c4,8f,d4,a7,e4,28,81,ba,c5,24,db,73,78,a8,24,67,
7c,67,a2,6f,9a,cb,9a,66,07,f6,0b,37,1d,ed,6c,dc,35,db,90,0f,3f,9b,72,63,70,\
"rkeysecu"=hex:19,e2,15,05,0e,15,8b,bc,dc,12,a0,93,53,f7,51,a4
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(288)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\program files\Stardock\Object Desktop\ThemeManager\fastload.dll
.
Celkový čas: 2010-07-29 16:19:27
ComboFix-quarantined-files.txt 2010-07-29 14:19

Před spuštěním: 2 151 452 672
Po spuštění: 2 146 127 872

- - End Of File - - 940907F84E3BE1D7F3B1090DD3A11357

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119418
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu :)

#6 Příspěvek od Rudy »

Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
Collect::
c:\windows\system32\E6599D5197.sys
c:\windows\system32\drivers\c4f7eb95.sys
c:\windows\system32\XDva143.sys
c:\windows\system32\XDva189.sys
c:\windows\system32\XDva195.sys
c:\windows\system32\XDva207.sys
c:\windows\system32\XDva208.sys
c:\windows\system32\XDva281.sys
c:\windows\system32\XDva344.sys
c:\windows\system32\XDva349.sys
c:\windows\system32\XDva351.sys
c:\windows\system32\XDva352.sys

Driver::
c4f7eb95
Akamai
XDva098
XDva143
XDva189
XDva195
XDva207
XDva208
XDva281
XDva344
XDva347
XDva349
XDva351
XDva352
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ivankrato
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 77
Registrován: 13 bře 2009 14:08

Re: Prosim o kontrolu :)

#7 Příspěvek od ivankrato »

Po aplikovani skriptu zase modra smrt, ale txt soubor se skriptem zmizel z plochy, tak se to mozna povedlo.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119418
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu :)

#8 Příspěvek od Rudy »

Mohl jste to provést v nouz. režimu. Mezi odstraňovanými soubory jsou rootkity, které musí bezpodmínečně ven.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ivankrato
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 77
Registrován: 13 bře 2009 14:08

Re: Prosim o kontrolu :)

#9 Příspěvek od ivankrato »

Tak jsem v nouzovem rezimu skript spustil znou, po dokonceni se PC restartoval, ale do normalniho rezimu, a kdyz to delalo log report, tak modra smrt.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119418
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu :)

#10 Příspěvek od Rudy »

Zřejmě je s něčím, co běží jen v norm. režimu v konfliktu. Podívejte se do C:\combofix.txt, zda je tam nový log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ivankrato
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 77
Registrován: 13 bře 2009 14:08

Re: Prosim o kontrolu :)

#11 Příspěvek od ivankrato »

Prave, ze tam neni

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119418
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu :)

#12 Příspěvek od Rudy »

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ivankrato
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 77
Registrován: 13 bře 2009 14:08

Re: Prosim o kontrolu :)

#13 Příspěvek od ivankrato »

Zejtra to jsem hodim, ted nemam moc casu :)

ivankrato
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 77
Registrován: 13 bře 2009 14:08

Re: Prosim o kontrolu :)

#14 Příspěvek od ivankrato »

Zde:

Autoscan: malfunction (events: 54, objects: 0, time: Unknown)
30.7.2010 13:23:09 Task started
30.7.2010 13:49:53 Detected: not-a-virus:AdWare.Win32.AdMedia.hb C:\Documents and Settings\Roman Kratochvíl\Plocha\wowmodelview-r682.zip/wowmodelview-r682/wowmodelview.exe
30.7.2010 13:49:54 Deleted: not-a-virus:AdWare.Win32.AdMedia.hb C:\Documents and Settings\Roman Kratochvíl\Plocha\wowmodelview-r682.zip/wowmodelview-r682/wowmodelview.exe
30.7.2010 13:49:54 Deleted: not-a-virus:AdWare.Win32.AdMedia.hb C:\Documents and Settings\Roman Kratochvíl\Plocha\wowmodelview-r682.zip/wowmodelview-r682/wowmodelview.exe
30.7.2010 14:05:48 Detected: HackTool.Win32.Sniffer.WpePro.u C:\Documents and Settings\Roman Kratochvíl\Local Settings\Data aplikací\Opera\Opera\profile\cache4\temporary_download\1HK (1).rar/wpeproalpha0_9a/WPE PRO.exe
30.7.2010 14:05:48 Untreated: HackTool.Win32.Sniffer.WpePro.u C:\Documents and Settings\Roman Kratochvíl\Local Settings\Data aplikací\Opera\Opera\profile\cache4\temporary_download\1HK (1).rar/wpeproalpha0_9a/WPE PRO.exe Write not supported
30.7.2010 14:05:48 Detected: HackTool.Win32.Sniffer.WpePro.u C:\Documents and Settings\Roman Kratochvíl\Local Settings\Data aplikací\Opera\Opera\profile\cache4\temporary_download\1HK (2).rar/wpeproalpha0_9a/WPE PRO.exe
30.7.2010 14:05:48 Untreated: HackTool.Win32.Sniffer.WpePro.u C:\Documents and Settings\Roman Kratochvíl\Local Settings\Data aplikací\Opera\Opera\profile\cache4\temporary_download\1HK (2).rar/wpeproalpha0_9a/WPE PRO.exe Write not supported
30.7.2010 14:05:49 Detected: HackTool.Win32.Sniffer.WpePro.w C:\Documents and Settings\Roman Kratochvíl\Local Settings\Data aplikací\Opera\Opera\profile\cache4\temporary_download\1HK (1).rar/wpeproalpha0_9a/WpeSpy.dll
30.7.2010 14:05:49 Untreated: HackTool.Win32.Sniffer.WpePro.w C:\Documents and Settings\Roman Kratochvíl\Local Settings\Data aplikací\Opera\Opera\profile\cache4\temporary_download\1HK (1).rar/wpeproalpha0_9a/WpeSpy.dll Write not supported
30.7.2010 14:05:49 Detected: HackTool.Win32.Sniffer.WpePro.w C:\Documents and Settings\Roman Kratochvíl\Local Settings\Data aplikací\Opera\Opera\profile\cache4\temporary_download\1HK (2).rar/wpeproalpha0_9a/WpeSpy.dll
30.7.2010 14:05:49 Untreated: HackTool.Win32.Sniffer.WpePro.w C:\Documents and Settings\Roman Kratochvíl\Local Settings\Data aplikací\Opera\Opera\profile\cache4\temporary_download\1HK (2).rar/wpeproalpha0_9a/WpeSpy.dll Write not supported
30.7.2010 14:06:10 Detected: HackTool.Win32.Sniffer.WpePro.u C:\Documents and Settings\Roman Kratochvíl\Local Settings\Data aplikací\Opera\Opera\profile\cache4\temporary_download\1HK.rar/wpeproalpha0_9a/WPE PRO.exe
30.7.2010 14:06:10 Untreated: HackTool.Win32.Sniffer.WpePro.u C:\Documents and Settings\Roman Kratochvíl\Local Settings\Data aplikací\Opera\Opera\profile\cache4\temporary_download\1HK.rar/wpeproalpha0_9a/WPE PRO.exe Write not supported
30.7.2010 14:06:11 Detected: HackTool.Win32.Sniffer.WpePro.w C:\Documents and Settings\Roman Kratochvíl\Local Settings\Data aplikací\Opera\Opera\profile\cache4\temporary_download\1HK.rar/wpeproalpha0_9a/WpeSpy.dll
30.7.2010 14:06:11 Untreated: HackTool.Win32.Sniffer.WpePro.w C:\Documents and Settings\Roman Kratochvíl\Local Settings\Data aplikací\Opera\Opera\profile\cache4\temporary_download\1HK.rar/wpeproalpha0_9a/WpeSpy.dll Write not supported
30.7.2010 16:16:50 Detected: Trojan-Downloader.Win32.Agent.dkvi C:\Program Files\DDD Pool\DDDPool.exe
30.7.2010 16:17:43 Deleted: Trojan-Downloader.Win32.Agent.dkvi C:\Program Files\DDD Pool\DDDPool.exe
30.7.2010 16:17:52 Detected: Trojan-PSW.Win32.VB.bur C:\Program Files\DsNET Corp\aTube Catcher 1.0\atc_lvr.exe
30.7.2010 16:17:55 Deleted: Trojan-PSW.Win32.VB.bur C:\Program Files\DsNET Corp\aTube Catcher 1.0\atc_lvr.exe
30.7.2010 16:23:07 Detected: Trojan-Dropper.Win32.Delf.eiw C:\Program Files\Lavasoft\Ad-Aware 2007\HostFileEditor.exe
30.7.2010 16:23:22 Deleted: Trojan-Dropper.Win32.Delf.eiw C:\Program Files\Lavasoft\Ad-Aware 2007\HostFileEditor.exe
30.7.2010 16:23:23 Detected: Trojan-Dropper.Win32.Delf.eix C:\Program Files\Lavasoft\Ad-Aware 2007\ProcessWatch.exe
30.7.2010 16:23:25 Deleted: Trojan-Dropper.Win32.Delf.eix C:\Program Files\Lavasoft\Ad-Aware 2007\ProcessWatch.exe
30.7.2010 16:23:25 Detected: Trojan-Dropper.Win32.Delf.epx C:\Program Files\Lavasoft\Ad-Aware 2007\update-cracked.exe/Armadillo
30.7.2010 16:23:26 Deleted: Trojan-Dropper.Win32.Delf.epx C:\Program Files\Lavasoft\Ad-Aware 2007\update-cracked.exe
30.7.2010 16:32:51 Detected: Trojan-Downloader.Win32.Agent.dkvi C:\System Volume Information\_restore{C082CFA3-7390-455D-B208-AD495427FA6E}\RP199\A0203487.exe
30.7.2010 16:32:51 Detected: Trojan-PSW.Win32.VB.bur C:\System Volume Information\_restore{C082CFA3-7390-455D-B208-AD495427FA6E}\RP199\A0203488.exe
30.7.2010 16:33:01 Deleted: Trojan-Downloader.Win32.Agent.dkvi C:\System Volume Information\_restore{C082CFA3-7390-455D-B208-AD495427FA6E}\RP199\A0203487.exe
30.7.2010 16:33:02 Deleted: Trojan-PSW.Win32.VB.bur C:\System Volume Information\_restore{C082CFA3-7390-455D-B208-AD495427FA6E}\RP199\A0203488.exe
30.7.2010 16:33:03 Detected: Trojan-Dropper.Win32.Delf.eiw C:\System Volume Information\_restore{C082CFA3-7390-455D-B208-AD495427FA6E}\RP199\A0203489.exe
30.7.2010 16:33:03 Detected: Trojan-Dropper.Win32.Delf.eix C:\System Volume Information\_restore{C082CFA3-7390-455D-B208-AD495427FA6E}\RP199\A0203490.exe
30.7.2010 16:33:04 Deleted: Trojan-Dropper.Win32.Delf.eiw C:\System Volume Information\_restore{C082CFA3-7390-455D-B208-AD495427FA6E}\RP199\A0203489.exe
30.7.2010 16:33:05 Detected: Trojan-Dropper.Win32.Delf.epx C:\System Volume Information\_restore{C082CFA3-7390-455D-B208-AD495427FA6E}\RP199\A0203491.exe/Armadillo
30.7.2010 16:33:05 Deleted: Trojan-Dropper.Win32.Delf.eix C:\System Volume Information\_restore{C082CFA3-7390-455D-B208-AD495427FA6E}\RP199\A0203490.exe
30.7.2010 16:33:08 Deleted: Trojan-Dropper.Win32.Delf.epx C:\System Volume Information\_restore{C082CFA3-7390-455D-B208-AD495427FA6E}\RP199\A0203491.exe
30.7.2010 18:37:40 Detected: Trojan-Dropper.Win32.Delf.eiw K:\AVG\Adware 2007\ad-aware-2007-pro.rar/crack/HostFileEditor.exe
30.7.2010 18:37:40 Untreated: Trojan-Dropper.Win32.Delf.eiw K:\AVG\Adware 2007\ad-aware-2007-pro.rar/crack/HostFileEditor.exe Write not supported
30.7.2010 18:38:10 Detected: Trojan-Dropper.Win32.Delf.eix K:\AVG\Adware 2007\ad-aware-2007-pro.rar/crack/ProcessWatch.exe
30.7.2010 18:38:10 Untreated: Trojan-Dropper.Win32.Delf.eix K:\AVG\Adware 2007\ad-aware-2007-pro.rar/crack/ProcessWatch.exe Write not supported
30.7.2010 18:38:15 Detected: Trojan-Dropper.Win32.Delf.epx K:\AVG\Adware 2007\ad-aware-2007-pro.rar/crack/update-cracked.exe/Armadillo
30.7.2010 18:38:15 Untreated: Trojan-Dropper.Win32.Delf.epx K:\AVG\Adware 2007\ad-aware-2007-pro.rar/crack/update-cracked.exe/Armadillo Write not supported
30.7.2010 20:52:03 Detected: Trojan-GameThief.Win32.Magania.dnjq K:\Program Files\MumboJumbo\Equilibria\equilibria.exe
30.7.2010 20:52:49 Deleted: Trojan-GameThief.Win32.Magania.dnjq K:\Program Files\MumboJumbo\Equilibria\equilibria.exe
30.7.2010 21:26:46 Detected: Trojan-GameThief.Win32.Magania.dnjq K:\System Volume Information\_restore{C082CFA3-7390-455D-B208-AD495427FA6E}\RP199\A0203504.exe
30.7.2010 21:26:55 Deleted: Trojan-GameThief.Win32.Magania.dnjq K:\System Volume Information\_restore{C082CFA3-7390-455D-B208-AD495427FA6E}\RP199\A0203504.exe
30.7.2010 21:32:37 Detected: Trojan-Dropper.Win32.Delf.eiw L:\Kratas\ad-aware-2007-pro.rar/crack/HostFileEditor.exe
30.7.2010 21:32:37 Untreated: Trojan-Dropper.Win32.Delf.eiw L:\Kratas\ad-aware-2007-pro.rar/crack/HostFileEditor.exe Write not supported
30.7.2010 21:32:59 Detected: Trojan-Dropper.Win32.Delf.eix L:\Kratas\ad-aware-2007-pro.rar/crack/ProcessWatch.exe
30.7.2010 21:32:59 Untreated: Trojan-Dropper.Win32.Delf.eix L:\Kratas\ad-aware-2007-pro.rar/crack/ProcessWatch.exe Write not supported
30.7.2010 21:33:11 Detected: Trojan-Dropper.Win32.Delf.epx L:\Kratas\ad-aware-2007-pro.rar/crack/update-cracked.exe/Armadillo
30.7.2010 21:33:11 Untreated: Trojan-Dropper.Win32.Delf.epx L:\Kratas\ad-aware-2007-pro.rar/crack/update-cracked.exe/Armadillo Write not supported
30.7.2010 21:45:21 Detected: not-a-virus:AdWare.Win32.AdMedia.hb L:\Program Files\wowmodelview-r682.rar/wowmodelview-r682/wowmodelview.exe
30.7.2010 21:45:21 Untreated: not-a-virus:AdWare.Win32.AdMedia.hb L:\Program Files\wowmodelview-r682.rar/wowmodelview-r682/wowmodelview.exe Write not supported

Bohuzel zitra odjizdime na dovolenou, takze tu tyden nebudu.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119418
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu :)

#15 Příspěvek od Rudy »

Bylo toho tam požehnaně, ale vše AVP smazal.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět