Už jsem našel RSIT na ulozto. takže přikládám vygenerovaný log:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Kancelar at 2010-04-23 13:45:36
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 29 GB (72%) free of 40 GB
Total RAM: 2047 MB (78% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:45:43, on 23.4.10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VNICMon.exe
C:\Program Files\Smart PDF Creator Pro\sspdfagentd.exe
C:\Documents and Settings\Kancelar\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
C:\Program Files\Připomínač\Připomínač.exe
C:\Documents and Settings\Kancelar\Local Settings\Data aplikací\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\Kancelar\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Kancelar\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Kancelar\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Kancelar\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Kancelar\Dokumenty\Downloads\RSIT\RSIT.exe
C:\Program Files\trend micro\Kancelar.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [NIC Monitor] VNICMon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [SmartSoft PDF Printer (demo) Agent] "C:\Program Files\Smart PDF Creator Pro\sspdfagentd.exe"
O4 - HKLM\..\Run: [SmartSoft PDF Printer (demo) virtual printer agent] "C:\Program Files\Smart PDF Creator Pro\sspdfagentd.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Kancelar\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Pripominac] C:\Program Files\Připomínač\Připomínač.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ALLWIN.lnk = C:\ALLCOM\ALLWIN.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
--
End of file - 4075 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NIC Monitor"=C:\WINDOWS\system32\VNICMon.exe [2002-05-30 40960]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2008-03-11 689488]
"SmartSoft PDF Printer (demo) Agent"=C:\Program Files\Smart PDF Creator Pro\sspdfagentd.exe [2007-10-22 94208]
"SmartSoft PDF Printer (demo) virtual printer agent"=C:\Program Files\Smart PDF Creator Pro\sspdfagentd.exe [2007-10-22 94208]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Documents and Settings\Kancelar\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-02-01 135664]
"Pripominac"=C:\Program Files\Připomínač\Připomínač.exe [2003-01-05 577024]
C:\Documents and Settings\Kancelar\Nabídka Start\Programy\Po spuštění
ALLWIN.lnk - C:\ALLCOM\ALLWIN.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-04-23 13:45:36 ----D---- C:\rsit
2010-04-23 13:45:36 ----D---- C:\Program Files\trend micro
2010-04-22 16:21:24 ----SHD---- C:\RECYCLER
2010-04-22 15:02:17 ----D---- C:\WINDOWS\temp
2010-04-22 15:02:15 ----A---- C:\ComboFix.txt
2010-04-22 14:57:27 ----A---- C:\Boot.bak
2010-04-22 14:57:22 ----RASHD---- C:\cmdcons
2010-04-22 14:56:36 ----A---- C:\WINDOWS\zip.exe
2010-04-22 14:56:36 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-04-22 14:56:36 ----A---- C:\WINDOWS\SWSC.exe
2010-04-22 14:56:36 ----A---- C:\WINDOWS\SWREG.exe
2010-04-22 14:56:36 ----A---- C:\WINDOWS\sed.exe
2010-04-22 14:56:36 ----A---- C:\WINDOWS\PEV.exe
2010-04-22 14:56:36 ----A---- C:\WINDOWS\NIRCMD.exe
2010-04-22 14:56:36 ----A---- C:\WINDOWS\MBR.exe
2010-04-22 14:56:36 ----A---- C:\WINDOWS\grep.exe
2010-04-22 14:56:31 ----D---- C:\ComboFix
2010-04-22 14:55:11 ----D---- C:\WINDOWS\ERDNT
2010-04-22 14:55:10 ----A---- C:\WINDOWS\system32\CF17697.exe
2010-04-22 14:55:08 ----D---- C:\Qoobox
2010-04-22 14:06:55 ----D---- C:\Documents and Settings\Kancelar\Data aplikací\Malwarebytes
2010-04-22 14:06:45 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-04-22 14:06:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-03-25 14:13:18 ----A---- C:\WINDOWS\system32\MRT.exe
2010-03-25 13:10:21 ----HDC---- C:\WINDOWS\$NtUninstallKB926239$
2010-03-25 13:09:46 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-03-25 13:09:45 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2010-03-25 13:09:31 ----D---- C:\Program Files\Windows Media Connect 2
2010-03-25 13:08:37 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2010-03-25 13:08:10 ----D---- C:\WINDOWS\system32\LogFiles
2010-03-25 13:08:06 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
======List of files/folders modified in the last 1 months======
2010-04-23 13:45:37 ----D---- C:\WINDOWS\Prefetch
2010-04-23 13:45:36 ----RD---- C:\Program Files
2010-04-23 13:23:05 ----D---- C:\Documents and Settings\Kancelar\Data aplikací\Skype
2010-04-23 13:18:35 ----D---- C:\Vertigo
2010-04-23 12:11:53 ----D---- C:\Documents and Settings\Kancelar\Data aplikací\skypePM
2010-04-23 12:03:38 ----D---- C:\ALLCOM
2010-04-23 12:03:34 ----D---- C:\WINDOWS\system32
2010-04-22 17:00:53 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-04-22 15:02:17 ----D---- C:\WINDOWS
2010-04-22 15:01:46 ----SD---- C:\WINDOWS\Tasks
2010-04-22 15:01:04 ----A---- C:\WINDOWS\system.ini
2010-04-22 14:59:48 ----D---- C:\WINDOWS\system32\drivers
2010-04-22 14:59:48 ----D---- C:\WINDOWS\AppPatch
2010-04-22 14:59:46 ----D---- C:\Program Files\Common Files
2010-04-22 14:58:08 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-22 14:57:27 ----RASH---- C:\boot.ini
2010-04-22 14:15:12 ----SHD---- C:\WINDOWS\Installer
2010-04-19 17:05:27 ----D---- C:\Documents and Settings\All Users\Data aplikací\CanonIJPLM
2010-04-19 17:05:27 ----D---- C:\Documents and Settings\All Users\Data aplikací\CanonIJ
2010-04-15 14:19:34 ----HD---- C:\WINDOWS\inf
2010-04-14 11:26:00 ----SHD---- C:\System Volume Information
2010-04-14 11:26:00 ----D---- C:\WINDOWS\system32\Restore
2010-04-09 13:54:03 ----SD---- C:\Documents and Settings\Kancelar\Data aplikací\Microsoft
2010-04-09 11:23:52 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-07 09:36:06 ----D---- C:\OL30
2010-03-31 16:08:51 ----D---- C:\Program Files\Školní archiv
2010-03-29 08:34:26 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-26 10:15:19 ----A---- C:\WINDOWS\win.ini
2010-03-26 10:10:59 ----D---- C:\Program Files\Windows Media Player
2010-03-25 14:15:11 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-25 14:15:09 ----D---- C:\WINDOWS\Help
2010-03-25 14:13:23 ----D---- C:\WINDOWS\Debug
2010-03-25 13:09:48 ----A---- C:\WINDOWS\imsins.BAK
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-17 39936]
R3 FETNDIS;VIA Rhine Family Fast Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2002-03-21 36352]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 25856]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 VIAudio;VIA AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\viaudio.sys [2002-09-15 64128]
S3 catchme;catchme; \??\C:\DOCUME~1\Kancelar\LOCALS~1\Temp\catchme.sys []
S3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-10-25 9600]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
S3 NTSIM;NTSIM; \??\C:\WINDOWS\system32\ntsim.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 VNICPKT5;VNICPKT5 Protocol Driver; \??\C:\WINDOWS\system32\VNICPKT5.SYS []
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 IJPLMSVC;Inkjet Printer/Scanner Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2008-01-22 103808]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
-----------------EOF-----------------