Stránka 1 z 1

Preventivní kontrola

Napsal: 25 dub 2010 06:57
od Al Bunda
Prosím o preventvní kontrolu. Děkuji.

Logfile of random's system information tool 1.06 (written by random/random)
Run by Tibor at 2010-04-25 07:53:16
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 5 GB (22%) free of 20 GB
Total RAM: 2047 MB (71% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:53:33, on 25.4.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
d:\Programy\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
D:\Programy\Acronis\TrueImageHome\TrueImageMonitor.exe
D:\Programy\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
D:\Programy\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\Programy\Google\Gmail Notifier\gnotify.exe
C:\WINDOWS\RTHDCPL.EXE
D:\Programy\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
D:\Programy\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\astsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PSIService.exe
d:\Programy\Photodex\ProShowGold\ScsiAccess.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
D:\Programy\Altap Salamander 2.5\SALAMAND.exe
D:\Programy\TC UP\Plugins\Media\AIMP\AIMP2.exe
D:\Programy\Mozilla Firefox\firefox.exe
D:\d\RSIT.exe
C:\Program Files\trend micro\Tibor.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [TrueImageMonitor.exe] D:\Programy\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] D:\Programy\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "D:\Programy\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "D:\Programy\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] d:\Programy\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Programy\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Corel File Shell Monitor] D:\Programy\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
O4 - HKLM\..\Run: [avast5] d:\Programy\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\Programy\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Programy\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/L ... nstall.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{83D12583-75D7-4357-9702-E9A68B948BDA}: NameServer = 10.128.193.145
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: AST Service (astcc) - Nalpeiron Ltd. - C:\WINDOWS\system32\astsrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - d:\Programy\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - d:\Programy\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - d:\Programy\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Unknown owner - C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - d:\Programy\Photodex\ProShowGold\ScsiAccess.exe

--
End of file - 8165 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2010-04-03 349640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-19 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-19 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2010-04-03 349640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2010-04-03 349640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TrueImageMonitor.exe"=D:\Programy\Acronis\TrueImageHome\TrueImageMonitor.exe [2008-12-16 4375032]
"AcronisTimounterMonitor"=D:\Programy\Acronis\TrueImageHome\TimounterMonitor.exe [2008-12-16 962128]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2008-12-16 165144]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-09-27 86016]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-09-27 13918208]
"Adobe Acrobat Speed Launcher"=D:\Programy\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [2010-04-03 38840]
"Acrobat Assistant 8.0"=D:\Programy\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [2010-04-03 640440]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=d:\Programy\Google\Gmail Notifier\gnotify.exe [2005-07-15 479232]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-04-10 16861184]
"AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"Adobe Reader Speed Launcher"=D:\Programy\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
"Corel File Shell Monitor"=D:\Programy\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe [2008-01-15 16200]
"avast5"=d:\Programy\ALWILS~1\Avast5\avastUI.exe [2010-04-14 2790472]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-08-08 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"D:\Programy\Opera10\opera.exe"="D:\Programy\Opera10\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
"D:\Programy\eMule\emule.exe"="D:\Programy\eMule\emule.exe:*:Enabled:eMule"
"C:\f\DreamCom.exe"="C:\f\DreamCom.exe:*:Enabled:DreamCom"
"D:\Programy\TC UP\TOTALCMD.EXE"="D:\Programy\TC UP\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"
"D:\Programy\Opera\opera.exe"="D:\Programy\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"D:\Programy\Opera10.50\opera.exe"="D:\Programy\Opera10.50\opera.exe:*:Enabled:Opera Internet Browser"
"D:\Programy\Altap Salamander 2.5\SALAMAND.exe"="D:\Programy\Altap Salamander 2.5\SALAMAND.exe:*:Enabled:Altap Salamander, File Manager"
"D:\Programy\TC UP\PLUGINS\Media\uTorrent\utorrent.exe"="D:\Programy\TC UP\PLUGINS\Media\uTorrent\utorrent.exe:*:Enabled:µTorrent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2010-04-25 07:53:16 ----D---- C:\rsit
2010-04-24 18:28:12 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-04-24 18:28:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-04-24 08:01:08 ----SHD---- C:\RECYCLER
2010-04-24 07:45:07 ----A---- C:\mbam-error.txt
2010-04-24 07:42:15 ----A---- C:\ComboFix.txt
2010-04-23 23:20:52 ----A---- C:\WINDOWS\system32\DEVLOAD.EXE
2010-04-23 23:20:12 ----A---- C:\WINDOWS\SKLANG.INI
2010-04-23 23:20:12 ----A---- C:\WINDOWS\IsUninst.exe
2010-04-21 10:14:20 ----A---- C:\log.txt
2010-04-18 17:34:47 ----D---- C:\Program Files\Photodex Presenter
2010-04-18 17:32:27 ----D---- C:\Documents and Settings\All Users\Data aplikací\Photodex
2010-04-15 13:20:42 ----D---- C:\Recovered Files
2010-04-15 08:25:04 ----A---- C:\WINDOWS\system32\BASSMOD.dll
2010-04-14 19:38:09 ----A---- C:\WINDOWS\system32\kbdkor.dll
2010-04-14 19:38:09 ----A---- C:\WINDOWS\system32\kbdjpn.dll
2010-04-14 19:38:09 ----A---- C:\WINDOWS\system32\kbd103.dll
2010-04-14 19:38:09 ----A---- C:\WINDOWS\system32\kbd101c.dll
2010-04-14 19:38:08 ----A---- C:\WINDOWS\system32\kbd101b.dll
2010-04-14 19:38:07 ----A---- C:\WINDOWS\system32\kbd106.dll
2010-04-14 09:52:38 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-14 09:52:27 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-14 09:50:00 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-14 09:49:50 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-14 09:49:42 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-14 09:49:25 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-04-13 05:42:55 ----D---- C:\Program Files\MSXML 4.0
2010-04-12 09:50:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Corel
2010-04-12 09:49:16 ----D---- C:\Program Files\Common Files\Corel
2010-04-11 20:26:22 ----D---- C:\WINDOWS\system32\windows media
2010-04-11 20:26:12 ----D---- C:\WINDOWS\RegisteredPackages
2010-04-11 20:26:10 ----HD---- C:\WINDOWS\msdownld.tmp
2010-04-11 20:16:48 ----D---- C:\Documents and Settings\Tibor\Data aplikací\Corel
2010-04-11 15:58:39 ----A---- C:\WINDOWS\zip.exe
2010-04-11 15:58:39 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-04-11 15:58:39 ----A---- C:\WINDOWS\SWSC.exe
2010-04-11 15:58:39 ----A---- C:\WINDOWS\SWREG.exe
2010-04-11 15:58:39 ----A---- C:\WINDOWS\sed.exe
2010-04-11 15:58:39 ----A---- C:\WINDOWS\PEV.exe
2010-04-11 15:58:39 ----A---- C:\WINDOWS\NIRCMD.exe
2010-04-11 15:58:39 ----A---- C:\WINDOWS\MBR.exe
2010-04-11 15:58:39 ----A---- C:\WINDOWS\grep.exe
2010-04-11 15:57:32 ----A---- C:\WINDOWS\system32\CF6417.exe
2010-04-09 09:23:49 ----A---- C:\WINDOWS\Bench32.INI
2010-04-06 13:44:42 ----D---- C:\Documents and Settings\Tibor\Data aplikací\ZIP RAR ACE Password Recovery
2010-04-05 07:28:55 ----D---- C:\Program Files\MIKSOFT
2010-03-31 19:07:46 ----D---- C:\Documents and Settings\Tibor\Data aplikací\OfficeRecovery
2010-03-31 18:03:10 ----A---- C:\WINDOWS\system32\RaCoInst.dll
2010-03-29 20:29:33 ----A---- C:\WINDOWS\posta2.ini
2010-03-29 15:09:51 ----A---- C:\WINDOWS\system32\W32N55.INI
2010-03-29 15:09:51 ----A---- C:\WINDOWS\system32\W32N55.dll
2010-03-29 15:09:51 ----A---- C:\WINDOWS\system32\Scutum.dll
2010-03-29 15:09:51 ----A---- C:\WINDOWS\system32\RalinkGina.dll
2010-03-29 15:09:51 ----A---- C:\WINDOWS\system32\DiagFunc.ini
2010-03-29 15:09:50 ----A---- C:\WINDOWS\system32\DiagFunc.dll
2010-03-29 15:05:28 ----D---- C:\Documents and Settings\All Users\Data aplikací\Ralink Driver
2010-03-28 20:49:15 ----A---- C:\WINDOWS\system32\NCTWMAFile2.dll
2010-03-28 20:49:15 ----A---- C:\WINDOWS\system32\NCTAudioVisualization2.dll
2010-03-28 20:49:15 ----A---- C:\WINDOWS\system32\NCTAudioTransform2.dll
2010-03-28 20:49:15 ----A---- C:\WINDOWS\system32\NCTAudioRecord2.dll
2010-03-28 20:49:15 ----A---- C:\WINDOWS\system32\NCTAudioPlayer2.dll
2010-03-28 20:49:14 ----A---- C:\WINDOWS\system32\NCTAudioInformation2.dll
2010-03-28 20:49:14 ----A---- C:\WINDOWS\system32\NCTAudioFile2.dll
2010-03-28 20:49:14 ----A---- C:\WINDOWS\system32\NCTAudioEditor2.dll
2010-03-28 20:49:14 ----A---- C:\WINDOWS\system32\NCTAudioDisplay2.dll
2010-03-28 20:49:14 ----A---- C:\WINDOWS\system32\NCTAudioDesign2.dll
2010-03-28 20:49:14 ----A---- C:\WINDOWS\system32\NCTAudioCDGrabber2.dll
2010-03-28 20:49:13 ----A---- C:\WINDOWS\system32\msvcr70.dll
2010-03-28 15:51:11 ----D---- C:\Program Files\HDD Regenerator
2010-03-28 15:00:18 ----D---- C:\Program Files\Common Files\DVDVideoSoft
2010-03-28 14:11:23 ----D---- C:\Documents and Settings\Tibor\Data aplikací\vlc

======List of files/folders modified in the last 1 months======

2010-04-25 07:53:33 ----D---- C:\Program Files\trend micro
2010-04-25 06:09:37 ----D---- C:\c
2010-04-25 05:56:09 ----D---- C:\WINDOWS\Temp
2010-04-24 22:13:16 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-04-24 20:08:41 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-24 19:47:22 ----D---- C:\d
2010-04-24 18:30:53 ----AD---- C:\WINDOWS
2010-04-24 18:29:59 ----D---- C:\WINDOWS\system32\config
2010-04-24 18:28:22 ----D---- C:\WINDOWS\system32\drivers
2010-04-24 18:28:19 ----SHD---- C:\WINDOWS\Installer
2010-04-24 18:28:18 ----D---- C:\WINDOWS\WinSxS
2010-04-24 18:28:12 ----AD---- C:\WINDOWS\system32
2010-04-24 18:10:08 ----HD---- C:\WINDOWS\inf
2010-04-24 18:08:10 ----RD---- C:\Program Files
2010-04-24 18:08:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab
2010-04-24 07:45:05 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-04-24 07:42:28 ----D---- C:\Qoobox
2010-04-24 07:39:03 ----D---- C:\WINDOWS\Prefetch
2010-04-24 07:38:13 ----A---- C:\WINDOWS\system.ini
2010-04-24 07:36:43 ----D---- C:\WINDOWS\ERDNT
2010-04-24 07:35:24 ----D---- C:\WINDOWS\AppPatch
2010-04-24 07:35:23 ----D---- C:\Program Files\Common Files
2010-04-24 07:29:16 ----D---- C:\WINDOWS\Debug
2010-04-23 23:23:46 ----D---- C:\e
2010-04-23 20:14:34 ----D---- C:\foto
2010-04-22 09:01:10 ----D---- C:\Program Files\Common Files\InstallShield
2010-04-21 21:42:48 ----D---- C:\Documents and Settings\Tibor\Data aplikací\Mozilla
2010-04-21 10:04:16 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-04-19 20:28:38 ----D---- C:\Documents and Settings\Tibor\Data aplikací\dvdcss
2010-04-14 21:16:09 ----A---- C:\WINDOWS\win.ini
2010-04-14 20:48:45 ----D---- C:\Documents and Settings\Tibor\Data aplikací\Adobe
2010-04-14 15:16:39 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-04-14 09:52:34 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-11 21:05:29 ----RSD---- C:\WINDOWS\Fonts
2010-04-11 20:28:49 ----D---- C:\Program Files\Internet Explorer
2010-04-11 20:25:36 ----HD---- C:\Program Files\InstallShield Installation Information
2010-04-11 20:11:49 ----D---- C:\WINDOWS\system32\DirectX
2010-04-11 20:11:35 ----RSD---- C:\WINDOWS\assembly
2010-04-11 19:34:35 ----A---- C:\WINDOWS\disney.ini
2010-04-11 12:54:51 ----D---- C:\b
2010-04-06 19:52:54 ----A---- C:\WINDOWS\system32\MRT.exe
2010-03-31 19:57:59 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-03-31 11:42:16 ----D---- C:\Documents and Settings
2010-03-29 18:59:53 ----D---- C:\WINDOWS\system32\CatRoot
2010-03-29 15:10:37 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-29 15:09:44 ----ASD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-03-28 16:09:25 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-04-14 28880]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 43008]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-04-14 162768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-04-14 46672]
R1 FileDisk;FileDisk; C:\WINDOWS\system32\drivers\FileDisk.sys [2005-10-16 12928]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 PQNTDrv;PQNTDrv; C:\WINDOWS\system32\drivers\PQNTDrv.sys [2004-05-05 4228]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2009-11-09 59388]
R1 VD_FileDisk;VD_FileDisk; C:\WINDOWS\system32\drivers\VD_FileDisk.sys [2006-01-13 15872]
R2 adfs;adfs; C:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-04-14 19024]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-04-14 100432]
R2 irda;Protokol IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-14 88192]
R2 SBKUPNT;SBKUPNT; \??\C:\WINDOWS\system32\Drivers\SBKUPNT.SYS []
R2 Scutum50;Scutum50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\Scutum50.sys [2009-04-21 19072]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2009-11-19 44704]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-04-14 23376]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-04-17 4707328]
R3 irsir;Microsoft Serial Infrared Driver; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-09-27 7655872]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-09-11 57856]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-09-11 19968]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-11-23 47360]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2008-08-05 1684736]
S3 BIOSCHK;BIOSCHK; \??\C:\DOCUME~1\Tibor\LOCALS~1\Temp\tti8A7.tmp\disk1\BIOSCHK.SYS []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 FLASHSYS;FLASHSYS; \??\d:\Programy\MSI\Live Update 4\LU4\FLASHSYS.sys []
S3 FreshIO;FreshIO; \??\D:\Programy\FreshDevices\FreshDiagnose\FreshIO.sys []
S3 FTDIBUS;USB Serial Converter Driver; C:\WINDOWS\system32\drivers\ftdibus.sys [2009-10-22 57800]
S3 FTSER2K;USB Serial Port Driver; C:\WINDOWS\system32\drivers\ftser2k.sys [2009-10-22 72520]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2006-01-04 1389056]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\rt2870.sys [2009-08-03 724736]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys []
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2008-08-08 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-08-08 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-12-11 691696]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2008-12-16 554264]
R2 astcc;AST Service; C:\WINDOWS\system32\astsrv.exe [2009-11-20 57344]
R2 avast! Antivirus;avast! Antivirus; d:\Programy\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
R2 Irmon;Sledování infračerveného přenosu; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-17 153376]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-09-27 172100]
R2 ProtexisLicensing;ProtexisLicensing; C:\WINDOWS\system32\PSIService.exe [2007-06-05 177704]
R2 ScsiAccess;ScsiAccess; d:\Programy\Photodex\ProShowGold\ScsiAccess.exe [2010-04-18 186760]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; d:\Programy\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
R3 avast! Web Scanner;avast! Web Scanner; d:\Programy\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
S2 RalinkRegistryWriter;Ralink Registry Writer; C:\Program Files\Ralink\Common\RalinkRegistryWriter.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-12-12 867080]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Preventivní kontrola

Napsal: 25 dub 2010 13:58
od Rudy
Log vypadá čistý.