chtěl bych poprosit o kontrolu rsit logu z mého počítače. Povedlo se mi totiž před nějakou dobou ho nakazit, a to zejména kvůli své vlastní neopatrnosti a neznalosti současných poměrů, co se všelijaké havěti týče. Počítač používám pro práci do školy, občas nějaké přehrání videa, prohlížení internetu. Vím, že řešením je přeinstalace a zodpovědnější přístup. Přesto kdyby si některý z rádců nebo moderátorů našel chviličku ku přelouskání mého logu, budu velmi vděčen. Zkoušel jsem si s tím poradit sám, nejdříve pomocí různých programů na odstranění havěti, pak i pomocí logů tu uváděných, leč neúspěšně. Přiznávám ale, že nevím přesně co je v logu nesprávné i když mám podezření na některé záznamy.
Současný stav se projevuje tak, že se mi svchost snaží připojit na příliš mnoho adres zároveň. Tedy něco co on obsluhuje. Je to vidět např. zde, z win defendera.

Předem děkuji za jakýkoliv tip a Váš čas. A ještě samozřejmě přiložím log z rsit. Tady je:
Kód: Vybrat vše
Logfile of random's system information tool 1.08 (written by random/random)
Run by uzivatel at 2011-01-10 00:05:53
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 984 MB (4%) free of 23 GB
Total RAM: 2047 MB (73% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45AD732C-2CE2-4666-B366-B2214AD57A49}]
Idea2 SidebarBrowserMonitor Class - C:\Program Files\00 Desktop Sidebar\sbhelp.dll [2004-09-04 233472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-01 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-01 73728]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SmcService"=C:\PROGRA~1\00SYGA~1\SPF\smc.exe [2004-09-02 2528480]
"UnlockerAssistant"=C:\Program Files\00 Unlocker\UnlockerAssistant.exe [2006-09-07 15872]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-01 149280]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"IntelliPoint"=C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2006-11-21 842584]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-06-20 77824]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SIDEBAR"=C:\Program Files\00 Desktop Sidebar\dsidebar.exe [2004-09-04 1126400]
"RestoreDesktop"=C:\Program Files\00 Restore Desktop\RestoreDesktop.exe [2003-03-11 45056]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Infium"=C:\Program Files\00 QIP Infium\infium.exe [2009-03-19 5244928]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3
"FLEXnet Licensing Service"=3
"Bonjour Service"=3
"aihbe"=2
"RSVP"=3
C:\Documents and Settings\uzivatel\Nabídka Start\Programy\Po spuštění
JDownloader.lnk - C:\Documents and Settings\uzivatel\Dokumenty\JDownloader 0.87\JDownloader.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\00WIND~1\MpShHook.dll [2006-11-03 83224]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveSearch"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe"="C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe:*:Enabled:Ad-Aware"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\00 totalcmd\TOTALCMD.EXE"="C:\00 totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\00 QIP Infium\infium.exe"="C:\Program Files\00 QIP Infium\infium.exe:*:Enabled:QIP Infium"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\00 Mathematica 5.2\Mathematica.exe"="C:\Program Files\00 Mathematica 5.2\Mathematica.exe:*:Enabled:Mathematica 5.2 for Students"
"C:\Program Files\00 Mathematica 5.2\MathKernel.exe"="C:\Program Files\00 Mathematica 5.2\MathKernel.exe:*:Enabled:Mathematica 5.2 for Students Kernel"
"C:\Program Files\00 Mathematica 5.2\math.exe"="C:\Program Files\00 Mathematica 5.2\math.exe:*:Enabled:math.exe"
"C:\Program Files\00 VideoLAN VLC\vlc.exe"="C:\Program Files\00 VideoLAN VLC\vlc.exe:*:Enabled:VLC media player"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======File associations======
.scr - open - "C:\WINDOWS\system32\NOTEPAD.EXE" "%1"
.scr - install -
.scr - config -
======List of files/folders created in the last 1 months======
2011-01-10 00:05:55 ----D---- C:\Program Files\trend micro
2011-01-10 00:05:53 ----D---- C:\rsit
2011-01-07 03:32:23 ----A---- C:\WINDOWS\system32\drivers\SBREDrv.sys
2011-01-07 03:22:30 ----HDC---- C:\Documents and Settings\All Users\Data aplikací\{2162CCC0-3A5F-4887-B51F-CE5F195B3620}
2011-01-07 03:21:07 ----D---- C:\Program Files\CCleaner
2011-01-06 12:59:25 ----D---- C:\Program Files\00 Spybot - Search & Destroy
2011-01-06 12:59:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-12-29 00:56:11 ----D---- C:\Program Files\00 NetMeter
2010-12-11 20:49:33 ----D---- C:\Documents and Settings\All Users\Data aplikací\IObit
2010-12-11 15:19:21 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Google
======List of files/folders modified in the last 1 months======
2011-01-10 00:05:55 ----RD---- C:\Program Files
2011-01-10 00:05:25 ----D---- C:\Program Files\00 Mozilla Firefox
2011-01-10 00:04:32 ----D---- C:\WINDOWS\system32
2011-01-10 00:03:03 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Desktop Sidebar
2011-01-10 00:02:36 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-01-09 23:55:31 ----D---- C:\WINDOWS\Prefetch
2011-01-09 23:45:39 ----D---- C:\WINDOWS
2011-01-09 23:42:12 ----SD---- C:\WINDOWS\Tasks
2011-01-09 23:31:37 ----D---- C:\WINDOWS\Temp
2011-01-09 23:27:05 ----D---- C:\WINDOWS\system32\CatRoot2
2011-01-09 23:24:03 ----SHD---- C:\WINDOWS\Installer
2011-01-09 23:23:58 ----HD---- C:\WINDOWS\inf
2011-01-09 23:23:57 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-01-09 16:29:35 ----A---- C:\WINDOWS\NeroDigital.ini
2011-01-09 12:02:28 ----D---- C:\Program Files\00 Mozilla Thunderbird
2011-01-07 03:32:23 ----D---- C:\WINDOWS\system32\drivers
2011-01-07 03:28:32 ----DC---- C:\WINDOWS\system32\DRVSTORE
2011-01-07 03:27:43 ----D---- C:\WINDOWS\system32\CatRoot
2011-01-07 02:31:24 ----D---- C:\WINDOWS\system32\config
2011-01-07 02:31:06 ----D---- C:\WINDOWS\system32\wbem
2011-01-07 02:31:04 ----D---- C:\WINDOWS\Registration
2011-01-07 02:30:28 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-01-07 02:30:22 ----D---- C:\Program Files\Spyware Terminator
2011-01-07 02:30:03 ----D---- C:\WINDOWS\system32\Restore
2011-01-07 02:22:43 ----D---- C:\Program Files\Common Files
2011-01-06 17:58:44 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\AIMP
2011-01-06 17:42:37 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Spyware Terminator
2011-01-06 17:31:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2011-01-06 16:35:17 ----D---- C:\Program Files\Messenger
2011-01-06 13:08:37 ----D---- C:\Program Files\00 Advanced SystemCare 3
2011-01-06 02:58:10 ----A---- C:\WINDOWS\win.ini
2011-01-06 02:58:10 ----A---- C:\WINDOWS\system.ini
2011-01-06 02:41:32 ----D---- C:\WINDOWS\security
2011-01-06 02:02:01 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Wireshark
2011-01-06 01:54:03 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\vlc
2010-12-12 03:45:20 ----A---- C:\WINDOWS\matlab.ini
2010-12-11 20:49:56 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\IObit
2010-12-11 15:18:18 ----D---- C:\Program Files\Google
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 Lbd;Lbd; C:\WINDOWS\system32\DRIVERS\Lbd.sys [2010-12-03 64288]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-06-14 691696]
R0 Teefer;Teefer for NT; C:\WINDOWS\SYSTEM32\Drivers\Teefer.sys [2004-08-10 59984]
R0 uagp35;Filtr Microsoft AGPv3.5; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-14 44672]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 nltdi;nltdi; \??\C:\WINDOWS\system32\drivers\nltdi.sys []
R1 PQNTDrv;PQNTDrv; C:\WINDOWS\system32\drivers\PQNTDrv.sys [2002-09-16 4228]
R1 wpsdrvnt;wpsdrvnt; \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys []
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-10-28 281760]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-10-28 25888]
R2 wg3n;SyGate for NT, wg3n; C:\WINDOWS\SYSTEM32\Drivers\wg3n.sys [2004-08-10 14240]
R2 wg4n;SyGate for NT, wg4n; C:\WINDOWS\SYSTEM32\Drivers\wg4n.sys [2004-08-10 14240]
R2 wg5n;SyGate for NT, wg5n; C:\WINDOWS\SYSTEM32\Drivers\wg5n.sys [2004-08-10 14240]
R2 wg6n;SyGate for NT, wg6n; C:\WINDOWS\SYSTEM32\Drivers\wg6n.sys [2004-08-10 14240]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-06-20 2324480]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-04-14 701440]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys [2006-11-07 21760]
R3 SISNIC;SiS PCI Fast Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\sisnic.sys [2008-04-13 32768]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 aelq9jnq;aelq9jnq; C:\WINDOWS\system32\drivers\aelq9jnq.sys []
S3 axosnj5c;axosnj5c; C:\WINDOWS\system32\drivers\axosnj5c.sys []
S3 Lavasoft Kernexplorer;Lavasoft helper driver; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys []
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2008-05-02 17536]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2008-05-02 20864]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2010-06-25 35088]
S3 Ser2pl;Prolific2 Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2005-07-25 48640]
S3 usbser;Nokia USB Serial Port; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-14 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2008-05-02 8064]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S4 vsdatant;vsdatant; C:\WINDOWS\system32\drivers\vsdatant.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-01 153376]
R2 matlabserver;MATLAB Server; C:\Program Files\00 MATLAB71\webserver\bin\win32\matlabserver.exe [2005-07-27 536576]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2010-06-14 75064]
R2 SmcService;Sygate Personal Firewall; C:\Program Files\00 Sygate\SPF\smc.exe [2004-09-02 2528480]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-05-10 488960]
R2 WinVNC4;VNC Server Version 4; C:\Program Files\00 VNC 4\WinVNC4.exe [2008-10-15 439632]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-12-11 136176]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2009-10-05 85096]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-12-03 1389400]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2010-06-25 117264]
S3 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S4 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
S4 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-10-26 654848]
S4 WinDefend;Windows Defender; C:\Program Files\00 Windows Defender\MsMpEng.exe [2006-11-03 13592]
-----------------EOF-----------------