
Logfile of random's system information tool 1.06 (written by random/random)
Run by Petr at 2010-12-30 15:55:17
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 86 GB (58%) free of 149 GB
Total RAM: 767 MB (31% free)
HijackThis download failed
======Scheduled tasks folder======
C:\Windows\tasks\1-Click Maintenance.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll [2010-10-06 842296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-06-02 1018616]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-02-15 4390912]
"WarReg_PopUp"=C:\Acer\WR_PopUp\WarReg_PopUp.exe [2006-11-05 57344]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-06-20 13535776]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-06-20 92704]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2010-09-07 2838912]
"eRecoveryService"= []
"Malwarebytes' Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-12-20 963976]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-19 1233920]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"Skype"=C:\Program Files\Skype\\Phone\Skype.exe [2010-09-02 13351304]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2010-12-30 15:40:22 ----D---- C:\Program Files\trend micro
2010-12-30 15:40:20 ----D---- C:\rsit
2010-12-30 14:11:06 ----D---- C:\Users\Petr\AppData\Roaming\Malwarebytes
2010-12-30 14:10:54 ----D---- C:\ProgramData\Malwarebytes
2010-12-30 14:10:50 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-12-30 14:06:34 ----A---- C:\Windows\system32\TUProgSt.exe
2010-12-30 14:05:34 ----A---- C:\Windows\system32\uxtuneup.dll
2010-12-30 14:05:34 ----A---- C:\Windows\system32\authuitu.dll
2010-12-30 14:05:19 ----A---- C:\Windows\system32\TuneUpDefragService.exe
2010-12-30 14:04:13 ----D---- C:\Users\Petr\AppData\Roaming\TuneUp Software
2010-12-30 14:02:27 ----D---- C:\ProgramData\TuneUp Software
2010-12-30 14:02:27 ----D---- C:\Program Files\TuneUp Utilities 2009
2010-12-30 13:57:47 ----SHD---- C:\ProgramData\{55A29068-F2CE-456C-9148-C869879E2357}
2010-12-30 13:51:13 ----D---- C:\Program Files\CCleaner
2010-12-16 05:15:34 ----A---- C:\Windows\system32\schedsvc.dll
2010-12-16 05:15:33 ----A---- C:\Windows\system32\wmicmiplugin.dll
2010-12-16 05:15:33 ----A---- C:\Windows\system32\taskschd.dll
2010-12-16 05:15:32 ----A---- C:\Windows\system32\taskeng.exe
2010-12-16 05:15:31 ----A---- C:\Windows\system32\taskcomp.dll
2010-12-16 05:15:02 ----A---- C:\Windows\system32\consent.exe
2010-12-16 05:14:51 ----A---- C:\Windows\system32\atmfd.dll
2010-12-16 05:14:50 ----A---- C:\Windows\system32\atmlib.dll
2010-12-16 05:14:47 ----A---- C:\Windows\system32\fontsub.dll
2010-12-16 05:12:10 ----A---- C:\Windows\system32\tzres.dll
2010-12-16 05:05:32 ----A---- C:\Windows\system32\mstime.dll
2010-12-16 05:05:28 ----A---- C:\Windows\system32\ieframe.dll
2010-12-16 05:05:26 ----A---- C:\Windows\system32\msfeeds.dll
2010-12-16 05:05:25 ----A---- C:\Windows\system32\mshtml.dll
2010-12-16 05:05:22 ----A---- C:\Windows\system32\ieapfltr.dll
2010-12-16 05:05:20 ----A---- C:\Windows\system32\mshtmled.dll
2010-12-16 05:05:19 ----A---- C:\Windows\system32\wininet.dll
2010-12-16 05:05:17 ----A---- C:\Windows\system32\urlmon.dll
2010-12-16 05:05:16 ----A---- C:\Windows\system32\ieaksie.dll
2010-12-16 05:05:14 ----A---- C:\Windows\system32\iertutil.dll
2010-12-16 05:05:14 ----A---- C:\Windows\system32\iepeers.dll
2010-12-16 05:05:14 ----A---- C:\Windows\system32\iedkcs32.dll
2010-12-16 05:05:13 ----A---- C:\Windows\system32\occache.dll
2010-12-16 05:05:12 ----A---- C:\Windows\system32\jsproxy.dll
2010-12-16 05:05:12 ----A---- C:\Windows\system32\ieencode.dll
2010-12-14 10:25:16 ----D---- C:\Users\Petr\AppData\Roaming\elefundesktops
2010-12-14 10:25:04 ----D---- C:\Program Files\EleFun Desktops
2010-12-14 10:17:19 ----D---- C:\Program Files\Prolific Publishing, Inc
======List of files/folders modified in the last 1 months======
2010-12-30 15:55:14 ----D---- C:\Windows\Temp
2010-12-30 15:40:22 ----RD---- C:\Program Files
2010-12-30 15:38:14 ----D---- C:\Windows\system32\drivers
2010-12-30 15:37:52 ----SHD---- C:\Config.Msi
2010-12-30 15:37:43 ----D---- C:\Windows\Microsoft.NET
2010-12-30 14:50:24 ----SHD---- C:\Windows\Installer
2010-12-30 14:50:20 ----RD---- C:\Program Files\Skype
2010-12-30 14:36:34 ----HD---- C:\ProgramData
2010-12-30 14:24:07 ----D---- C:\Windows\system32\Tasks
2010-12-30 14:06:48 ----D---- C:\Windows\Debug
2010-12-30 14:06:47 ----D---- C:\Windows\Prefetch
2010-12-30 14:06:47 ----D---- C:\Windows\Minidump
2010-12-30 14:06:47 ----D---- C:\Windows
2010-12-30 14:06:34 ----D---- C:\Windows\System32
2010-12-30 14:04:45 ----D---- C:\Windows\Tasks
2010-12-30 14:04:07 ----SD---- C:\Users\Petr\AppData\Roaming\Microsoft
2010-12-30 14:03:46 ----D---- C:\Users\Petr\AppData\Roaming\ICQ
2010-12-30 14:01:32 ----SHD---- C:\System Volume Information
2010-12-30 13:53:17 ----D---- C:\Windows\inf
2010-12-30 13:53:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-29 19:34:08 ----D---- C:\Program Files\Warcraft III
2010-12-29 19:03:48 ----D---- C:\Program Files\Garena
2010-12-22 23:41:17 ----D---- C:\Windows\system32\catroot2
2010-12-17 14:50:59 ----D---- C:\Windows\rescache
2010-12-17 14:39:21 ----D---- C:\Windows\winsxs
2010-12-17 14:20:05 ----D---- C:\Program Files\Windows Mail
2010-12-17 14:19:53 ----D---- C:\Program Files\Internet Explorer
2010-12-17 14:11:51 ----D---- C:\Windows\system32\cs-CZ
2010-12-17 14:11:01 ----D---- C:\Windows\system32\catroot
2010-12-17 13:59:55 ----A---- C:\Windows\system32\mrt.exe
2010-12-04 15:07:38 ----D---- C:\Windows\system32\WDI
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2010-09-07 23376]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2010-09-07 165584]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2010-09-07 46672]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2010-09-07 17744]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
R2 int15;int15; \??\C:\Acer\Empowering Technology\eRecovery\int15.sys [2006-12-07 76584]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-02-14 1740904]
R3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2007-05-03 6144]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-06-20 7468128]
R3 Ph3xIB32;Philips 713x VU PCI TV Card; C:\Windows\system32\DRIVERS\Ph3xIB32.sys [2007-04-03 1131136]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-09 194560]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 GarenaPEngine;GarenaPEngine; \??\C:\Users\Petr\AppData\Local\Temp\GWYFFB2.tmp [2010-12-29 25616]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files\Garena\safedrv.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-06-06 25280]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2008-01-19 47360]
S3 w200bus;Sony Ericsson W200 driver (WDM); C:\Windows\system32\DRIVERS\w200bus.sys [2006-11-07 61504]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\w200mdfl.sys [2006-11-07 9328]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\w200mdm.sys [2006-11-07 97056]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\w200mgmt.sys [2006-11-07 88560]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\w200obex.sys [2006-11-07 86368]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 eRecoveryService;eRecovery Service; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [2007-01-31 53248]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-06-02 246520]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-12-14 61440]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-06-20 118784]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2009-06-08 66872]
R2 PnkBstrB;PnkBstrB; C:\Windows\system32\PnkBstrB.exe [2009-06-12 202448]
R2 TuneUp.ProgramStatisticsSvc;@%SystemRoot%\System32\TUProgSt.exe,-1; C:\Windows\System32\TUProgSt.exe [2010-12-30 603904]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 CLTNetCnService;Symantec Lic NetConnect service; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-25 182768]
S3 TuneUp.Defrag;@%SystemRoot%\System32\TuneUpDefragService.exe,-1; C:\Windows\System32\TuneUpDefragService.exe [2010-12-30 360192]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
-----------------EOF-----------------
díky za brzké vyřešení