Logfile of random's system information tool 1.09 (written by random/random) Run by uzivatel at 2013-02-27 18:48:43 Microsoft® Windows Vista™ Home Premium Service Pack 2 System drive C: has 51 GB (21%) free of 238 GB Total RAM: 2046 MB (47% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 18:49:03, on 27.2.2013 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v9.00 (9.00.8112.16464) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Users\uzivatel\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\uzivatel\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\uzivatel\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\uzivatel\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\uzivatel\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\uzivatel\Downloads\RSIT.exe C:\Program Files\trend micro\uzivatel.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - - (no file) O1 - Hosts: ˙ţ127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKUS\S-1-5-21-3314771282-3977894261-815355269-1001\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'UpdatusUser') O4 - HKUS\S-1-5-21-3314771282-3977894261-815355269-1001\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'UpdatusUser') O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe O9 - Extra button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- End of file - 5875 bytes =========Mozilla firefox========= ProfilePath - C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\ovv1ht79.default "{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ "wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 11.6.602.168 Plugin "Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_168.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.10.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Windows\system32\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0] "Description"=Office Authorization plug-in for NPAPI browsers "Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] "Description"=Microsoft SharePoint Plug-in for Firefox "Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5] "Description"=Windows Presentation Foundation plug-in for Mozilla browsers "Path"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin] "Description"=This plugin detects and launches Pando Media Booster "Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.2] "Description"=VLC Multimedia Plugin "Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll C:\Program Files\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} C:\Program Files\Mozilla Firefox\components\ binary.manifest browsercomps.dll flashplayer.xpt C:\Program Files\Mozilla Firefox\plugins\ np-mswmp.dll nppdf32.dll WMP Firefox Plugin License.rtf WMP Firefox Plugin RelNotes.txt C:\Program Files\Mozilla Firefox\searchplugins\ google.xml heureka-cz.xml jyxo-cz.xml seznam-cz.xml slunecnice-cz.xml wikipedia-cz.xml yahoo.xml C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\ovv1ht79.default\extensions\ {ea614400-e918-4741-9a97-7a972ff7c30b} C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\ovv1ht79.default\searchplugins\ icqplugin-4.xml ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-01-11 460712] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-03-07 1003704] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 561552] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-03-07 4241512] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-10 1233920] "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-18 202240] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent] C:\Program Files\uTorrent\uTorrent.exe [2012-06-29 880496] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^uzivatel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.0.lnk] C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe [] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableUIADesktopToggle"=0 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDrives"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "BindDirectlyToPropertySetStorage"=0 "NoDrives"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "vidc.uyvy"=msyuv.dll "vidc.yuy2"=msyuv.dll "vidc.yvyu"=msyuv.dll "vidc.iyuv"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "vidc.yvu9"=iyvu9_32.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "vidc.cvid"=iccvid.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux1"=wdmaud.drv "vidc.iv50"=ir50_32.dll "vidc.iv41"=ir41_32.ax "vidc.iv31"=ir32_32.dll "vidc.iv32"=ir32_32.dll "VIDC.FPS1"=frapsvid.dll ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .scr - open - C:\Windows\system32\notepad.exe "%1" .scr - install - .scr - config - ======List of files/folders created in the last 1 month====== 2013-02-27 11:11:56 ----D---- C:\Users\uzivatel\AppData\Roaming\LolClient 2013-02-26 22:53:14 ----D---- C:\Users\uzivatel\AppData\Roaming\ICQ 2013-02-26 22:15:14 ----D---- C:\_OTL 2013-02-26 22:07:49 ----D---- C:\Windows\temp 2013-02-26 22:07:46 ----A---- C:\ComboFix.txt 2013-02-26 22:01:05 ----D---- C:\$RECYCLE.BIN 2013-02-26 22:00:07 ----ASH---- C:\hiberfil.sys 2013-02-26 21:35:24 ----A---- C:\Windows\ntbtlog.txt 2013-02-26 20:05:50 ----D---- C:\Windows\pss 2013-02-25 17:46:41 ----A---- C:\Windows\zip.exe 2013-02-25 17:46:41 ----A---- C:\Windows\SWSC.exe 2013-02-25 17:46:41 ----A---- C:\Windows\SWREG.exe 2013-02-25 17:46:41 ----A---- C:\Windows\sed.exe 2013-02-25 17:46:41 ----A---- C:\Windows\PEV.exe 2013-02-25 17:46:41 ----A---- C:\Windows\NIRCMD.exe 2013-02-25 17:46:41 ----A---- C:\Windows\MBR.exe 2013-02-25 17:46:41 ----A---- C:\Windows\grep.exe 2013-02-25 17:46:28 ----D---- C:\Qoobox 2013-02-25 17:45:58 ----D---- C:\Windows\erdnt 2013-02-24 20:11:38 ----D---- C:\Users\uzivatel\AppData\Roaming\Malwarebytes 2013-02-24 20:11:22 ----D---- C:\ProgramData\Malwarebytes 2013-02-24 20:11:19 ----D---- C:\Program Files\Malwarebytes' Anti-Malware 2013-02-24 20:11:19 ----A---- C:\Windows\system32\drivers\mbam.sys 2013-02-24 19:46:37 ----A---- C:\AdwCleaner[S1].txt 2013-02-24 17:45:38 ----D---- C:\Program Files\trend micro 2013-02-24 17:45:37 ----D---- C:\rsit 2013-02-17 12:28:00 ----A---- C:\Windows\system32\nvopencl.dll 2013-02-17 12:28:00 ----A---- C:\Windows\system32\nvoglv32.dll 2013-02-17 12:28:00 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys 2013-02-17 12:27:58 ----A---- C:\Windows\system32\nvcuvid.dll 2013-02-17 12:27:58 ----A---- C:\Windows\system32\nvcuvenc.dll 2013-02-17 12:27:58 ----A---- C:\Windows\system32\nvcuda.dll 2013-02-17 12:27:57 ----A---- C:\Windows\system32\nvcompiler.dll 2013-02-15 22:07:36 ----D---- C:\Program Files\FlatOut2 2013-02-14 23:43:56 ----A---- C:\Windows\system32\mshtmled.dll 2013-02-14 23:43:55 ----A---- C:\Windows\system32\vbscript.dll 2013-02-14 23:43:55 ----A---- C:\Windows\system32\jsproxy.dll 2013-02-14 23:43:55 ----A---- C:\Windows\system32\ieui.dll 2013-02-14 23:43:54 ----A---- C:\Windows\system32\msfeeds.dll 2013-02-14 23:43:54 ----A---- C:\Windows\system32\ieUnatt.exe 2013-02-14 23:43:53 ----A---- C:\Windows\system32\wininet.dll 2013-02-14 23:43:53 ----A---- C:\Windows\system32\jscript.dll 2013-02-14 23:43:52 ----A---- C:\Windows\system32\url.dll 2013-02-14 23:43:52 ----A---- C:\Windows\system32\jscript9.dll 2013-02-14 23:43:51 ----A---- C:\Windows\system32\iertutil.dll 2013-02-14 23:43:50 ----A---- C:\Windows\system32\urlmon.dll 2013-02-14 23:43:48 ----A---- C:\Windows\system32\mshtml.dll 2013-02-14 23:43:46 ----A---- C:\Windows\system32\ieframe.dll 2013-02-14 07:50:58 ----A---- C:\Windows\system32\win32k.sys 2013-02-14 07:50:56 ----A---- C:\Windows\system32\quartz.dll 2013-02-14 07:50:54 ----A---- C:\Windows\system32\drivers\tcpip.sys 2013-02-14 07:50:50 ----A---- C:\Windows\system32\ntoskrnl.exe 2013-02-14 07:50:50 ----A---- C:\Windows\system32\ntkrnlpa.exe 2013-02-13 20:06:58 ----D---- C:\Program Files\YTD Toolbar 2013-02-02 17:59:51 ----D---- C:\Program Files\Microsoft 2013-02-02 17:59:06 ----D---- C:\Windows\system32\directx ======List of files/folders modified in the last 1 month====== 2013-02-27 18:48:57 ----D---- C:\Windows\Prefetch 2013-02-27 18:44:31 ----D---- C:\Windows\system32\drivers\etc 2013-02-27 18:31:07 ----D---- C:\Windows\system32\drivers 2013-02-27 16:55:40 ----SHD---- C:\System Volume Information 2013-02-27 16:13:15 ----SHD---- C:\Windows\Installer 2013-02-27 16:13:02 ----D---- C:\ProgramData\Microsoft Help 2013-02-26 22:15:19 ----D---- C:\Windows 2013-02-26 22:01:27 ----A---- C:\Windows\system.ini 2013-02-26 21:55:07 ----D---- C:\Windows\Tasks 2013-02-26 21:47:56 ----D---- C:\Windows\System32 2013-02-26 21:47:56 ----D---- C:\Windows\AppPatch 2013-02-26 21:47:55 ----D---- C:\Program Files\Common Files 2013-02-26 19:58:20 ----D---- C:\Users\uzivatel\AppData\Roaming\uTorrent 2013-02-26 14:22:27 ----SD---- C:\ProgramData\Microsoft 2013-02-26 12:05:51 ----D---- C:\ProgramData\Skype 2013-02-26 12:05:46 ----D---- C:\Program Files 2013-02-26 12:05:38 ----D---- C:\Users\uzivatel\AppData\Roaming\Skype 2013-02-26 12:04:38 ----RSD---- C:\Windows\assembly 2013-02-26 12:04:34 ----D---- C:\Program Files\OpenOffice.org 2.0 2013-02-26 11:58:32 ----D---- C:\Program Files\EA Games 2013-02-25 22:25:08 ----D---- C:\Windows\system32\Tasks 2013-02-25 22:16:14 ----D---- C:\Users\uzivatel\AppData\Roaming\vlc 2013-02-25 18:02:32 ----SD---- C:\Windows\Downloaded Program Files 2013-02-25 10:40:35 ----D---- C:\Program Files\Pando Networks 2013-02-25 10:22:18 ----D---- C:\ProgramData 2013-02-25 10:20:45 ----D---- C:\Program Files\QIP 2013-02-25 10:03:30 ----D---- C:\Windows\system32\WDI 2013-02-24 22:22:35 ----D---- C:\Users\uzivatel\AppData\Roaming\OpenOffice.org2 2013-02-24 19:46:49 ----D---- C:\ProgramData\ICQ 2013-02-24 13:53:57 ----D---- C:\Windows\Debug 2013-02-24 11:14:30 ----D---- C:\Windows\system32\catroot2 2013-02-23 22:05:22 ----A---- C:\Windows\system32\FlashPlayerApp.exe 2013-02-23 22:04:43 ----D---- C:\ProgramData\Adobe 2013-02-21 20:39:42 ----D---- C:\Program Files\SystemRequirementsLab 2013-02-18 12:21:18 ----D---- C:\Windows\inf 2013-02-18 12:21:18 ----A---- C:\Windows\system32\PerfStringBackup.INI 2013-02-18 09:53:21 ----D---- C:\ProgramData\YTD Video Downloader 2013-02-17 12:32:50 ----D---- C:\ProgramData\NVIDIA 2013-02-17 12:30:09 ----D---- C:\Windows\system32\catroot 2013-02-15 15:37:23 ----D---- C:\Program Files\Steam 2013-02-15 15:25:03 ----D---- C:\Program Files\Common Files\InstallShield 2013-02-15 15:24:16 ----HD---- C:\Program Files\InstallShield Installation Information 2013-02-15 10:56:30 ----D---- C:\Windows\Microsoft.NET 2013-02-15 09:45:05 ----D---- C:\Windows\system32\migration 2013-02-15 09:45:05 ----D---- C:\Program Files\Internet Explorer 2013-02-14 23:46:10 ----A---- C:\Windows\system32\mrt.exe 2013-02-14 23:45:27 ----D---- C:\Windows\winsxs 2013-02-03 11:17:50 ----D---- C:\Windows\system32\NDF ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-03-12 691696] R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2012-03-07 24408] R1 AswRdr;aswRdr; C:\Windows\system32\drivers\AswRdr.sys [2012-03-07 35672] R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-03-07 612184] R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-03-07 337880] R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-03-07 53848] R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2009-11-09 59388] R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-03-07 20696] R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-03-07 57688] R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2006-09-19 298496] R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2012-12-14 21104] R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810] R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2013-01-03 10919864] R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-02 44544] R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560] R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136] S3 a6mbvdbb;a6mbvdbb; C:\Windows\system32\drivers\a6mbvdbb.sys [] S3 afhrqjm3;afhrqjm3; C:\Windows\system32\drivers\afhrqjm3.sys [] S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-18 5632] S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-10 236544] S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 8192] S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-18 5888] S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-18 5504] S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-18 6016] S3 usbaudio;Ovladač zvuků USB (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-10 73216] S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-18 35328] S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192] R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-03-07 44768] R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-18 21504] R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344] R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184] R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-01-03 634808] R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-01-03 1259448] R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2012-07-15 66872] R2 PnkBstrB;PnkBstrB; C:\Windows\system32\PnkBstrB.exe [2012-07-15 107832] R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688] R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728] S2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2012-03-07 134920] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-02-18 651720] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352] S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000] S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] -----------------EOF-----------------