Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

procesor na 100 (kontrola logu)

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
J0ZO
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2010 16:01

procesor na 100 (kontrola logu)

#1 Příspěvek od J0ZO »

mam procesor na 100 percent a neviem co s tym
Stalo sa mi to potom ako som si prezeral stranku na nete (tusim nejaky eshop) a zrazu mi na chvilu seklo PC (notebook) a objavila sa mi pracovna plocha ciernobiela s minimalnym rozlisenim.... Ked som to zmenil. Celi PC zamrzol a musel som ho restartovat.
Potom mi zacal poriadne hucat a ked som zapol spravcu uloh mal som tam procesor na 80-100 percent a dole to neslo
skusal som vsetko antivirak, spyware doctor, ccleaner, preinstaloval som aj zalohovane ovladace na pc ktore som nedavno aktualizoval, raz mi to po restartovani bezalo normalne (mal som to tak na 20 ked som pracoval s internetom)
a potom mi to zase zacalo robyt.

prosim pomozte mi nejako lebo mi neide nic (aj hudba mi seka) google by mi mozno aj pomohol ale musel by som hladat velmi dlho a nasiel som na nom vas :)
takze tu vam dam Logfile a ak mi pomozete budem vam velmi vdacny.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:51:54, on 24. 9. 2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\ATKGFNEX\GFNEXSrv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Luidia\eBeam Device Service\eBeamDeviceServiceMain.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\ifxspmgt.exe
C:\WINDOWS\system32\ifxtcs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\IfxPsdSv.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
C:\Program Files\Luidia\eBeam Device Service\eBeamDeviceServiceUI.exe
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
C:\Program Files\P4P\P4P.exe
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\WINDOWS\ASScrPro.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Atheros\ACU.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\WINDOWS\system32\ACEngSvr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Infineon\Security Platform Software\PSDrt.exe
C:\Program Files\Infineon\Security Platform Software\SpTna.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\system32\acovcnt.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ATK Hotkey\KBFiltr.exe
C:\Program Files\ATK Hotkey\WDC.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashQuick.exe
E:\Jozko\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.azet.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\PROGRA~1\IDM\QUICKF~1\PlugIns\IEHelp.dll
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O2 - BHO: ASUS Security Protect Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ATKHOTKEY] "C:\Program Files\ATK Hotkey\Hcontrol.exe"
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [IFXSPMGT] C:\WINDOWS\system32\ifxspmgt.exe /NotifyLogon
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [PowerForPhone] "C:\Program Files\P4P\P4P.exe"
O4 - HKLM\..\Run: [ACMON] "C:\Program Files\ASUS\Splendid\ACMON.exe"
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\WINDOWS\ASScrProlog.exe
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\WINDOWS\ASScrPro.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
O4 - HKLM\..\Run: [Wireless Console 2] "C:\Program Files\Wireless Console 2\wcourier.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [NortonUpdateAgent] C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: monmvr32.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: APSHook.dll
O20 - Winlogon Notify: OneCard - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
O23 - Service: Atheros Configuration Service (ACS) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eBeam Device Service - Luidia, Inc. - C:\Program Files\Luidia\eBeam Device Service\eBeamDeviceServiceMain.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\WINDOWS\system32\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\WINDOWS\system32\ifxtcs.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Lavasoft Ad-Aware Service - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\WINDOWS\system32\IfxPsdSv.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

--
End of file - 14889 bytes

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: procesor na 100 (kontrola logu)

#2 Příspěvek od Rudy »

Dejte log z RSIT: http://viry.cz/forum/viewtopic.php?f=24&t=81939 . Je podrobnější, než HijackThis.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

J0ZO
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2010 16:01

Re: procesor na 100 (kontrola logu)

#3 Příspěvek od J0ZO »

avast mi vzdy ked sa prihlasim hlasi malware
///uz sa mi to podarilo znizit ale stale to sem tam vyskoci na 80
tak tu je ten logfile:


Logfile of random's system information tool 1.08 (written by random/random)
Run by jozko at 2010-09-24 18:59:38
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 9 GB (9%) free of 100 GB
Total RAM: 2039 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:00:37, on 24. 9. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\ATKGFNEX\GFNEXSrv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Luidia\eBeam Device Service\eBeamDeviceServiceMain.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\ifxspmgt.exe
C:\WINDOWS\system32\ifxtcs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\IfxPsdSv.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Luidia\eBeam Device Service\eBeamDeviceServiceUI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
C:\Program Files\P4P\P4P.exe
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\WINDOWS\ASScrPro.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ATK Hotkey\KBFiltr.exe
C:\WINDOWS\system32\ACEngSvr.exe
C:\Program Files\ATK Hotkey\WDC.exe
C:\Program Files\Atheros\ACU.exe
C:\Program Files\Infineon\Security Platform Software\PSDrt.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\Infineon\Security Platform Software\SpTna.exe
C:\WINDOWS\system32\acovcnt.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\Jozko\rr2\RSIT.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\trend micro\jozko.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.azet.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\PROGRA~1\IDM\QUICKF~1\PlugIns\IEHelp.dll
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O2 - BHO: ASUS Security Protect Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ATKHOTKEY] "C:\Program Files\ATK Hotkey\Hcontrol.exe"
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [IFXSPMGT] C:\WINDOWS\system32\ifxspmgt.exe /NotifyLogon
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [PowerForPhone] "C:\Program Files\P4P\P4P.exe"
O4 - HKLM\..\Run: [ACMON] "C:\Program Files\ASUS\Splendid\ACMON.exe"
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\WINDOWS\ASScrProlog.exe
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\WINDOWS\ASScrPro.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
O4 - HKLM\..\Run: [Wireless Console 2] "C:\Program Files\Wireless Console 2\wcourier.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [NortonUpdateAgent] C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: APSHook.dll
O20 - Winlogon Notify: OneCard - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Atheros Configuration Service (ACS) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eBeam Device Service - Luidia, Inc. - C:\Program Files\Luidia\eBeam Device Service\eBeamDeviceServiceMain.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\WINDOWS\system32\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\WINDOWS\system32\ifxtcs.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Lavasoft Ad-Aware Service - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\WINDOWS\system32\IfxPsdSv.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

--
End of file - 15364 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Jozef.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - C:\Program Files\ICQToolbar\toolbaru.dll [2006-12-25 701952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}]
C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll [2007-01-15 96936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-07-14 278192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll [2010-09-01 842296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C08DF07A-3E49-4E25-9AB0-D3882835F153}]
QUICKfind BHO Object - C:\PROGRA~1\IDM\QUICKF~1\PlugIns\IEHelp.dll [2003-06-30 337920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF21F1DB-80C6-11D3-9483-B03D0EC10000}]
ASUS Security Protect Manager - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll [2006-11-24 70928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{90222687-F593-4738-B738-FBEE9C7B26DF} - Show Norton Toolbar - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll [2007-01-15 607888]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-07-14 278192]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATKHOTKEY"=C:\Program Files\ATK Hotkey\Hcontrol.exe [2007-06-29 225280]
"ATKOSD2"=C:\Program Files\ATKOSD2\ATKOSD2.exe [2007-07-03 7708672]
"SMSERIAL"=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2006-08-10 573440]
"IntelZeroConfig"=C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [2007-06-01 823296]
"IntelWireless"=C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [2007-06-01 974848]
"CognizanceTS"=C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll [2003-12-24 17920]
"IFXSPMGT"=C:\WINDOWS\system32\ifxspmgt.exe [2007-03-04 677408]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2006-10-15 815104]
"ATKMEDIA"=C:\Program Files\ASUS\ATK Media\DMEDIA.EXE [2006-11-02 61440]
"Power_Gear"=C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe [2006-07-26 90112]
"PowerForPhone"=C:\Program Files\P4P\P4P.exe [2007-07-19 778240]
"ACMON"=C:\Program Files\ASUS\Splendid\ACMON.exe [2007-06-26 851968]
"ASUS Camera ScreenSaver"=C:\WINDOWS\ASScrProlog.exe [2008-06-30 37232]
"ASUS Screen Saver Protector"=C:\WINDOWS\ASScrPro.exe [2008-06-30 33136]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2007-01-13 115816]
"osCheck"=C:\Program Files\Norton Internet Security\osCheck.exe [2007-01-17 771704]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"ACU"=C:\Program Files\Atheros\ACU.exe [2007-10-16 405593]
"Wireless Console 2"=C:\Program Files\Wireless Console 2\wcourier.exe [2007-07-05 1040384]
"Symantec PIF AlertEng"=C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [2008-01-29 583048]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-01-05 413696]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2010-09-03 19573352]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2010-01-13 134656]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2010-01-13 166912]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2010-01-13 135680]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-11-17 39408]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-05-13 26192168]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-01-05 413696]
"NortonUpdateAgent"=C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe [2010-09-07 1819504]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe

C:\Documents and Settings\jozko\Start Menu\Programs\Startup
PowerReg Scheduler V3.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="APSHook.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2010-01-13 205824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\OneCard]
C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll [2007-02-09 74240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
ASWLNPkg

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQLite\ICQLite.exe"="C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite"
"C:\Program Files\EA Games\The Battle for Middle-earth (tm)\game.dat"="C:\Program Files\EA Games\The Battle for Middle-earth (tm)\game.dat:*:Enabled:The Battle for Middle-earth (tm)"
"C:\Program Files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat"="C:\Program Files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Electronic Arts\The Lord of the Rings, The Rise of the Witch-king\game.dat"="C:\Program Files\Electronic Arts\The Lord of the Rings, The Rise of the Witch-king\game.dat:*:Enabled:The Lord of the Rings, The Rise of the Witch-king"
"C:\Documents and Settings\Deti\Local Settings\Application Data\Skype\Phone\Skype.exe"="C:\Documents and Settings\Deti\Local Settings\Application Data\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\UBISOFT\Assassin's Creed\AssassinsCreed_Dx9.exe"="C:\Program Files\UBISOFT\Assassin's Creed\AssassinsCreed_Dx9.exe:*:Enabled:Assassin's Creed Dx9"
"C:\Program Files\UBISOFT\Assassin's Creed\AssassinsCreed_Dx10.exe"="C:\Program Files\UBISOFT\Assassin's Creed\AssassinsCreed_Dx10.exe:*:Enabled:Assassin's Creed Dx10"
"C:\Program Files\UBISOFT\Assassin's Creed\AssassinsCreed_Launcher.exe"="C:\Program Files\UBISOFT\Assassin's Creed\AssassinsCreed_Launcher.exe:*:Enabled:Assassin's Creed Update"
"C:\Program Files\UBISOFT\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="C:\Program Files\UBISOFT\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-09-24 19:00:29 ----D---- C:\Program Files\trend micro
2010-09-24 18:59:38 ----D---- C:\rsit
2010-09-24 18:55:07 ----A---- C:\WINDOWS\OEWABLog.txt
2010-09-24 18:54:02 ----D---- C:\WINDOWS\Prefetch
2010-09-24 18:50:55 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-09-24 18:50:44 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-09-24 18:50:26 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-09-24 18:50:15 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-09-24 18:50:04 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-09-24 18:49:53 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-09-24 18:49:41 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-09-24 18:49:30 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-09-24 18:49:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-09-24 18:49:08 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-09-24 18:48:55 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-09-24 18:48:43 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-09-24 18:48:29 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-09-24 18:48:14 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
2010-09-24 18:47:56 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-09-24 18:47:47 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-09-24 18:47:35 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-09-24 18:47:24 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-09-24 18:47:13 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-09-24 18:47:03 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-09-24 18:46:50 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-09-24 18:46:39 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-09-24 18:46:29 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-09-24 18:46:16 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-09-24 18:46:05 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-09-24 18:45:54 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-09-24 18:45:41 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-09-24 18:45:31 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-09-24 18:45:19 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-09-24 18:45:06 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-09-24 18:44:54 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-09-24 18:44:44 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2010-09-24 18:44:33 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2010-09-24 18:44:19 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2010-09-24 18:44:06 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-09-24 18:43:54 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-09-24 18:43:42 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-09-24 18:43:32 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-09-24 18:43:18 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-09-24 18:43:07 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2010-09-24 18:42:53 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-09-24 18:42:42 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-09-24 18:42:29 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-09-24 18:42:18 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2010-09-24 18:42:07 ----HDC---- C:\WINDOWS\$NtUninstallKB961371$
2010-09-24 18:41:48 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-09-24 18:41:38 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-09-24 18:41:28 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-09-24 18:41:12 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-09-24 18:41:02 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-09-24 18:40:50 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2010-09-24 18:40:40 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2010-09-24 18:40:28 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-09-24 18:40:16 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2010-09-24 18:40:05 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2010-09-24 18:39:55 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-09-24 18:39:43 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2010-09-24 18:39:32 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-09-24 18:39:21 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-09-24 18:39:03 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-09-24 18:38:46 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-09-24 18:38:35 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2010-09-24 18:38:25 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-09-24 18:38:14 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_1$
2010-09-24 18:38:05 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2010-09-24 18:37:53 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2010-09-24 18:37:42 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-09-24 18:37:31 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-09-24 18:37:18 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-09-24 18:37:05 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-09-24 18:36:55 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2010-09-24 18:36:45 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-09-24 18:36:33 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2010-09-24 18:36:23 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-09-24 18:36:12 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-09-24 18:36:00 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-09-24 18:35:51 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2010-09-24 18:35:38 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-09-24 18:35:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2010-09-24 18:35:21 ----D---- C:\WINDOWS\LastGood.Tmp
2010-09-24 18:31:50 ----A---- C:\WINDOWS\setuplog.txt
2010-09-24 18:30:19 ----D---- C:\WINDOWS\system32\scripting
2010-09-24 18:30:19 ----D---- C:\WINDOWS\l2schemas
2010-09-24 18:30:17 ----D---- C:\WINDOWS\system32\en
2010-09-24 18:30:17 ----D---- C:\WINDOWS\system32\bits
2010-09-24 18:21:44 ----D---- C:\WINDOWS\network diagnostic
2010-09-24 18:15:31 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-09-24 16:30:25 ----A---- C:\WINDOWS\system32\acovcnt.exe
2010-09-23 17:55:15 ----D---- C:\WINDOWS\system32\x64
2010-09-23 16:43:35 ----D---- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2010-09-23 16:42:40 ----D---- C:\Program Files\Security Task Manager
2010-09-22 21:44:31 ----D---- C:\WINDOWS\pss
2010-09-21 21:47:11 ----A---- C:\WINDOWS\system32\drivers\qqifxh.sys
2010-09-18 12:29:19 ----A---- C:\WINDOWS\system32\RicohMediadriverVer.dll
2010-09-16 14:38:03 ----D---- C:\WINDOWS\ie8updates
2010-09-16 14:36:24 ----D---- C:\WINDOWS\WBEM
2010-09-16 14:34:18 ----HDC---- C:\WINDOWS\ie8
2010-09-16 14:34:18 ----D---- C:\WINDOWS\system32\sk-SK
2010-09-16 14:31:19 ----A---- C:\WINDOWS\system32\xmllite.dll
2010-09-16 14:31:19 ----A---- C:\WINDOWS\system32\nlsdl.dll
2010-09-16 14:31:18 ----N---- C:\WINDOWS\system32\WinFXDocObj.exe
2010-09-16 14:31:18 ----A---- C:\WINDOWS\system32\normaliz.dll
2010-09-16 14:31:18 ----A---- C:\WINDOWS\system32\msdbg2.dll
2010-09-16 14:31:18 ----A---- C:\WINDOWS\system32\ieudinit.exe
2010-09-16 14:31:18 ----A---- C:\WINDOWS\system32\idndl.dll
2010-09-16 14:31:16 ----N---- C:\WINDOWS\system32\msrating.dll.mui
2010-09-16 14:31:15 ----N---- C:\WINDOWS\system32\mshta.exe.mui
2010-09-16 14:31:15 ----N---- C:\WINDOWS\system32\msfeedssync.exe
2010-09-16 14:31:15 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2010-09-16 14:31:15 ----A---- C:\WINDOWS\system32\msfeeds.dll
2010-09-16 14:31:13 ----N---- C:\WINDOWS\system32\ieui.dll
2010-09-16 14:31:12 ----A---- C:\WINDOWS\system32\iertutil.dll
2010-09-16 14:31:11 ----N---- C:\WINDOWS\system32\ieframe.dll.mui
2010-09-16 14:31:09 ----A---- C:\WINDOWS\system32\ieframe.dll
2010-09-16 14:31:08 ----N---- C:\WINDOWS\system32\iedkcs32.dll.mui
2010-09-16 14:31:08 ----N---- C:\WINDOWS\system32\ieapfltr.dll
2010-09-16 14:31:08 ----N---- C:\WINDOWS\system32\ie4uinit.exe.mui
2010-09-16 14:31:08 ----N---- C:\WINDOWS\system32\icardie.dll
2010-09-16 14:31:07 ----N---- C:\WINDOWS\system32\advpack.dll.mui
2010-09-16 14:22:14 ----A---- C:\WINDOWS\system32\MRT.exe
2010-09-16 14:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB932823-v3$
2010-09-11 08:22:05 ----D---- C:\WINDOWS\system32\AGEIA
2010-08-29 16:36:27 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2010-08-29 16:36:26 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2010-08-29 16:36:26 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2010-08-29 16:36:23 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2010-08-29 16:36:23 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2010-08-29 16:36:23 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2010-08-29 16:36:23 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2010-08-29 16:36:02 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-08-29 16:10:26 ----HD---- C:\WINDOWS\system32\explorer

======List of files/folders modified in the last 1 months======

2010-09-24 19:00:29 ----RD---- C:\Program Files
2010-09-24 19:00:27 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-09-24 18:59:39 ----D---- C:\WINDOWS\Temp
2010-09-24 18:57:28 ----D---- C:\Documents and Settings\jozko\Application Data\Skype
2010-09-24 18:56:51 ----HD---- C:\WINDOWS\inf
2010-09-24 18:56:46 ----D---- C:\WINDOWS\system32
2010-09-24 18:56:39 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-09-24 18:55:53 ----A---- C:\WINDOWS\ModemLog_Motorola SM56 Speakerphone Modem.txt
2010-09-24 18:55:07 ----D---- C:\WINDOWS
2010-09-24 18:55:05 ----D---- C:\WINDOWS\Debug
2010-09-24 18:54:36 ----D---- C:\WINDOWS\system32\CatRoot2
2010-09-24 18:52:46 ----D---- C:\WINDOWS\system32\Setup
2010-09-24 18:52:46 ----D---- C:\WINDOWS\ime
2010-09-24 18:52:46 ----D---- C:\WINDOWS\AppPatch
2010-09-24 18:52:46 ----D---- C:\Program Files\Messenger
2010-09-24 18:52:45 ----D---- C:\WINDOWS\system32\wbem
2010-09-24 18:52:44 ----RSD---- C:\WINDOWS\Fonts
2010-09-24 18:52:37 ----D---- C:\WINDOWS\system32\drivers
2010-09-24 18:51:56 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-09-24 18:51:46 ----D---- C:\WINDOWS\system32\CatRoot
2010-09-24 18:50:59 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-09-24 18:49:22 ----D---- C:\Program Files\Outlook Express
2010-09-24 18:47:49 ----D---- C:\Program Files\Movie Maker
2010-09-24 18:41:04 ----D---- C:\WINDOWS\security
2010-09-24 18:31:13 ----D---- C:\WINDOWS\WinSxS
2010-09-24 18:31:01 ----D---- C:\Program Files\Windows Media Player
2010-09-24 18:30:40 ----D---- C:\WINDOWS\system32\inetsrv
2010-09-24 18:30:40 ----D---- C:\WINDOWS\Help
2010-09-24 18:30:20 ----D---- C:\WINDOWS\system32\usmt
2010-09-24 18:30:20 ----D---- C:\WINDOWS\system32\en-US
2010-09-24 18:30:19 ----D---- C:\Program Files\Internet Explorer
2010-09-24 18:30:18 ----SHD---- C:\WINDOWS\Installer
2010-09-24 18:30:17 ----D---- C:\WINDOWS\PeerNet
2010-09-24 18:25:38 ----D---- C:\WINDOWS\ServicePackFiles
2010-09-24 18:25:21 ----D---- C:\WINDOWS\system32\Restore
2010-09-24 18:25:20 ----D---- C:\WINDOWS\system32\npp
2010-09-24 18:25:20 ----D---- C:\WINDOWS\mui
2010-09-24 18:25:17 ----D---- C:\WINDOWS\msagent
2010-09-24 18:25:14 ----D---- C:\WINDOWS\srchasst
2010-09-24 18:25:12 ----D---- C:\Program Files\NetMeeting
2010-09-24 18:25:10 ----D---- C:\WINDOWS\system32\Com
2010-09-24 18:25:04 ----D---- C:\Program Files\Windows NT
2010-09-24 18:24:59 ----D---- C:\Program Files\Common Files\System
2010-09-24 18:24:24 ----D---- C:\WINDOWS\system32\oobe
2010-09-24 18:24:21 ----D---- C:\WINDOWS\system
2010-09-24 18:19:08 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-09-24 18:15:29 ----D---- C:\WINDOWS\ehome
2010-09-24 17:43:16 ----D---- C:\WINDOWS\Minidump
2010-09-24 14:41:38 ----A---- C:\WINDOWS\NeroDigital.ini
2010-09-24 14:24:39 ----D---- C:\Program Files\Eidos
2010-09-24 14:08:47 ----RSD---- C:\WINDOWS\assembly
2010-09-24 14:07:48 ----D---- C:\WINDOWS\system32\DirectX
2010-09-23 18:29:12 ----ASH---- C:\boot.ini
2010-09-23 17:58:45 ----D---- C:\WINDOWS\system32\RTCOM
2010-09-23 17:54:04 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-09-23 16:37:01 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2010-09-20 21:14:30 ----SHD---- C:\Config.Msi
2010-09-18 12:29:16 ----HD---- C:\Program Files\InstallShield Installation Information
2010-09-18 07:41:37 ----HD---- C:\WINDOWS\$hf_mig$
2010-09-17 22:20:48 ----D---- C:\Program Files\Tomb Raider - Anniversary
2010-09-17 22:10:57 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2010-09-17 15:58:07 ----RD---- C:\jozy
2010-09-17 15:56:39 ----D---- C:\usb
2010-09-17 15:56:36 ----SHD---- C:\RECYCLER
2010-09-17 15:53:01 ----D---- C:\Documents and Settings
2010-09-16 14:36:28 ----D---- C:\WINDOWS\system32\config
2010-09-16 14:36:07 ----D---- C:\WINDOWS\Media
2010-09-14 14:05:27 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
2010-09-14 04:17:21 ----D---- C:\Documents and Settings\All Users\Application Data\Norton
2010-09-11 08:22:12 ----D---- C:\Program Files\AGEIA Technologies
2010-09-11 08:21:44 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-09-05 19:16:11 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Games
2010-09-03 16:20:40 ----A---- C:\WINDOWS\vncutil.exe
2010-09-03 16:20:40 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2010-09-03 16:20:40 ----A---- C:\WINDOWS\SkyTel.exe
2010-09-03 16:20:28 ----A---- C:\WINDOWS\RtlUpd.exe
2010-09-03 16:20:28 ----A---- C:\WINDOWS\RTLCPL.EXE
2010-09-03 16:20:18 ----A---- C:\WINDOWS\system32\RtkCoInstXP.dll
2010-09-03 16:20:06 ----A---- C:\WINDOWS\RtkAudioService.exe
2010-09-03 16:20:06 ----A---- C:\WINDOWS\RTHDCPL.EXE
2010-09-03 16:19:54 ----A---- C:\WINDOWS\MicCal.exe
2010-09-03 16:19:44 ----A---- C:\WINDOWS\ALCWZRD.EXE
2010-09-03 16:19:44 ----A---- C:\WINDOWS\ALCMTR.EXE
2010-08-31 16:28:46 ----A---- C:\WINDOWS\RtlExUpd.dll
2010-08-29 16:29:58 ----D---- C:\Documents and Settings\All Users\Application Data\Avira

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 Lbd;Lbd; C:\WINDOWS\system32\DRIVERS\Lbd.sys [2009-12-02 64288]
R0 ohci1394;OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2004-09-03 115680]
R0 prosync1;StarForce Protection Synchronization Driver v1; C:\WINDOWS\System32\drivers\prosync1.sys [2004-07-19 7040]
R0 risdptsk;risdptsk; C:\WINDOWS\system32\DRIVERS\risdptsk.sys [2005-07-14 27904]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2005-08-10 50688]
R0 sfhlp01;StarForce Protection Helper Driver; C:\WINDOWS\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2005-05-16 6656]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\WINDOWS\System32\drivers\sfsync02.sys [2005-08-10 19968]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2005-09-29 66048]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-08-29 721904]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-09-15 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 ItSDisk;ItSDisk; C:\WINDOWS\System32\Drivers\ItSDisk.sys [2006-05-19 23232]
R1 PersonalSecureDrive;PersonalSecureDrive; C:\WINDOWS\System32\drivers\psd.sys [2007-01-29 39080]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-09-03 54368]
R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
R1 SRTSPX;SRTSPX; C:\WINDOWS\System32\Drivers\SRTSPX.SYS [2007-01-15 25400]
R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2007-01-13 191544]
R1 Tosrfcom;Bluetooth RFCOMM; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2007-05-24 64000]
R1 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2006-02-28 12032]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.7.4.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-06-30 21393]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys []
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-09-15 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-09-15 94160]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2010-05-06 281760]
R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys []
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2010-05-06 25888]
R2 rimmptsk;rimmptsk; C:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2007-02-24 39936]
R2 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2009-06-25 44544]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\WINDOWS\system32\DRIVERS\rixdptsk.sys [2009-06-25 38400]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2007-05-29 12416]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l151x86.sys [2007-08-31 36864]
R3 ATSWPDRV;AuthenTec TruePrint USB Driver (SwipeSensor); C:\WINDOWS\system32\DRIVERS\ATSwpDrv.sys [2007-06-16 146824]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2010-01-13 1730272]
R3 IFXTPM;IFXTPM; C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2007-01-29 36608]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2010-09-03 6139496]
R3 kbfiltr;Keyboard Filter; C:\WINDOWS\system32\DRIVERS\kbfiltr.sys [2007-01-27 5632]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2006-12-17 7680]
R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070110.052\NAVENG.SYS []
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20070110.052\NAVEX15.SYS []
R3 NETw5x32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw5x32.sys [2010-01-13 6598656]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 smserial;smserial; C:\WINDOWS\system32\DRIVERS\smserial.sys [2006-08-10 980608]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\WINDOWS\system32\DRIVERS\snp2uvc.sys [2007-10-01 1769984]
R3 SRTSP;SRTSP; C:\WINDOWS\System32\Drivers\SRTSP.SYS [2007-01-15 247608]
R3 SYMDNS;SYMDNS; C:\WINDOWS\System32\Drivers\SYMDNS.SYS [2007-01-13 12984]
R3 SymEvent;SymEvent; \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
R3 SYMFW;SYMFW; C:\WINDOWS\System32\Drivers\SYMFW.SYS [2007-01-13 145976]
R3 SYMIDS;SYMIDS; C:\WINDOWS\System32\Drivers\SYMIDS.SYS [2007-01-13 40120]
R3 SYMIDSCO;SYMIDSCO; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\idsdefs\20070108.003\SymIDSCo.sys []
R3 SYMNDIS;SYMNDIS; C:\WINDOWS\System32\Drivers\SYMNDIS.SYS [2007-01-13 35256]
R3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2007-01-13 27576]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2006-10-15 198976]
R3 tosporte;Bluetooth COM Port; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2006-10-10 41600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S3 a6vfpda1;a6vfpda1; C:\WINDOWS\system32\drivers\a6vfpda1.sys []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 NETw4x32;Intel(R) Wireless WiFi Link Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw4x32.sys [2007-06-21 2208512]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2006-02-28 5888]
S3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SRTSPL;SRTSPL; C:\WINDOWS\System32\Drivers\SRTSPL.SYS [2007-01-15 276792]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 toshidpt;Bluetooth HID Port; C:\WINDOWS\system32\drivers\Toshidpt.sys [2005-07-11 3712]
S3 tosrfbd;Bluetooth RFBUS; C:\WINDOWS\system32\DRIVERS\tosrfbd.sys [2007-04-24 113920]
S3 tosrfbnp;Bluetooth RFBNEP; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2006-11-20 36480]
S3 Tosrfhid;Bluetooth RFHID; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2007-03-01 73728]
S3 tosrfnds;Bluetooth Personal Area Network; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2005-01-06 18612]
S3 tosrfusb;Bluetooth USB Controller; C:\WINDOWS\system32\DRIVERS\tosrfusb.sys [2007-06-11 41856]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 WSIMD;wsimd Service; C:\WINDOWS\system32\DRIVERS\wsimd.sys [2007-07-03 57344]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 XDva076;XDva076; \??\C:\WINDOWS\system32\XDva076.sys []
S3 XDva309;XDva309; \??\C:\WINDOWS\system32\XDva309.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACS;Atheros Configuration Service; C:\WINDOWS\system32\acs.exe [2007-10-16 364629]
R2 ASBroker;Logon Session Broker; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 ASChannel;Local Communication Channel; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2007-09-12 554352]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2007-01-13 108648]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2007-01-13 108648]
R2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2007-01-13 108648]
R2 eBeam Device Service;eBeam Device Service; C:\Program Files\Luidia\eBeam Device Service\eBeamDeviceServiceMain.exe [2007-09-05 180224]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2007-06-01 647168]
R2 IFXSpMgtSrv;Security Platform Management Service; C:\WINDOWS\system32\ifxspmgt.exe [2007-03-04 677408]
R2 IFXTCS;Trusted Platform Core Service; C:\WINDOWS\system32\ifxtcs.exe [2007-02-28 849440]
R2 LiveUpdate Notice Ex;LiveUpdate Notice Service Ex; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2007-01-13 108648]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 PersonalSecureDriveService;Personal Secure Drive Service; C:\WINDOWS\system32\IfxPsdSv.exe [2007-02-28 140832]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2007-06-01 327680]
R2 S24EventMonitor;Intel(R) PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2007-06-01 987136]
R2 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2006-12-28 123248]
R2 SymAppCore;Symantec AppCore Service; C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe [2007-01-08 47712]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-25 125048]
R2 UserAccess7;SecuROM User Access Service (V7); C:\WINDOWS\system32\UAService7.exe [2010-01-12 126976]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
R3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2007-09-12 2999664]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-30 135664]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe []
S2 LiveUpdate Notice Service;LiveUpdate Notice Service; C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [2008-01-29 583048]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 comHost;COM Host; C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe [2007-01-16 49248]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-11-17 182768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ISPwdSvc;Symantec IS Password Validation; C:\Program Files\Norton Internet Security\isPwdSvc.exe [2007-01-17 80504]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Symantec Core LC;Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [2008-06-30 1174664]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: procesor na 100 (kontrola logu)

#4 Příspěvek od Rudy »

V PC máte 2 antiviry. Avast a Norton. Jeden odinstalujte. Pokud máte z Nortona jen zbytky smažte je pomocí utility SymNrt: http://us.norton.com/support/kb/web_vie ... N&ln=en_US . Zřejmě dochází k sw kolizi.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

J0ZO
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2010 16:01

Re: procesor na 100 (kontrola logu)

#5 Příspěvek od J0ZO »

OK, v najhorsom pripade skusim aj to ale ja mam northon od kedy som kupil notebook (3roky) a avast mam uz asi 2 roky a toto mi este nerobylo.Iba ked som nainstaloval avast tak ano, pretoze sa mi aktualizovali obidve virusove databazy ale ked som na northon odinstaloval aktualizovanie tak uz to bezalo normalne. Nemyslim ze je to v tom.
Uz sa to aj znormalizovalo ale uvidim ked zase zapnem PC ci to nebude robyt.
Dakujem za radu. Ja zase niesom taky skuseny, takze ked to bude pokracovat, tak dam jeden prec. aj tak northon mi este nic nenasiel :)
Naposledy upravil(a) J0ZO dne 25 zář 2010 12:26, celkem upraveno 1 x.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: procesor na 100 (kontrola logu)

#6 Příspěvek od Rudy »

J0ZO píše:OK, v najhorsom pripade skusim aj to ale ja mam northon od kedy som kupil notebook (3roky) a avast mam viac uz asi 2 roky a toto mi este nerobylo.Iba ked som nainstaloval avast tak ano, pretoze sa mi aktualizovali obidve virusove databazy ale ked som na northon odinstaloval aktualizovanie tak uz to bezalo normalne. Nemyslim ze je to v tom.
Uz sa to aj znormalizovalo ale uvidim ked zase zapnem PC ci to nebude robyt.
Dakujem za radu. Ja zase niesom taky skuseny, takze ked to bude pokracovat, tak dam jeden prec. aj tak northon mi este nic nenasiel :)
Sw konflikt také může způsobit, že vám nic nenajde ani jeden AV, přestože váš PC bude zavirován. Castěji ale způsobuje vytížení CPU.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

J0ZO
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2010 16:01

Re: procesor na 100 (kontrola logu)

#7 Příspěvek od J0ZO »

Uz procesor neroby problemy ale stale mi pri zapnuti pc Avast nahlasi malware> WIN/system32/drivers/qqifxh.sys
Malware name> Win32:Rootkit-gen [Rtk] co to je??
A co sa tyka mojho povodneho problemu, tak ked som stiahol update tak sa procesor uz znormalizoval, je pri necinnosti
2-12% a pri praci s netom 15-25, sem tam skoci na 50 {ale to je asi normalne nvm}.
A ten northon mozem odinstalovat cez ccleaner?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: procesor na 100 (kontrola logu)

#8 Příspěvek od Rudy »

1. k důkladnému odstranění aplikací od symantec je SymNrt: http://us.norton.com/support/kb/web_vie ... N&ln=en_US .
2. V PC máte rootkit. Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

J0ZO
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2010 16:01

Re: procesor na 100 (kontrola logu)

#9 Příspěvek od J0ZO »

Ale teraz som si spomenul na povolenia od symatecu ked mi chce nieco odoslat udaje na internet. Bude to robyt aj Avast?Lebo by som bol nerad keby mi kazdu chvilu nieco odoslalo na net a ja o tom neviem. A CCleaner to neodstrani dokladne?

Antispyware je aj Avast a Northon (tie mam tiez vypnut)?
A mal by som najprv odinstalovat Northona, predtym ako zacnem s tym ComboFixom, alebo to mozem spustit aj s dvoma antivir?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: procesor na 100 (kontrola logu)

#10 Příspěvek od Rudy »

Nortona vám CCleaner neodstraní, musíte použít SymNrt, ten ho vymete kompletně. 2 antiviry (Avast a Norton není antspy, nýbrž antivir) v jednom systému způsobují sw kolize. 1 AV odinstalujte, druhý vypněte a pak spusťte ComboFix.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

J0ZO
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2010 16:01

Re: procesor na 100 (kontrola logu)

#11 Příspěvek od J0ZO »

Takze toto mi vypisalo>


ComboFix 10-09-25.07 - jozko . 09. 2010 15:19:49.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2039.1350 [GMT 2:00]
Running from: c:\documents and settings\jozko\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100926-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\jozko\Application Data\avdrn.dat
c:\windows\system32\Explorer
c:\windows\system32\Explorer\Decrypt.txt
c:\windows\system32\Explorer\melt.txt
c:\windows\system32\Explorer\pic\Img%.jpeg
c:\windows\system32\Explorer\pic\Img1.jpeg

.
((((((((((((((((((((((((( Files Created from 2010-08-26 to 2010-09-26 )))))))))))))))))))))))))))))))
.

2010-09-26 08:42 . 2010-09-26 08:42 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-09-25 12:07 . 2010-09-25 12:07 -------- d-----w- c:\documents and settings\Gretka\Application Data\Intel
2010-09-25 12:07 . 2010-09-25 12:07 -------- d-----w- c:\documents and settings\Default User\Application Data\Intel
2010-09-25 12:07 . 2010-09-25 12:07 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Intel
2010-09-25 12:07 . 2010-09-25 12:07 -------- d-----w- c:\documents and settings\LocalService\Application Data\Intel
2010-09-25 12:07 . 2010-09-25 12:07 -------- d-----w- c:\documents and settings\Lenka\Application Data\Intel
2010-09-25 12:07 . 2010-09-25 12:07 -------- d-----w- c:\documents and settings\TR\Application Data\Intel
2010-09-25 12:06 . 2010-09-25 12:06 -------- d-----w- c:\program files\Common Files\Intel
2010-09-25 12:04 . 2010-09-25 12:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Intel
2010-09-25 12:04 . 2010-09-25 12:04 -------- d-----w- c:\documents and settings\jozko\Application Data\Intel
2010-09-24 17:00 . 2010-09-24 17:00 -------- d-----w- c:\program files\trend micro
2010-09-24 16:59 . 2010-09-24 17:00 -------- d-----w- C:\rsit
2010-09-24 16:30 . 2010-09-24 16:30 -------- d-----w- c:\windows\system32\scripting
2010-09-24 16:30 . 2010-09-24 16:30 -------- d-----w- c:\windows\l2schemas
2010-09-24 16:30 . 2010-09-24 16:30 -------- d-----w- c:\windows\system32\en
2010-09-24 16:30 . 2010-09-24 16:30 -------- d-----w- c:\windows\system32\bits
2010-09-24 12:35 . 2010-09-24 12:35 -------- d-----w- c:\documents and settings\TR\Application Data\Ubisoft
2010-09-23 15:55 . 2010-09-23 15:55 -------- d-----w- c:\windows\system32\x64
2010-09-23 14:43 . 2010-09-24 14:44 -------- d-----w- c:\documents and settings\All Users\Application Data\SecTaskMan
2010-09-23 14:42 . 2010-09-23 14:42 -------- d-----w- c:\program files\Security Task Manager
2010-09-21 19:47 . 2010-09-26 13:31 564800 ----a-w- c:\windows\system32\drivers\qqifxh.sys
2010-09-18 10:29 . 2009-12-17 07:15 114688 ----a-w- c:\windows\system32\RicohMediadriverVer.dll
2010-09-17 20:18 . 2010-09-17 20:18 -------- d-----w- c:\documents and settings\TR\Local Settings\Application Data\Adobe
2010-09-17 20:11 . 2010-09-17 20:11 -------- d-sh--w- c:\documents and settings\TR\PrivacIE
2010-09-17 20:11 . 2010-09-24 14:30 -------- d-----w- c:\documents and settings\TR\Local Settings\Application Data\Google
2010-09-17 19:23 . 2010-09-17 19:23 -------- d-----w- c:\documents and settings\TR\Application Data\CyberLink
2010-09-17 13:54 . 2010-09-17 13:54 27688 ----a-w- c:\documents and settings\TR\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-16 18:31 . 2010-09-16 18:31 -------- d-sh--w- c:\documents and settings\Deti\PrivacIE
2010-09-16 18:29 . 2010-09-16 18:29 -------- d-sh--w- c:\documents and settings\Deti\IETldCache
2010-09-16 12:44 . 2010-09-16 12:44 -------- d-sh--w- c:\documents and settings\jozko\IECompatCache
2010-09-16 12:43 . 2010-09-16 12:43 -------- d-sh--w- c:\documents and settings\jozko\PrivacIE
2010-09-16 12:41 . 2010-09-16 12:41 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-09-16 12:41 . 2010-09-16 12:41 -------- d-sh--w- c:\documents and settings\jozko\IETldCache
2010-09-16 12:38 . 2010-09-25 18:46 -------- d-----w- c:\windows\ie8updates
2010-09-16 12:34 . 2010-09-16 12:36 -------- dc-h--w- c:\windows\ie8
2010-09-16 12:34 . 2010-09-16 12:36 -------- d-----w- c:\windows\system32\sk-SK
2010-09-16 12:20 . 2010-06-24 12:21 599040 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-09-16 12:20 . 2010-06-24 12:21 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-09-16 12:20 . 2010-06-24 12:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-09-16 12:20 . 2010-06-24 12:21 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-09-16 12:20 . 2010-06-24 12:21 1986560 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-09-16 12:20 . 2010-06-24 12:21 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-09-16 12:20 . 2010-06-24 15:51 11077120 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-09-11 06:22 . 2010-09-11 06:22 -------- d-----w- c:\windows\system32\AGEIA
2010-08-29 14:36 . 2009-11-24 22:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-08-29 14:36 . 2009-11-24 22:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-08-29 14:36 . 2009-11-24 22:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-08-29 14:36 . 2009-11-24 22:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2010-08-29 14:36 . 2009-11-24 22:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-08-29 14:36 . 2009-09-15 10:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-08-29 14:36 . 2009-09-15 10:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-08-29 14:36 . 2009-09-15 10:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-29 14:36 . 2009-11-24 22:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-26 13:31 . 2009-11-17 14:33 -------- d-----w- c:\documents and settings\jozko\Application Data\Skype
2010-09-26 13:30 . 2010-09-26 13:30 45056 ----a-w- c:\windows\system32\acovcnt.exe
2010-09-26 12:54 . 2008-06-30 07:56 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-09-26 12:52 . 2009-12-16 09:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-09-26 12:52 . 2008-06-30 07:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-09-25 12:06 . 2008-06-30 07:24 -------- d-----w- c:\program files\Intel
2010-09-24 16:55 . 2009-05-21 21:34 28464 ----a-w- c:\documents and settings\jozko\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-24 16:33 . 2008-06-30 07:11 5938 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-09-24 16:33 . 2008-06-30 07:11 166455 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-09-24 12:24 . 2010-04-30 16:58 -------- d-----w- c:\program files\Eidos
2010-09-23 17:01 . 2010-09-23 17:01 16 ----a-w- c:\documents and settings\LocalService\Application Data\apiqfw.dat
2010-09-23 14:43 . 2010-09-23 14:43 58 ----a-w- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_AE37A9D95D2BFC24BB45C54C9D0F1843.dll
2010-09-23 14:37 . 2010-01-23 10:16 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-09-21 19:46 . 2010-09-21 19:46 12 ----a-w- c:\windows\system32\config\systemprofile\Application Data\apiqfw.dat
2010-09-18 10:29 . 2008-06-30 07:27 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-17 20:20 . 2010-02-22 05:16 -------- d-----w- c:\program files\Tomb Raider - Anniversary
2010-09-17 20:10 . 2008-06-30 18:56 108144 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-09-17 13:53 . 2010-09-17 13:53 -------- d-----w- c:\documents and settings\TR\Application Data\Infineon
2010-09-11 06:22 . 2009-11-16 16:23 -------- d-----w- c:\program files\AGEIA Technologies
2010-09-11 06:21 . 2009-04-01 17:29 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-09-05 17:16 . 2009-04-22 14:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Games
2010-09-03 14:20 . 2010-03-21 08:35 359016 ----a-w- c:\windows\vncutil.exe
2010-09-03 14:20 . 2008-06-30 07:32 84584 ----a-w- c:\windows\SOUNDMAN.EXE
2010-09-03 14:20 . 2008-06-30 07:32 1833576 ----a-w- c:\windows\SkyTel.exe
2010-09-03 14:20 . 2008-06-30 07:32 1489512 ----a-w- c:\windows\RtlUpd.exe
2010-09-03 14:20 . 2008-06-30 07:32 9721960 ----a-w- c:\windows\RTLCPL.EXE
2010-09-03 14:20 . 2010-03-21 08:35 54888 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2010-09-03 14:20 . 2008-06-30 07:31 6139496 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2010-09-03 14:20 . 2010-03-21 08:35 129640 ----a-w- c:\windows\RtkAudioService.exe
2010-09-03 14:20 . 2008-06-30 07:32 19573352 ----a-w- c:\windows\RTHDCPL.EXE
2010-09-03 14:19 . 2008-06-30 07:32 2180712 ----a-w- c:\windows\MicCal.exe
2010-09-03 14:19 . 2008-06-30 07:32 64104 ----a-w- c:\windows\ALCMTR.EXE
2010-09-03 14:19 . 2008-06-30 07:32 2815592 ----a-w- c:\windows\ALCWZRD.EXE
2010-08-31 14:28 . 2008-06-30 07:32 1251944 ----a-w- c:\windows\RtlExUpd.dll
2010-08-29 14:29 . 2010-04-30 15:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-08-19 13:09 . 2009-08-01 11:45 -------- d-----w- c:\documents and settings\jozko\Application Data\My Battle for Middle-earth Files
2010-08-17 13:17 . 2006-02-28 12:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-08 15:50 . 2010-01-28 18:56 -------- d-----w- c:\documents and settings\jozko\Application Data\U3
2010-07-22 15:49 . 2006-02-28 12:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57 . 2009-04-15 16:42 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-10 21:05 . 2010-07-10 20:44 10134 ----a-r- c:\documents and settings\jozko\Application Data\Microsoft\Installer\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}\ARPPRODUCTICON.exe
2010-06-30 12:31 . 2006-02-28 12:00 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-28 19:38 . 2010-06-28 19:38 503808 ----a-w- c:\documents and settings\jozko\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-73e00e15-n\msvcp71.dll
2010-06-28 19:38 . 2010-06-28 19:38 12800 ----a-w- c:\documents and settings\jozko\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-402d0e25-n\decora-d3d.dll
2010-06-28 19:38 . 2010-06-28 19:38 61440 ----a-w- c:\documents and settings\jozko\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-402d0e25-n\decora-sse.dll
2010-06-28 19:38 . 2010-06-28 19:38 499712 ----a-w- c:\documents and settings\jozko\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-73e00e15-n\jmc.dll
2010-06-28 19:38 . 2010-06-28 19:38 348160 ----a-w- c:\documents and settings\jozko\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-73e00e15-n\msvcr71.dll
2010-06-28 19:37 . 2010-06-28 19:37 411368 ----a-w- c:\windows\system32\deployJava1.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Secure Disks]
@="{666C7836-A9B6-4AB4-94ED-DC238C81E925}"
[HKEY_CLASSES_ROOT\CLSID\{666C7836-A9B6-4AB4-94ED-DC238C81E925}]
2006-10-29 16:35 391168 ----a-r- c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\SFSShell.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-17 39408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26192168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATKHOTKEY"="c:\program files\ATK Hotkey\Hcontrol.exe" [2007-06-29 225280]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2007-07-03 7708672]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-08-10 573440]
"CognizanceTS"="c:\progra~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll" [2003-12-24 17920]
"IFXSPMGT"="c:\windows\system32\ifxspmgt.exe" [2007-03-04 677408]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-15 815104]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-07-26 90112]
"PowerForPhone"="c:\program files\P4P\P4P.exe" [2007-07-19 778240]
"ACMON"="c:\program files\ASUS\Splendid\ACMON.exe" [2007-06-26 851968]
"ASUS Camera ScreenSaver"="c:\windows\ASScrProlog.exe" [2008-06-30 37232]
"ASUS Screen Saver Protector"="c:\windows\ASScrPro.exe" [2008-06-30 33136]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"ACU"="c:\program files\Atheros\ACU.exe" [2007-10-16 405593]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2007-07-05 1040384]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"RTHDCPL"="RTHDCPL.EXE" [2010-09-03 19573352]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-01-13 134656]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-01-13 166912]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-01-13 135680]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2010-03-05 1396736]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-03-05 1206544]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\jozko\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2009-10-10 225280]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-5-22 2756608]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
2007-02-09 17:30 74240 ----a-r- c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\APSHook.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\EA Games\\The Battle for Middle-earth (tm)\\game.dat"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth (tm) II\\game.dat"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Electronic Arts\\The Lord of the Rings, The Rise of the Witch-king\\game.dat"=
"c:\\Documents and Settings\\Deti\\Local Settings\\Application Data\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\UBISOFT\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"c:\\Program Files\\UBISOFT\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"c:\\Program Files\\UBISOFT\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [23. 1. 2010 19:32 64288]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [29. 8. 2010 16:36 114768]
R1 ItSDisk;ItSDisk;c:\windows\system32\drivers\itsdisk.sys [19. 5. 2006 19:14 23232]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [29. 1. 2007 14:07 39080]
R2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe -k Cognizance [28. 2. 2006 14:00 14336]
R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Cognizance [28. 2. 2006 14:00 14336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [29. 8. 2010 16:36 20560]
R2 eBeam Device Service;eBeam Device Service;c:\program files\Luidia\eBeam Device Service\eBeamDeviceServiceMain.exe [13. 3. 2010 17:29 180224]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [30. 6. 2008 9:32 36864]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [30. 6. 2008 9:45 36608]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [30. 1. 2010 8:52 135664]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\Lavasoft\Ad-Aware\AAWService.exe" --> c:\program files\Lavasoft\Ad-Aware\AAWService.exe [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [21. 3. 2010 10:35 1691480]
S3 XDva076;XDva076;\??\c:\windows\system32\XDva076.sys --> c:\windows\system32\XDva076.sys [?]
S3 XDva309;XDva309;\??\c:\windows\system32\XDva309.sys --> c:\windows\system32\XDva309.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [27. 2. 2009 16:37 721904]

--- Other Services/Drivers In Memory ---

*Deregistered* - qqifxh

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASBroker ASChannel
.
Contents of the 'Scheduled Tasks' folder

2010-09-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2010-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 06:52]

2010-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 06:52]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.azet.sk/
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-NortonUpdateAgent - c:\documents and settings\All Users\Application Data\Norton\NUA.exe
AddRemove-{B931FB80-537A-4600-00AD-AC5DEDB6C25B} - c:\program files\Electronic Arts\The Lord of the Rings



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-26 15:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\windows\system32\acovcnt.exe 45056 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\qqifxh]

.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1214440339-725345543-477535893-1007\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:88,b8,30,cc,d4,18,16,a5,7f,f6,ed,48,0c,24,1b,af,2e,7b,bc,e8,ec,ed,94,
d9,5c,84,1c,22,86,f6,f7,97,a3,ff,a3,18,f3,70,56,69,3d,dd,1b,7c,a5,51,f7,1b,\
"??"=hex:85,43,67,92,3f,da,95,6f,af,bc,9a,a0,a2,92,4b,2f

[HKEY_USERS\S-1-5-21-1214440339-725345543-477535893-1007\Software\SecuROM\License information*]
"datasecu"=hex:3f,0a,7e,2f,24,64,8d,e8,43,c8,8c,bf,d5,ab,b1,87,d5,a7,4d,52,92,
a0,c3,ca,eb,3e,fc,e8,ed,df,83,8b,23,58,9c,30,3e,23,33,b1,16,32,0b,36,1a,c9,\
"rkeysecu"=hex:4c,62,e0,14,a2,ed,db,92,19,ed,ec,6f,94,89,2c,b0
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1276)
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\ItMsg.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\TrayIcon.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\brand.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsChnl.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItDAC.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItReports.DLL
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\BioAuth.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASBioAT.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItVCClient.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\AuthWiz.dll

- - - - - - - > 'explorer.exe'(5572)
c:\windows\system32\WININET.dll
c:\windows\system32\APSHook.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\SFSShell.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItMsg.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\WiFi\bin\S24EvMon.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\acs.exe
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\Luidia\eBeam Device Service\eBeamDeviceServiceUI.exe
c:\windows\system32\ifxtcs.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\IfxPsdSv.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\windows\system32\UAService7.exe
c:\windows\System32\SCardSvr.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATK Hotkey\ATKOSD.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\ACEngSvr.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\ATK Hotkey\KBFiltr.exe
c:\program files\ATK Hotkey\WDC.exe
c:\windows\system32\acovcnt.exe
c:\program files\Infineon\Security Platform Software\PSDrt.exe
c:\program files\Infineon\Security Platform Software\SpTna.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
.
**************************************************************************
.
Completion time: 2010-09-26 15:36:04 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-26 13:36

Pre-Run: 8 562 319 360 bytes free
Post-Run: 11 239 321 600 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptOut

- - End Of File - - C3DB293E421C17F6BB44C07F335C4882

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: procesor na 100 (kontrola logu)

#12 Příspěvek od Rudy »

Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
Collect::
c:\windows\system32\drivers\qqifxh.sys
c:\windows\system32\acovcnt.exe
c:\windows\system32\XDva076.sys
c:\windows\system32\XDva309.sys
c:\documents and settings\jozko\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe


Driver::
qqifxh
XDva076
XDva309
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pustte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

J0ZO
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2010 16:01

Re: procesor na 100 (kontrola logu)

#13 Příspěvek od J0ZO »

ok teraz mi vypisalo toto. Cize uz je to OK?


ComboFix 10-09-25.07 - jozko . 09. 2010 21:05:57.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2039.1354 [GMT 2:00]
Running from: c:\documents and settings\jozko\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\jozko\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100926-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

file zipped: c:\documents and settings\jozko\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
file zipped: c:\windows\system32\acovcnt.exe
file zipped: c:\windows\system32\drivers\qqifxh.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\jozko\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
c:\windows\system32\acovcnt.exe
c:\windows\system32\drivers\qqifxh.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_QQIFXH
-------\Legacy_XDVA076
-------\Service_qqifxh
-------\Service_XDva076
-------\Service_XDva309


((((((((((((((((((((((((( Files Created from 2010-08-26 to 2010-09-26 )))))))))))))))))))))))))))))))
.

2010-09-26 08:42 . 2010-09-26 08:42 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-09-25 12:07 . 2010-09-25 12:07 -------- d-----w- c:\documents and settings\Gretka\Application Data\Intel
2010-09-25 12:07 . 2010-09-25 12:07 -------- d-----w- c:\documents and settings\Default User\Application Data\Intel
2010-09-25 12:07 . 2010-09-25 12:07 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Intel
2010-09-25 12:07 . 2010-09-25 12:07 -------- d-----w- c:\documents and settings\LocalService\Application Data\Intel
2010-09-25 12:07 . 2010-09-25 12:07 -------- d-----w- c:\documents and settings\Lenka\Application Data\Intel
2010-09-25 12:07 . 2010-09-25 12:07 -------- d-----w- c:\documents and settings\TR\Application Data\Intel
2010-09-25 12:06 . 2010-09-25 12:06 -------- d-----w- c:\program files\Common Files\Intel
2010-09-25 12:04 . 2010-09-25 12:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Intel
2010-09-25 12:04 . 2010-09-25 12:04 -------- d-----w- c:\documents and settings\jozko\Application Data\Intel
2010-09-24 17:00 . 2010-09-24 17:00 -------- d-----w- c:\program files\trend micro
2010-09-24 16:59 . 2010-09-24 17:00 -------- d-----w- C:\rsit
2010-09-24 16:30 . 2010-09-24 16:30 -------- d-----w- c:\windows\system32\scripting
2010-09-24 16:30 . 2010-09-24 16:30 -------- d-----w- c:\windows\l2schemas
2010-09-24 16:30 . 2010-09-24 16:30 -------- d-----w- c:\windows\system32\en
2010-09-24 16:30 . 2010-09-24 16:30 -------- d-----w- c:\windows\system32\bits
2010-09-24 12:35 . 2010-09-24 12:35 -------- d-----w- c:\documents and settings\TR\Application Data\Ubisoft
2010-09-23 15:55 . 2010-09-23 15:55 -------- d-----w- c:\windows\system32\x64
2010-09-23 14:43 . 2010-09-24 14:44 -------- d-----w- c:\documents and settings\All Users\Application Data\SecTaskMan
2010-09-23 14:42 . 2010-09-23 14:42 -------- d-----w- c:\program files\Security Task Manager
2010-09-18 10:29 . 2009-12-17 07:15 114688 ----a-w- c:\windows\system32\RicohMediadriverVer.dll
2010-09-17 20:18 . 2010-09-17 20:18 -------- d-----w- c:\documents and settings\TR\Local Settings\Application Data\Adobe
2010-09-17 20:11 . 2010-09-17 20:11 -------- d-sh--w- c:\documents and settings\TR\PrivacIE
2010-09-17 20:11 . 2010-09-24 14:30 -------- d-----w- c:\documents and settings\TR\Local Settings\Application Data\Google
2010-09-17 19:23 . 2010-09-17 19:23 -------- d-----w- c:\documents and settings\TR\Application Data\CyberLink
2010-09-17 13:54 . 2010-09-17 13:54 27688 ----a-w- c:\documents and settings\TR\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-16 18:31 . 2010-09-16 18:31 -------- d-sh--w- c:\documents and settings\Deti\PrivacIE
2010-09-16 18:29 . 2010-09-16 18:29 -------- d-sh--w- c:\documents and settings\Deti\IETldCache
2010-09-16 12:44 . 2010-09-16 12:44 -------- d-sh--w- c:\documents and settings\jozko\IECompatCache
2010-09-16 12:43 . 2010-09-16 12:43 -------- d-sh--w- c:\documents and settings\jozko\PrivacIE
2010-09-16 12:41 . 2010-09-16 12:41 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-09-16 12:41 . 2010-09-16 12:41 -------- d-sh--w- c:\documents and settings\jozko\IETldCache
2010-09-16 12:38 . 2010-09-25 18:46 -------- d-----w- c:\windows\ie8updates
2010-09-16 12:34 . 2010-09-16 12:36 -------- dc-h--w- c:\windows\ie8
2010-09-16 12:34 . 2010-09-16 12:36 -------- d-----w- c:\windows\system32\sk-SK
2010-09-16 12:20 . 2010-06-24 12:21 599040 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-09-16 12:20 . 2010-06-24 12:21 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-09-16 12:20 . 2010-06-24 12:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-09-16 12:20 . 2010-06-24 12:21 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-09-16 12:20 . 2010-06-24 12:21 1986560 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-09-16 12:20 . 2010-06-24 12:21 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-09-16 12:20 . 2010-06-24 15:51 11077120 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-09-11 06:22 . 2010-09-11 06:22 -------- d-----w- c:\windows\system32\AGEIA
2010-08-29 14:36 . 2009-11-24 22:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-08-29 14:36 . 2009-11-24 22:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-08-29 14:36 . 2009-11-24 22:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-08-29 14:36 . 2009-11-24 22:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2010-08-29 14:36 . 2009-11-24 22:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-08-29 14:36 . 2009-09-15 10:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-08-29 14:36 . 2009-09-15 10:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-08-29 14:36 . 2009-09-15 10:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-29 14:36 . 2009-11-24 22:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-26 19:17 . 2009-11-17 14:33 -------- d-----w- c:\documents and settings\jozko\Application Data\Skype
2010-09-26 19:16 . 2010-09-26 19:16 45056 ----a-w- c:\windows\system32\acovcnt.exe
2010-09-26 12:54 . 2008-06-30 07:56 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-09-26 12:52 . 2009-12-16 09:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-09-26 12:52 . 2008-06-30 07:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-09-25 12:06 . 2008-06-30 07:24 -------- d-----w- c:\program files\Intel
2010-09-24 16:55 . 2009-05-21 21:34 28464 ----a-w- c:\documents and settings\jozko\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-24 16:33 . 2008-06-30 07:11 5938 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-09-24 16:33 . 2008-06-30 07:11 166455 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-09-24 12:24 . 2010-04-30 16:58 -------- d-----w- c:\program files\Eidos
2010-09-23 17:01 . 2010-09-23 17:01 16 ----a-w- c:\documents and settings\LocalService\Application Data\apiqfw.dat
2010-09-23 14:43 . 2010-09-23 14:43 58 ----a-w- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_AE37A9D95D2BFC24BB45C54C9D0F1843.dll
2010-09-23 14:37 . 2010-01-23 10:16 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-09-21 19:46 . 2010-09-21 19:46 12 ----a-w- c:\windows\system32\config\systemprofile\Application Data\apiqfw.dat
2010-09-18 10:29 . 2008-06-30 07:27 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-17 20:20 . 2010-02-22 05:16 -------- d-----w- c:\program files\Tomb Raider - Anniversary
2010-09-17 20:10 . 2008-06-30 18:56 108144 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-09-17 13:53 . 2010-09-17 13:53 -------- d-----w- c:\documents and settings\TR\Application Data\Infineon
2010-09-11 06:22 . 2009-11-16 16:23 -------- d-----w- c:\program files\AGEIA Technologies
2010-09-11 06:21 . 2009-04-01 17:29 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-09-05 17:16 . 2009-04-22 14:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Games
2010-09-03 14:20 . 2010-03-21 08:35 359016 ----a-w- c:\windows\vncutil.exe
2010-09-03 14:20 . 2008-06-30 07:32 84584 ----a-w- c:\windows\SOUNDMAN.EXE
2010-09-03 14:20 . 2008-06-30 07:32 1833576 ----a-w- c:\windows\SkyTel.exe
2010-09-03 14:20 . 2008-06-30 07:32 1489512 ----a-w- c:\windows\RtlUpd.exe
2010-09-03 14:20 . 2008-06-30 07:32 9721960 ----a-w- c:\windows\RTLCPL.EXE
2010-09-03 14:20 . 2010-03-21 08:35 54888 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2010-09-03 14:20 . 2008-06-30 07:31 6139496 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2010-09-03 14:20 . 2010-03-21 08:35 129640 ----a-w- c:\windows\RtkAudioService.exe
2010-09-03 14:20 . 2008-06-30 07:32 19573352 ----a-w- c:\windows\RTHDCPL.EXE
2010-09-03 14:19 . 2008-06-30 07:32 2180712 ----a-w- c:\windows\MicCal.exe
2010-09-03 14:19 . 2008-06-30 07:32 64104 ----a-w- c:\windows\ALCMTR.EXE
2010-09-03 14:19 . 2008-06-30 07:32 2815592 ----a-w- c:\windows\ALCWZRD.EXE
2010-08-31 14:28 . 2008-06-30 07:32 1251944 ----a-w- c:\windows\RtlExUpd.dll
2010-08-29 14:29 . 2010-04-30 15:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-08-19 13:09 . 2009-08-01 11:45 -------- d-----w- c:\documents and settings\jozko\Application Data\My Battle for Middle-earth Files
2010-08-17 13:17 . 2006-02-28 12:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-08 15:50 . 2010-01-28 18:56 -------- d-----w- c:\documents and settings\jozko\Application Data\U3
2010-07-22 15:49 . 2006-02-28 12:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57 . 2009-04-15 16:42 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-10 21:05 . 2010-07-10 20:44 10134 ----a-r- c:\documents and settings\jozko\Application Data\Microsoft\Installer\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}\ARPPRODUCTICON.exe
2010-06-30 12:31 . 2006-02-28 12:00 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-28 19:38 . 2010-06-28 19:38 503808 ----a-w- c:\documents and settings\jozko\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-73e00e15-n\msvcp71.dll
2010-06-28 19:38 . 2010-06-28 19:38 12800 ----a-w- c:\documents and settings\jozko\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-402d0e25-n\decora-d3d.dll
2010-06-28 19:38 . 2010-06-28 19:38 61440 ----a-w- c:\documents and settings\jozko\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-402d0e25-n\decora-sse.dll
2010-06-28 19:38 . 2010-06-28 19:38 499712 ----a-w- c:\documents and settings\jozko\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-73e00e15-n\jmc.dll
2010-06-28 19:38 . 2010-06-28 19:38 348160 ----a-w- c:\documents and settings\jozko\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-73e00e15-n\msvcr71.dll
2010-06-28 19:37 . 2010-06-28 19:37 411368 ----a-w- c:\windows\system32\deployJava1.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Secure Disks]
@="{666C7836-A9B6-4AB4-94ED-DC238C81E925}"
[HKEY_CLASSES_ROOT\CLSID\{666C7836-A9B6-4AB4-94ED-DC238C81E925}]
2006-10-29 16:35 391168 ----a-r- c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\SFSShell.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-17 39408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26192168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATKHOTKEY"="c:\program files\ATK Hotkey\Hcontrol.exe" [2007-06-29 225280]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2007-07-03 7708672]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-08-10 573440]
"CognizanceTS"="c:\progra~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll" [2003-12-24 17920]
"IFXSPMGT"="c:\windows\system32\ifxspmgt.exe" [2007-03-04 677408]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-15 815104]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-07-26 90112]
"PowerForPhone"="c:\program files\P4P\P4P.exe" [2007-07-19 778240]
"ACMON"="c:\program files\ASUS\Splendid\ACMON.exe" [2007-06-26 851968]
"ASUS Camera ScreenSaver"="c:\windows\ASScrProlog.exe" [2008-06-30 37232]
"ASUS Screen Saver Protector"="c:\windows\ASScrPro.exe" [2008-06-30 33136]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"ACU"="c:\program files\Atheros\ACU.exe" [2007-10-16 405593]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2007-07-05 1040384]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"RTHDCPL"="RTHDCPL.EXE" [2010-09-03 19573352]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-01-13 134656]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-01-13 166912]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-01-13 135680]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2010-03-05 1396736]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-03-05 1206544]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-5-22 2756608]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
2007-02-09 17:30 74240 ----a-r- c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\APSHook.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\EA Games\\The Battle for Middle-earth (tm)\\game.dat"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth (tm) II\\game.dat"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Electronic Arts\\The Lord of the Rings, The Rise of the Witch-king\\game.dat"=
"c:\\Documents and Settings\\Deti\\Local Settings\\Application Data\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\UBISOFT\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"c:\\Program Files\\UBISOFT\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"c:\\Program Files\\UBISOFT\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [23. 1. 2010 19:32 64288]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [29. 8. 2010 16:36 114768]
R1 ItSDisk;ItSDisk;c:\windows\system32\drivers\itsdisk.sys [19. 5. 2006 19:14 23232]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [29. 1. 2007 14:07 39080]
R2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe -k Cognizance [28. 2. 2006 14:00 14336]
R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Cognizance [28. 2. 2006 14:00 14336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [29. 8. 2010 16:36 20560]
R2 eBeam Device Service;eBeam Device Service;c:\program files\Luidia\eBeam Device Service\eBeamDeviceServiceMain.exe [13. 3. 2010 17:29 180224]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [30. 6. 2008 9:32 36864]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [30. 6. 2008 9:45 36608]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [30. 1. 2010 8:52 135664]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\Lavasoft\Ad-Aware\AAWService.exe" --> c:\program files\Lavasoft\Ad-Aware\AAWService.exe [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [21. 3. 2010 10:35 1691480]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [27. 2. 2009 16:37 721904]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASBroker ASChannel
.
Contents of the 'Scheduled Tasks' folder

2010-09-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2010-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 06:52]

2010-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 06:52]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.azet.sk/
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -

AddRemove-HijackThis - e:\jozko\hijackthis\HijackThis.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-26 21:15
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\windows\system32\acovcnt.exe 45056 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1214440339-725345543-477535893-1007\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:88,b8,30,cc,d4,18,16,a5,7f,f6,ed,48,0c,24,1b,af,2e,7b,bc,e8,ec,ed,94,
d9,5c,84,1c,22,86,f6,f7,97,a3,ff,a3,18,f3,70,56,69,3d,dd,1b,7c,a5,51,f7,1b,\
"??"=hex:85,43,67,92,3f,da,95,6f,af,bc,9a,a0,a2,92,4b,2f

[HKEY_USERS\S-1-5-21-1214440339-725345543-477535893-1007\Software\SecuROM\License information*]
"datasecu"=hex:3f,0a,7e,2f,24,64,8d,e8,43,c8,8c,bf,d5,ab,b1,87,d5,a7,4d,52,92,
a0,c3,ca,eb,3e,fc,e8,ed,df,83,8b,23,58,9c,30,3e,23,33,b1,16,32,0b,36,1a,c9,\
"rkeysecu"=hex:4c,62,e0,14,a2,ed,db,92,19,ed,ec,6f,94,89,2c,b0
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1260)
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\ItMsg.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\TrayIcon.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\brand.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsChnl.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItDAC.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItReports.DLL
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\BioAuth.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASBioAT.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItVCClient.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\AuthWiz.dll

- - - - - - - > 'explorer.exe'(4256)
c:\windows\system32\WININET.dll
c:\windows\system32\APSHook.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\SFSShell.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItMsg.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\WiFi\bin\S24EvMon.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\acs.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\Luidia\eBeam Device Service\eBeamDeviceServiceUI.exe
c:\windows\system32\ifxtcs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
c:\windows\system32\IfxPsdSv.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\windows\system32\UAService7.exe
c:\windows\System32\SCardSvr.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATK Hotkey\ATKOSD.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\ACEngSvr.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Infineon\Security Platform Software\PSDrt.exe
c:\program files\ATK Hotkey\KBFiltr.exe
c:\program files\Infineon\Security Platform Software\SpTna.exe
c:\windows\system32\acovcnt.exe
c:\program files\ATK Hotkey\WDC.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
.
**************************************************************************
.
Completion time: 2010-09-26 21:21:36 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-26 19:21
ComboFix2.txt 2010-09-26 13:36

Pre-Run: 11 149 811 712 bytes free
Post-Run: 11 274 399 744 bytes free

- - End Of File - - 31DFA57ED2B489525C9D577CD0D6BE66

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: procesor na 100 (kontrola logu)

#14 Příspěvek od Rudy »

Log již vypadá čistý. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

J0ZO
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 24 zář 2010 16:01

Re: procesor na 100 (kontrola logu)

#15 Příspěvek od J0ZO »

JJ, procesor ide este trochu lepsie, a uz mi avast nic nehlasi, aj internet ťaha rychlejsie, takze Ďakujem.
Ale teraz mi nechce spustat daemon tools. Neiete preco? Mi to asi vymazalo alebo co. (mozno staci len preinstalovat, ale ci prave v ňom nebol virus). Ale este raz vdaka, lebo sa to zmenilo k lepsiemu.

Odpovědět