Stránka 1 z 1

Prosím o kontrolu logu

Napsal: 13 čer 2010 14:38
od katarina69
prosím o kontrolu logu:

Run by Robert at 2010-06-13 15:15:24
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 60 GB (63%) free of 95 GB
Total RAM: 2038 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:15:47, on 13.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Vista Components\Vista Drive Icon\DrvIcon.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Funcom\Dreamfall\dreamfall.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Robert\Plocha\RSIT.exe
C:\Program Files\trend micro\Robert.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=67233
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer - Microsoft Windows XP 2009 Ultra Edition
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [DrvIcon] C:\Program Files\Vista Components\Vista Drive Icon\DrvIcon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [NodTrialReset] regedit /s NodTrialReset.reg
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
O4 - HKLM\..\Run: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless WiFi Service (S24EventMonitor) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\WLKeeper.exe

--
End of file - 9729 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\MP Scheduled Scan.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00011268-E188-40DF-A514-835FCD78B1BF}]
IE7Pro BHO - C:\Program Files\IEPro\iepro.dll [2008-09-23 756840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-09-23 1088296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll [2008-08-11 656696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]
"AlwaysReady Power Message APP"=C:\WINDOWS\ARPWRMSG.EXE [2008-11-05 77312]
"DrvIcon"=C:\Program Files\Vista Components\Vista Drive Icon\DrvIcon.exe [2007-07-04 45056]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2006-11-03 866584]
"NodTrialReset"=regedit /s NodTrialReset.reg []
"SigmatelSysTrayApp"=C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe [2007-05-10 405504]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-03-30 138008]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-03-30 162584]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-03-30 138008]
"MSSE"=c:\Program Files\Microsoft Security Essentials\msseces.exe [2010-02-21 1093208]
"ProfilerU"=C:\Program Files\Saitek\SD6\Software\ProfilerU.exe [2009-06-03 237568]
"SaiMfd"=C:\Program Files\Saitek\SD6\Software\SaiMfd.exe [2009-06-03 131072]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-10-19 66560]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun []
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-03-30 204800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-24 267304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-09-23 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\WIFD1F~1\MpShHook.dll [2006-11-03 83224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"ForceClassicControlPanel"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Disabled:Run a DLL as an App"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2607aad6-6746-11df-9df1-001641b57b6b}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL "TrustPort USB\Common Files\bin\tptray.exe"


======List of files/folders created in the last 1 months======

2010-06-13 15:15:25 ----D---- C:\Program Files\trend micro
2010-06-13 15:15:24 ----D---- C:\rsit
2010-06-12 09:43:57 ----SHD---- C:\WINDOWS\CSC
2010-06-10 11:05:04 ----RA---- C:\WINDOWS\system32\ffpage32.dll
2010-06-10 11:05:03 ----RA---- C:\WINDOWS\system32\ffdriver32.Dll
2010-06-10 11:04:25 ----HDC---- C:\WINDOWS\$NtUninstallWdf01005$
2010-06-10 11:03:55 ----RA---- C:\WINDOWS\system32\WdfCoInstaller01005.dll
2010-06-09 23:29:24 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-06-09 23:29:10 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-06-09 23:22:26 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-06-09 23:18:08 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-09 23:16:52 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-06-09 23:14:56 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-06-09 12:58:00 ----A---- C:\WINDOWS\system32\hidserv.dll
2010-06-09 12:53:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\Saitek
2010-06-09 12:52:45 ----D---- C:\Program Files\Saitek
2010-06-08 03:05:17 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2010-06-08 02:42:43 ----D---- C:\Program Files\Funcom
2010-06-08 02:27:33 ----D---- C:\Program Files\PowerISO
2010-06-05 15:02:50 ----A---- C:\WINDOWS\CoD.INI
2010-06-05 01:01:57 ----D---- C:\Program Files\DAEMON Tools Lite
2010-06-05 01:01:11 ----D---- C:\Documents and Settings\Robert\Data aplikací\DAEMON Tools Lite
2010-06-05 01:01:06 ----D---- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
2010-06-04 23:39:10 ----D---- C:\Program Files\Microsoft ActiveSync
2010-06-03 23:32:13 ----D---- C:\WINDOWS\SoftwareDistribution
2010-06-03 19:11:50 ----A---- C:\WINDOWS\unvise32qt.exe
2010-06-03 19:11:33 ----D---- C:\WINDOWS\system32\QuickTime
2010-06-03 19:09:44 ----A---- C:\WINDOWS\IsUninst.exe
2010-06-02 13:15:40 ----D---- C:\Documents and Settings\Robert\Data aplikací\Gamelab
2010-06-01 11:45:24 ----D---- C:\Program Files\Microsoft Security Essentials
2010-06-01 11:41:47 ----D---- C:\246be863765b39d88baee1953d
2010-06-01 11:04:05 ----HDC---- C:\WINDOWS\$NtUninstallKB971513$
2010-05-31 22:38:46 ----A---- C:\WINDOWS\NeroDigital.ini
2010-05-30 12:16:43 ----D---- C:\Documents and Settings\All Users\Data aplikací\Trymedia
2010-05-29 21:43:07 ----D---- C:\WINDOWS\pss
2010-05-29 08:02:41 ----D---- C:\WINDOWS\system32\NtmsData
2010-05-27 18:19:46 ----D---- C:\Documents and Settings\Robert\Data aplikací\WinRAR
2010-05-27 18:13:09 ----D---- C:\Documents and Settings\Robert\Data aplikací\Dell
2010-05-27 18:11:24 ----A---- C:\WINDOWS\system32\stlang.dll
2010-05-27 18:11:24 ----A---- C:\WINDOWS\stsystra.exe
2010-05-27 18:09:58 ----A---- C:\WINDOWS\system32\stacapi.dll
2010-05-27 18:09:58 ----A---- C:\WINDOWS\system32\st325602.dll
2010-05-27 18:09:57 ----D---- C:\Program Files\SigmaTel
2010-05-27 17:58:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-05-27 17:40:49 ----D---- C:\WINDOWS\system32\Dell
2010-05-27 17:07:47 ----D---- C:\Program Files\Broadcom
2010-05-27 16:51:51 ----A---- C:\WINDOWS\system32\igfxres.dll
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igxprd32.dll
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igxpgd32.dll
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igxpdx32.dll
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igxpdv32.dll
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\iglicd32.dll
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igldev32.dll
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igfxzoom.exe
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igfxtray.exe
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igfxsrvc.exe
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igfxsrvc.dll
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igfxress.dll
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igfxpph.dll
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igfxpers.exe
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igfxext.exe
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igfxexps.dll
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igfxdo.dll
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igfxdev.dll
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igfxCoIn_v4814.dll
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\igfxcfg.exe
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\hkcmd.exe
2010-05-27 16:49:58 ----A---- C:\WINDOWS\system32\hccutils.dll
2010-05-27 16:49:56 ----D---- C:\WINDOWS\system32\Lang
2010-05-27 16:49:56 ----A---- C:\WINDOWS\system32\igxpun.exe
2010-05-27 16:49:56 ----A---- C:\WINDOWS\system32\difxapi.dll
2010-05-27 16:49:01 ----D---- C:\Intel
2010-05-27 16:34:49 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-05-27 16:34:07 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-05-27 16:23:00 ----D---- C:\WINDOWS\system32\appmgmt
2010-05-26 12:09:58 ----SHD---- C:\RECYCLER
2010-05-26 11:38:45 ----A---- C:\WINDOWS\ModemLog_Standardní modem připojený pomocí technologie Bluetooth.txt
2010-05-25 05:17:13 ----D---- C:\cb1667bec25e354dc71c2063
2010-05-25 05:16:53 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-05-25 05:15:22 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-05-25 04:15:27 ----D---- C:\Documents and Settings\Robert\Data aplikací\uTorrent
2010-05-25 03:07:23 ----D---- C:\WINDOWS\system32\XPSViewer
2010-05-25 03:07:13 ----D---- C:\WINDOWS\system32\en-US
2010-05-25 03:07:04 ----D---- C:\Program Files\Reference Assemblies
2010-05-25 03:06:30 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-05-25 03:06:30 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-05-25 03:06:29 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-05-25 03:06:29 ----D---- C:\0e3b0cacd63588c81f6b0e3a25bf48
2010-05-25 00:44:26 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-05-25 00:44:16 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-05-25 00:44:04 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-05-25 00:42:19 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-05-25 00:42:07 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-05-25 00:41:55 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-05-25 00:41:44 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-05-25 00:41:31 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-05-25 00:41:20 ----HDC---- C:\WINDOWS\$NtUninstallKB970483$
2010-05-25 00:41:09 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-05-25 00:40:59 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-05-25 00:40:50 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2010-05-25 00:40:41 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-05-25 00:40:30 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-05-25 00:40:21 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-05-25 00:40:11 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-05-25 00:40:02 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-05-25 00:39:51 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-05-25 00:39:42 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-05-25 00:39:31 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-05-25 00:39:14 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-05-25 00:39:03 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-05-25 00:38:52 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-05-25 00:38:40 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-05-25 00:38:26 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-05-24 23:59:02 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-05-24 23:57:02 ----D---- C:\Program Files\Dell
2010-05-24 23:56:46 ----D---- C:\Program Files\Common Files\InstallShield
2010-05-24 23:55:16 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-05-24 23:55:03 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-05-24 23:54:48 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-05-24 23:54:34 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-05-24 23:54:22 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-05-24 23:54:10 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-05-24 23:53:59 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-05-24 23:53:43 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-05-24 23:53:26 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-05-24 23:06:53 ----D---- C:\Program Files\IDT
2010-05-24 23:06:47 ----A---- C:\WINDOWS\system32\ksuser.dll
2010-05-24 21:46:31 ----D---- C:\Documents and Settings\Robert\Data aplikací\ESET
2010-05-24 21:44:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2010-05-24 21:23:50 ----D---- C:\Documents and Settings\Robert\Data aplikací\Macromedia
2010-05-24 21:23:50 ----D---- C:\Documents and Settings\Robert\Data aplikací\Adobe
2010-05-24 21:17:58 ----D---- C:\WINDOWS\ie8updates
2010-05-24 21:15:36 ----HDC---- C:\WINDOWS\ie8
2010-05-24 21:12:52 ----A---- C:\WINDOWS\system32\MRT.exe
2010-05-24 21:09:51 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-05-24 21:08:31 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-05-24 21:08:23 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-05-24 21:08:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-05-24 21:07:24 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-05-24 21:07:16 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-05-24 21:05:12 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-05-24 21:04:12 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-05-24 21:04:04 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-05-24 21:03:52 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-05-24 20:56:34 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-05-24 20:55:08 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
2010-05-24 20:51:57 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-05-24 20:34:25 ----D---- C:\Downloads
2010-05-24 20:33:52 ----D---- C:\Documents and Settings\Robert\Data aplikací\IEPro
2010-05-24 19:49:56 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-05-24 19:41:38 ----D---- C:\Documents and Settings\Robert\Data aplikací\Mozilla
2010-05-24 19:16:28 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2010-05-24 19:12:56 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-05-24 19:06:24 ----D---- C:\Documents and Settings\Robert\Data aplikací\Intel
2010-05-24 19:05:50 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-05-24 19:05:50 ----A---- C:\WINDOWS\system32\NETw5r32.dll
2010-05-24 19:05:50 ----A---- C:\WINDOWS\system32\NETw5c32.dll
2010-05-24 19:05:19 ----D---- C:\Program Files\Intel
2010-05-24 19:05:19 ----D---- C:\Program Files\Common Files\Intel
2010-05-24 19:05:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\Intel
2010-05-24 19:04:22 ----A---- C:\WINDOWS\iProInstLog.txt
2010-05-24 19:03:28 ----D---- C:\dell
2010-05-24 18:58:42 ----D---- C:\Documents and Settings\Robert\Data aplikací\TrustPort
2010-05-24 17:41:39 ----D---- C:\Documents and Settings\Robert\Data aplikací\Skype
2010-05-24 17:40:32 ----A---- C:\WINDOWS\system32\wmpns.dll
2010-05-24 17:40:29 ----D---- C:\Documents and Settings\Robert\Data aplikací\Identities
2010-05-24 17:40:07 ----HD---- C:\Program Files\Uninstall Information
2010-05-24 17:37:56 ----D---- C:\Program Files\Windows Defender
2010-05-24 17:37:40 ----D---- C:\Program Files\Notepad++
2010-05-24 17:37:40 ----D---- C:\Documents and Settings\Robert\Data aplikací\Notepad++
2010-05-24 17:35:52 ----RA---- C:\WINDOWS\system32\TwnLib20.dll
2010-05-24 17:35:49 ----RA---- C:\WINDOWS\system32\picn20.dll
2010-05-24 17:35:48 ----RA---- C:\WINDOWS\system32\imagx5.dll
2010-05-24 17:35:48 ----RA---- C:\WINDOWS\system32\imagr5.dll
2010-05-24 17:35:47 ----RA---- C:\WINDOWS\system32\ImagXpr5.dll
2010-05-24 17:35:46 ----RA---- C:\WINDOWS\system32\NeroCheck.exe
2010-05-24 17:35:46 ----D---- C:\Program Files\Common Files\Ahead
2010-05-24 17:35:41 ----D---- C:\Program Files\Ahead
2010-05-24 17:35:28 ----D---- C:\Documents and Settings\All Users\Data aplikací\DVD Shrink
2010-05-24 17:35:27 ----D---- C:\Program Files\DVD Shrink
2010-05-24 17:35:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\NVIDIA Corporation
2010-05-24 17:35:05 ----A---- C:\WINDOWS\system32\MFC71.dll
2010-05-24 17:35:05 ----A---- C:\WINDOWS\system32\DSETUP.dll
2010-05-24 17:35:05 ----A---- C:\WINDOWS\system32\DolbyHph.dll
2010-05-24 17:35:05 ----A---- C:\WINDOWS\system32\atl71.dll
2010-05-24 17:35:04 ----HD---- C:\Program Files\InstallShield Installation Information
2010-05-24 17:34:42 ----D---- C:\extensions
2010-05-24 17:34:38 ----D---- C:\Program Files\BitComet
2010-05-24 17:34:30 ----D---- C:\Program Files\Total Commander
2010-05-24 17:34:26 ----D---- C:\Program Files\VisualTaskTips
2010-05-24 17:33:59 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2010-05-24 17:33:59 ----A---- C:\WINDOWS\system32\pndx5032.dll
2010-05-24 17:33:59 ----A---- C:\WINDOWS\system32\pndx5016.dll
2010-05-24 17:33:59 ----A---- C:\WINDOWS\system32\pncrt.dll
2010-05-24 17:33:58 ----A---- C:\WINDOWS\system32\unrar.dll
2010-05-24 17:33:57 ----A---- C:\WINDOWS\avisplitter.ini
2010-05-24 17:33:53 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2010-05-24 17:33:53 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2010-05-24 17:33:53 ----A---- C:\WINDOWS\system32\xvidcore.dll
2010-05-24 17:33:52 ----A---- C:\WINDOWS\system32\qt-dx331.dll
2010-05-24 17:33:52 ----A---- C:\WINDOWS\system32\dpl100.dll
2010-05-24 17:33:51 ----A---- C:\WINDOWS\system32\divx.dll
2010-05-24 17:33:50 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
2010-05-24 17:33:50 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2010-05-24 17:33:48 ----A---- C:\WINDOWS\system32\msvcr71.dll
2010-05-24 17:33:48 ----A---- C:\WINDOWS\system32\msvcp71.dll
2010-05-24 17:33:47 ----D---- C:\Program Files\K-Lite Codec Pack
2010-05-24 17:33:47 ----D---- C:\Documents and Settings\Robert\Data aplikací\Real
2010-05-24 17:33:47 ----D---- C:\Documents and Settings\All Users\Data aplikací\Real
2010-05-24 17:33:34 ----D---- C:\Program Files\IrfanView
2010-05-24 17:33:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-05-24 17:32:55 ----D---- C:\Program Files\Common Files\Adobe
2010-05-24 17:32:55 ----D---- C:\Program Files\Adobe
2010-05-24 17:31:47 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2010-05-24 17:31:41 ----D---- C:\Program Files\Google
2010-05-24 17:31:34 ----D---- C:\Program Files\Skype
2010-05-24 17:31:33 ----D---- C:\Program Files\Common Files\Skype
2010-05-24 17:31:27 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2010-05-24 17:31:00 ----D---- C:\Program Files\ICQ6
2010-05-24 17:30:52 ----D---- C:\Program Files\WinRAR
2010-05-24 17:30:48 ----D---- C:\Program Files\7-Zip
2010-05-24 17:24:31 ----A---- C:\WINDOWS\system32\msonpmon.dll
2010-05-24 17:22:51 ----D---- C:\Program Files\Microsoft Works
2010-05-24 17:22:40 ----D---- C:\Program Files\MSBuild
2010-05-24 17:22:20 ----D---- C:\Program Files\Microsoft Visual Studio
2010-05-24 17:22:20 ----D---- C:\Program Files\Common Files\DESIGNER
2010-05-24 17:21:41 ----D---- C:\Program Files\Microsoft.NET
2010-05-24 17:18:28 ----D---- C:\WINDOWS\SHELLNEW
2010-05-24 17:18:13 ----D---- C:\Program Files\Microsoft Office
2010-05-24 17:18:13 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-05-24 17:17:56 ----RHD---- C:\MSOCache
2010-05-24 17:17:15 ----D---- C:\Program Files\Mozilla Firefox
2010-05-24 17:17:01 ----D---- C:\Program Files\IEPro
2010-05-24 17:13:01 ----A---- C:\WINDOWS\system32\javaws.exe
2010-05-24 17:13:01 ----A---- C:\WINDOWS\system32\javaw.exe
2010-05-24 17:13:01 ----A---- C:\WINDOWS\system32\java.exe
2010-05-24 17:12:29 ----D---- C:\Program Files\Java
2010-05-24 17:12:27 ----D---- C:\Program Files\Common Files\Java
2010-05-24 17:12:22 ----D---- C:\Documents and Settings\Robert\Data aplikací\Sun
2010-05-24 17:07:59 ----D---- C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage
2010-05-24 17:07:54 ----ASH---- C:\Documents and Settings\Robert\Data aplikací\desktop.ini
2010-05-24 17:07:53 ----SD---- C:\Documents and Settings\Robert\Data aplikací\Microsoft
2010-05-24 17:03:29 ----D---- C:\WINDOWS\IIS Temporary Compressed Files
2010-05-24 17:03:27 ----D---- C:\WINDOWS\Prefetch
2010-05-24 17:03:26 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-05-24 16:11:31 ----A---- C:\WINDOWS\system32\h323log.txt
2010-05-24 15:55:23 ----A---- C:\WINDOWS\system32\wshirda.dll
2010-05-24 15:55:23 ----A---- C:\WINDOWS\system32\irmon.dll
2010-05-24 15:55:23 ----A---- C:\WINDOWS\system32\irftp.exe
2010-05-24 15:53:42 ----A---- C:\WINDOWS\system32\usbui.dll
2010-05-24 15:51:46 ----A---- C:\WINDOWS\imsins.BAK
2010-05-24 15:51:42 ----SHD---- C:\WINDOWS\Installer
2010-05-24 15:51:42 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-05-24 15:51:41 ----D---- C:\Program Files\Common Files\ODBC
2010-05-24 15:51:41 ----A---- C:\WINDOWS\ODBCINST.INI
2010-05-24 15:51:34 ----D---- C:\Program Files\Common Files\SpeechEngines
2010-05-24 15:51:33 ----RD---- C:\Program Files
2010-05-24 15:51:33 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-05-24 15:51:33 ----D---- C:\Program Files\Common Files
2010-05-24 15:51:26 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2010-05-24 15:51:25 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2010-05-24 15:51:25 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2010-05-24 15:51:22 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2010-05-24 15:51:22 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2010-05-24 15:51:21 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2010-05-24 15:51:21 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2010-05-24 15:51:21 ----RA---- C:\WINDOWS\system32\kbdur.dll
2010-05-24 15:51:21 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2010-05-24 15:51:21 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2010-05-24 15:51:21 ----RA---- C:\WINDOWS\system32\kbdru.dll
2010-05-24 15:51:21 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2010-05-24 15:51:21 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2010-05-24 15:51:21 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2010-05-24 15:51:20 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2010-05-24 15:51:17 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2010-05-24 15:51:17 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2010-05-24 15:51:17 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2010-05-24 15:51:17 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2010-05-24 15:51:17 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2010-05-24 15:51:16 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2010-05-24 15:51:16 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2010-05-24 15:51:13 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2010-05-24 15:51:13 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2010-05-24 15:51:13 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2010-05-24 15:51:13 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2010-05-24 15:51:13 ----RA---- C:\WINDOWS\system32\kbdest.dll
2010-05-24 15:51:00 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2010-05-24 15:51:00 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2010-05-24 15:51:00 ----RA---- C:\WINDOWS\system32\kbdro.dll
2010-05-24 15:51:00 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2010-05-24 15:51:00 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2010-05-24 15:50:59 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2010-05-24 15:50:59 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2010-05-24 15:50:59 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2010-05-24 15:50:59 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2010-05-24 15:50:59 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2010-05-24 15:50:56 ----A---- C:\WINDOWS\system32\irclass.dll
2010-05-24 15:50:56 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2010-05-24 15:50:55 ----A---- C:\WINDOWS\system32\spxcoins.dll
2010-05-24 15:50:55 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2010-05-24 15:50:55 ----A---- C:\WINDOWS\system32\dgsetup.dll
2010-05-24 15:50:51 ----A---- C:\WINDOWS\TASKMAN.EXE
2010-05-24 15:50:50 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2010-05-24 15:50:50 ----A---- C:\WINDOWS\system32\batt.dll
2010-05-24 15:50:48 ----A---- C:\WINDOWS\system32\storprop.dll
2010-05-24 15:50:37 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\desktop.ini
2010-05-24 15:50:25 ----RA---- C:\WINDOWS\SET8.tmp
2010-05-24 15:50:22 ----RA---- C:\WINDOWS\SET4.tmp
2010-05-24 15:50:19 ----RA---- C:\WINDOWS\SET3.tmp
2010-05-24 15:50:13 ----D---- C:\WINDOWS\system32\CatRoot2
2010-05-24 15:50:13 ----D---- C:\WINDOWS\system32\CatRoot
2010-05-24 15:50:07 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-05-24 15:49:43 ----A---- C:\WINDOWS\setuplog.txt
2010-05-24 15:25:19 ----D---- C:\Documents and Settings
2010-05-24 15:25:18 ----SHD---- C:\System Volume Information
2010-05-24 15:24:20 ----SH---- C:\boot.ini
2010-05-24 15:15:05 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-05-24 15:15:05 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-05-24 15:15:05 ----RSD---- C:\WINDOWS\Fonts
2010-05-24 15:15:05 ----RD---- C:\WINDOWS\Web
2010-05-24 15:15:05 ----HD---- C:\WINDOWS\inf
2010-05-24 15:15:05 ----D---- C:\WINDOWS\WinSxS
2010-05-24 15:15:05 ----D---- C:\WINDOWS\WBEM
2010-05-24 15:15:05 ----D---- C:\WINDOWS\twain_32
2010-05-24 15:15:05 ----D---- C:\WINDOWS\Temp
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\wins
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\wbem
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\usmt
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\spool
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\ShellExt
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\Setup
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\ras
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\oobe
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\npp
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\mui
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\inetsrv
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\IME
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\icsxml
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\ias
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\export
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\drivers
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\dhcp
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\cs-cz
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\cs
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\config
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\3com_dmi
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\3076
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\2052
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\1054
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\1042
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\1041
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\1037
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\1033
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\1031
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\1029
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\1028
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32\1025
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system32
2010-05-24 15:15:05 ----D---- C:\WINDOWS\system
2010-05-24 15:15:05 ----D---- C:\WINDOWS\security
2010-05-24 15:15:05 ----D---- C:\WINDOWS\SDTEmp
2010-05-24 15:15:05 ----D---- C:\WINDOWS\Resources
2010-05-24 15:15:05 ----D---- C:\WINDOWS\repair
2010-05-24 15:15:05 ----D---- C:\WINDOWS\Provisioning
2010-05-24 15:15:05 ----D---- C:\WINDOWS\pchealth
2010-05-24 15:15:05 ----D---- C:\WINDOWS\PeerNet
2010-05-24 15:15:05 ----D---- C:\WINDOWS\Offline Web Pages
2010-05-24 15:15:05 ----D---- C:\WINDOWS\Network Diagnostic
2010-05-24 15:15:05 ----D---- C:\WINDOWS\mui
2010-05-24 15:15:05 ----D---- C:\WINDOWS\msapps
2010-05-24 15:15:05 ----D---- C:\WINDOWS\msagent
2010-05-24 15:15:05 ----D---- C:\WINDOWS\Media
2010-05-24 15:15:05 ----D---- C:\WINDOWS\L2Schemas
2010-05-24 15:15:05 ----D---- C:\WINDOWS\java
2010-05-24 15:15:05 ----D---- C:\WINDOWS\ime
2010-05-24 15:15:05 ----D---- C:\WINDOWS\Help
2010-05-24 15:15:05 ----D---- C:\WINDOWS\ehome
2010-05-24 15:15:05 ----D---- C:\WINDOWS\Driver Cache
2010-05-24 15:15:05 ----D---- C:\WINDOWS\Debug
2010-05-24 15:15:05 ----D---- C:\WINDOWS\Cursors
2010-05-24 15:15:05 ----D---- C:\WINDOWS\Connection Wizard
2010-05-24 15:15:05 ----D---- C:\WINDOWS\Config
2010-05-24 15:15:05 ----D---- C:\WINDOWS\AppPatch
2010-05-24 15:15:05 ----D---- C:\WINDOWS\addins
2010-05-24 15:15:05 ----D---- C:\WINDOWS
2010-05-24 14:53:43 ----D---- C:\WINDOWS\system32\xircom
2010-05-24 14:53:43 ----D---- C:\Program Files\xerox
2010-05-24 14:53:43 ----D---- C:\Program Files\microsoft frontpage
2010-05-24 14:52:46 ----D---- C:\Program Files\Microsoft Games
2010-05-24 14:52:24 ----D---- C:\Program Files\Vista Components
2010-05-24 14:52:05 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2010-05-24 14:51:51 ----D---- C:\Program Files\Alky for Applications
2010-05-24 14:45:52 ----D---- C:\WINDOWS\system32\URTTemp
2010-05-24 14:45:38 ----RSD---- C:\WINDOWS\assembly
2010-05-24 14:44:04 ----D---- C:\Program Files\Microsoft Silverlight
2010-05-24 14:42:08 ----D---- C:\WINDOWS\system32\PreInstall
2010-05-24 14:41:16 ----HD---- C:\WINDOWS\$hf_mig$
2010-05-24 14:41:07 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-05-24 14:41:07 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2010-05-24 14:40:42 ----A---- C:\WINDOWS\control.ini
2010-05-24 14:40:42 ----A---- C:\AUTOEXEC.BAT
2010-05-24 14:40:09 ----A---- C:\WINDOWS\OEWABLog.txt
2010-05-24 14:40:02 ----A---- C:\WINDOWS\system32\mapi32.dll
2010-05-24 14:36:54 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2010-05-24 14:36:44 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2010-05-24 14:36:31 ----HD---- C:\Program Files\WindowsUpdate
2010-05-24 14:36:25 ----D---- C:\Program Files\Online Services
2010-05-24 14:35:35 ----D---- C:\WINDOWS\system32\DirectX
2010-05-24 14:35:14 ----A---- C:\WINDOWS\system32\atrace.dll
2010-05-24 14:35:08 ----A---- C:\WINDOWS\system32\desktop.ini
2010-05-24 14:35:08 ----A---- C:\WINDOWS\desktop.ini
2010-05-24 14:34:55 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2010-05-24 14:34:53 ----A---- C:\WINDOWS\system32\acctres.dll
2010-05-24 14:34:52 ----D---- C:\Program Files\Common Files\Services
2010-05-24 14:34:45 ----SD---- C:\WINDOWS\Tasks
2010-05-24 14:34:45 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2010-05-24 14:34:43 ----D---- C:\Program Files\Common Files\MSSoap
2010-05-24 14:34:33 ----D---- C:\WINDOWS\srchasst
2010-05-24 14:34:30 ----D---- C:\WINDOWS\system32\Macromed
2010-05-24 14:34:26 ----A---- C:\WINDOWS\system32\wuweb.dll
2010-05-24 14:34:25 ----A---- C:\WINDOWS\system32\wucltui.dll
2010-05-24 14:34:25 ----A---- C:\WINDOWS\system32\wuauserv.dll
2010-05-24 14:34:25 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2010-05-24 14:34:24 ----A---- C:\WINDOWS\system32\wuaueng.dll
2010-05-24 14:34:23 ----A---- C:\WINDOWS\system32\wups.dll
2010-05-24 14:34:23 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2010-05-24 14:34:22 ----A---- C:\WINDOWS\system32\wuauclt.exe
2010-05-24 14:34:22 ----A---- C:\WINDOWS\system32\wuapi.dll
2010-05-24 14:34:21 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2010-05-24 14:34:21 ----A---- C:\WINDOWS\system32\qmgr.dll
2010-05-24 14:34:21 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2010-05-24 14:34:21 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2010-05-24 14:34:21 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2010-05-24 14:33:23 ----A---- C:\WINDOWS\system32\safrslv.dll
2010-05-24 14:33:23 ----A---- C:\WINDOWS\system32\safrdm.dll
2010-05-24 14:33:22 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2010-05-24 14:33:22 ----A---- C:\WINDOWS\system32\racpldlg.dll
2010-05-24 14:33:11 ----A---- C:\WINDOWS\system32\fltMc.exe
2010-05-24 14:33:11 ----A---- C:\WINDOWS\system32\fltlib.dll
2010-05-24 14:33:10 ----D---- C:\WINDOWS\system32\Restore
2010-05-24 14:33:10 ----A---- C:\WINDOWS\system32\srrstr.dll
2010-05-24 14:33:09 ----A---- C:\WINDOWS\system32\srsvc.dll
2010-05-24 14:33:09 ----A---- C:\WINDOWS\system32\srclient.dll
2010-05-24 14:33:08 ----A---- C:\WINDOWS\system32\ils.dll
2010-05-24 14:33:07 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2010-05-24 14:33:07 ----A---- C:\WINDOWS\system32\mnmdd.dll
2010-05-24 14:33:07 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2010-05-24 14:33:06 ----A---- C:\WINDOWS\system32\msconf.dll
2010-05-24 14:33:06 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2010-05-24 14:33:00 ----D---- C:\Program Files\NetMeeting
2010-05-24 14:32:59 ----A---- C:\WINDOWS\system32\msoert2.dll
2010-05-24 14:32:59 ----A---- C:\WINDOWS\system32\msoeacct.dll
2010-05-24 14:32:56 ----A---- C:\WINDOWS\system32\inetres.dll
2010-05-24 14:32:55 ----AC---- C:\WINDOWS\system32\inetcomm.dll
2010-05-24 14:32:50 ----D---- C:\Program Files\Outlook Express
2010-05-24 14:32:50 ----A---- C:\WINDOWS\system32\schedsvc.dll
2010-05-24 14:32:50 ----A---- C:\WINDOWS\system32\mstinit.exe
2010-05-24 14:32:49 ----A---- C:\WINDOWS\system32\mstask.dll
2010-05-24 14:32:48 ----A---- C:\WINDOWS\system32\isign32.dll
2010-05-24 14:32:48 ----A---- C:\WINDOWS\system32\icwphbk.dll
2010-05-24 14:32:48 ----A---- C:\WINDOWS\system32\icwdial.dll
2010-05-24 14:32:47 ----A---- C:\WINDOWS\system32\inetcfg.dll
2010-05-24 14:32:32 ----D---- C:\Program Files\Common Files\System
2010-05-24 14:32:25 ----D---- C:\Program Files\Internet Explorer
2010-05-24 14:30:34 ----D---- C:\Program Files\ComPlus Applications
2010-05-24 14:30:31 ----A---- C:\WINDOWS\vbaddin.ini
2010-05-24 14:30:31 ----A---- C:\WINDOWS\vb.ini
2010-05-24 14:30:25 ----D---- C:\WINDOWS\Registration
2010-05-24 14:30:15 ----SD---- C:\WINDOWS\system32\Microsoft
2010-05-24 14:30:14 ----D---- C:\WINDOWS\system32\Cache
2010-05-24 14:27:38 ----D---- C:\Program Files\VistaExperience.org
2010-05-24 14:23:37 ----D---- C:\Program Files\Windows Sidebar
2010-05-24 14:21:52 ----D---- C:\Program Files\Windows Plus
2010-05-24 14:21:17 ----D---- C:\Program Files\Windows Media Connect 2
2010-05-24 14:20:04 ----D---- C:\WINDOWS\Microsoft.NET
2010-05-24 14:16:51 ----D---- C:\Program Files\Windows Media Player
2010-05-24 14:16:50 ----D---- C:\Program Files\Movie Maker
2010-05-24 14:16:50 ----A---- C:\WINDOWS\system32\mhn.dll
2010-05-24 14:16:49 ----A---- C:\WINDOWS\system32\igdetect.dll
2010-05-24 14:15:20 ----D---- C:\Program Files\Messenger
2010-05-24 14:15:10 ----A---- C:\WINDOWS\system32\w3svapi.dll
2010-05-24 14:15:10 ----A---- C:\WINDOWS\system32\w3ctrs.ini
2010-05-24 14:15:10 ----A---- C:\WINDOWS\system32\w3ctrs.dll
2010-05-24 14:15:09 ----A---- C:\WINDOWS\system32\axperf.ini
2010-05-24 14:15:09 ----A---- C:\WINDOWS\system32\aspperf.dll
2010-05-24 14:15:08 ----A---- C:\WINDOWS\system32\wamregps.dll
2010-05-24 14:15:08 ----A---- C:\WINDOWS\system32\iisrstap.dll
2010-05-24 14:15:08 ----A---- C:\WINDOWS\system32\iisreset.exe
2010-05-24 14:15:08 ----A---- C:\WINDOWS\system32\ftpsapi2.dll
2010-05-24 14:15:07 ----A---- C:\WINDOWS\system32\infoctrs.ini
2010-05-24 14:15:07 ----A---- C:\WINDOWS\system32\infoctrs.dll
2010-05-24 14:15:07 ----A---- C:\WINDOWS\system32\inetsloc.dll
2010-05-24 14:15:07 ----A---- C:\WINDOWS\system32\iismui.dll
2010-05-24 14:15:07 ----A---- C:\WINDOWS\system32\convlog.exe
2010-05-24 14:15:06 ----A---- C:\WINDOWS\system32\admxprox.dll
2010-05-24 14:14:58 ----D---- C:\Program Files\MSN Gaming Zone
2010-05-24 14:14:58 ----A---- C:\WINDOWS\system32\write.exe
2010-05-24 14:14:29 ----A---- C:\WINDOWS\system32\sndvol32.exe
2010-05-24 14:14:28 ----A---- C:\WINDOWS\system32\hticons.dll
2010-05-24 14:14:28 ----A---- C:\WINDOWS\system32\avwav.dll
2010-05-24 14:14:27 ----A---- C:\WINDOWS\system32\avtapi.dll
2010-05-24 14:14:27 ----A---- C:\WINDOWS\system32\avmeter.dll
2010-05-24 14:14:26 ----A---- C:\WINDOWS\system32\winchat.exe
2010-05-24 14:14:10 ----A---- C:\WINDOWS\system32\getuname.dll
2010-05-24 14:14:09 ----A---- C:\WINDOWS\system32\charmap.exe
2010-05-24 14:14:07 ----A---- C:\WINDOWS\system32\winmine.exe
2010-05-24 14:14:07 ----A---- C:\WINDOWS\system32\sol.exe
2010-05-24 14:14:06 ----A---- C:\WINDOWS\system32\mshearts.exe
2010-05-24 14:14:05 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2010-05-24 14:14:05 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2010-05-24 14:14:05 ----A---- C:\WINDOWS\system32\tskill.exe
2010-05-24 14:14:05 ----A---- C:\WINDOWS\system32\reset.exe
2010-05-24 14:14:05 ----A---- C:\WINDOWS\system32\freecell.exe
2010-05-24 14:14:04 ----A---- C:\WINDOWS\system32\tslabels.ini
2010-05-24 14:14:04 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2010-05-24 14:14:04 ----A---- C:\WINDOWS\system32\tscon.exe
2010-05-24 14:14:04 ----A---- C:\WINDOWS\system32\shadow.exe
2010-05-24 14:14:04 ----A---- C:\WINDOWS\system32\rwinsta.exe
2010-05-24 14:14:03 ----A---- C:\WINDOWS\system32\regini.exe
2010-05-24 14:14:03 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2010-05-24 14:14:03 ----A---- C:\WINDOWS\system32\qwinsta.exe
2010-05-24 14:14:03 ----A---- C:\WINDOWS\system32\qappsrv.exe
2010-05-24 14:14:03 ----A---- C:\WINDOWS\system32\msg.exe
2010-05-24 14:14:02 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2010-05-24 14:14:02 ----A---- C:\WINDOWS\system32\logoff.exe
2010-05-24 14:14:02 ----A---- C:\WINDOWS\system32\cdmodem.dll
2010-05-24 14:13:47 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2010-05-24 14:13:42 ----A---- C:\WINDOWS\system32\smtpapi.dll
2010-05-24 14:13:42 ----A---- C:\WINDOWS\system32\rwnh.dll
2010-05-24 14:13:40 ----A---- C:\WINDOWS\system32\infoadmn.dll
2010-05-24 14:13:40 ----A---- C:\WINDOWS\system32\iisext.dll
2010-05-24 14:13:40 ----A---- C:\WINDOWS\system32\adsiis.dll
2010-05-24 14:13:39 ----A---- C:\WINDOWS\system32\iisRtl.dll
2010-05-24 14:13:39 ----A---- C:\WINDOWS\system32\iismap.dll
2010-05-24 14:13:39 ----A---- C:\WINDOWS\system32\exstrace.dll
2010-05-24 14:13:39 ----A---- C:\WINDOWS\system32\admwprox.dll
2010-05-24 14:13:35 ----A---- C:\WINDOWS\system32\staxmem.dll
2010-05-24 14:13:33 ----A---- C:\WINDOWS\system32\accwiz.exe
2010-05-24 14:13:32 ----A---- C:\WINDOWS\system32\sndrec32.exe
2010-05-24 14:13:32 ----A---- C:\WINDOWS\system32\mplay32.exe
2010-05-24 14:13:31 ----A---- C:\WINDOWS\system32\hypertrm.dll
2010-05-24 14:13:30 ----D---- C:\Program Files\Windows NT
2010-05-24 14:13:29 ----A---- C:\WINDOWS\system32\clipbrd.exe
2010-05-24 14:13:27 ----A---- C:\WINDOWS\system32\spider.exe
2010-05-24 14:13:25 ----A---- C:\WINDOWS\system32\tsgqec.dll
2010-05-24 14:13:25 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2010-05-24 14:13:24 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2010-05-24 14:13:24 ----A---- C:\WINDOWS\system32\aaclient.dll
2010-05-24 14:13:22 ----AC---- C:\WINDOWS\system32\mstscax.dll
2010-05-24 14:13:22 ----A---- C:\WINDOWS\system32\mstsc.exe
2010-05-24 14:13:21 ----A---- C:\WINDOWS\system32\remotepg.dll
2010-05-24 14:13:21 ----A---- C:\WINDOWS\system32\rdshost.exe
2010-05-24 14:13:21 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2010-05-24 14:13:20 ----A---- C:\WINDOWS\system32\termsrv.dll
2010-05-24 14:13:20 ----A---- C:\WINDOWS\system32\sessmgr.exe
2010-05-24 14:13:20 ----A---- C:\WINDOWS\system32\rdchost.dll
2010-05-24 14:13:19 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2010-05-24 14:13:19 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2010-05-24 14:13:19 ----A---- C:\WINDOWS\system32\rdpclip.exe
2010-05-24 14:13:19 ----A---- C:\WINDOWS\system32\qprocess.exe
2010-05-24 14:13:18 ----D---- C:\WINDOWS\system32\MsDtc
2010-05-24 14:13:18 ----AC---- C:\WINDOWS\system32\msdtcuiu.dll
2010-05-24 14:13:18 ----A---- C:\WINDOWS\system32\icaapi.dll
2010-05-24 14:13:18 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2010-05-24 14:13:17 ----AC---- C:\WINDOWS\system32\mtxoci.dll
2010-05-24 14:13:17 ----AC---- C:\WINDOWS\system32\msdtcprx.dll
2010-05-24 14:13:16 ----AC---- C:\WINDOWS\system32\msdtctm.dll
2010-05-24 14:13:16 ----AC---- C:\WINDOWS\system32\msdtclog.dll
2010-05-24 14:13:16 ----A---- C:\WINDOWS\system32\xolehlp.dll
2010-05-24 14:13:15 ----A---- C:\WINDOWS\system32\msdtc.exe
2010-05-24 14:13:14 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2010-05-24 14:13:13 ----D---- C:\WINDOWS\system32\Com
2010-05-24 14:13:13 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2010-05-24 14:13:13 ----A---- C:\WINDOWS\system32\mtxex.dll
2010-05-24 14:13:13 ----A---- C:\WINDOWS\system32\mtxdm.dll
2010-05-24 14:13:13 ----A---- C:\WINDOWS\system32\comaddin.dll
2010-05-24 14:13:13 ----A---- C:\WINDOWS\system32\colbact.dll
2010-05-24 14:13:12 ----A---- C:\WINDOWS\system32\stclient.dll
2010-05-24 14:13:12 ----A---- C:\WINDOWS\system32\comrepl.dll
2010-05-24 14:13:12 ----A---- C:\WINDOWS\system32\clbcatex.dll
2010-05-24 14:13:12 ----A---- C:\WINDOWS\system32\catsrvps.dll
2010-05-24 14:13:11 ----A---- C:\WINDOWS\system32\catsrvut.dll
2010-05-24 14:13:11 ----A---- C:\WINDOWS\system32\catsrv.dll
2010-05-24 14:13:10 ----A---- C:\WINDOWS\system32\comsvcs.dll
2010-05-24 14:13:09 ----A---- C:\WINDOWS\system32\comuid.dll
2010-05-24 14:13:09 ----A---- C:\WINDOWS\system32\comsnap.dll
2010-05-24 14:13:08 ----A---- C:\WINDOWS\system32\clbcatq.dll
2010-05-24 14:12:51 ----A---- C:\WINDOWS\system32\servdeps.dll
2010-05-24 14:12:50 ----A---- C:\WINDOWS\system32\mmfutil.dll
2010-05-24 14:12:50 ----A---- C:\WINDOWS\system32\licwmi.dll
2010-05-24 14:12:50 ----A---- C:\WINDOWS\system32\cmprops.dll
2010-05-24 14:12:37 ----D---- C:\WINDOWS\system32\Logfiles
2010-05-24 14:12:37 ----D---- C:\Inetpub

======List of files/folders modified in the last 1 months======

2010-06-13 00:56:21 ----A---- C:\WINDOWS\system.ini
2010-05-29 21:45:26 ----A---- C:\WINDOWS\win.ini

pokračování logu v dalším příspěvku

Re: Prosím o kontrolu logu

Napsal: 13 čer 2010 16:59
od Rudy
Odinstalujte cracklý NOD a použijte nějakou free verzi AV programu. Výběr zde: http://www.viry.cz/forum/viewtopic.php?f=29&t=38810 .

Re: Prosím o kontrolu logu

Napsal: 14 čer 2010 01:16
od katarina69
Zdravím..

Ale já NOD nainstalovaný vůbec nemám, mám mirosoft security essentials..

Re: Prosím o kontrolu logu

Napsal: 14 čer 2010 11:04
od JaRon
zaskocim za kolegu:
Presun ComboFix
na plochu (ak tam este nie je)

otvor si Poznamkovy blok - notepad

do neho zkopiruj skript z nasledujiceho okna:

Kód: Vybrat vše

Registry::
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NodTrialReset"=-



uloz vytvoreny textovy soubor ako CFScript.txt na plochu

po ulozeni uchop vytvoreny skript lavym tlacitkom mysi a presun ho nad ikonu Combofixu, nad nim skript upust:

Obrázek

po aplikacii by mal vzniknut dalsi log, ten vloz sem :)

Re: Prosím o kontrolu logu

Napsal: 14 čer 2010 23:25
od katarina69
Zdravim.....tak tady to je :

ComboFix 10-06-14.02 - Robert 15.06.2010 0:00.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2038.1545 [GMT 2:00]
Spuštěný z: c:\documents and settings\Robert\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Robert\Plocha\CFScript.txt
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Robert\codsp.exe
c:\windows\Downloaded Program Files\ODCTOOLS
c:\windows\Downloaded Program Files\ODCTOOLS\007fe149-a8cd-4c7f-94a0-64b4f71648a1.cab
c:\windows\Downloaded Program Files\ODCTOOLS\632a73e1-8239-4697-8784-dd99c3138805.cab
c:\windows\system32\Cache
c:\windows\system32\st325602.dll

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-05-14 do 2010-06-14 )))))))))))))))))))))))))))))))
.

2010-06-14 20:15 . 2010-06-14 20:13 391680 ----a-w- c:\windows\system32\CF16908.exe
2010-06-14 09:05 . 2010-06-14 09:04 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-13 13:15 . 2010-06-13 13:15 -------- d-----w- c:\program files\trend micro
2010-06-13 13:15 . 2010-06-13 13:15 -------- d-----w- C:\rsit
2010-06-10 09:05 . 2008-10-22 13:06 188416 ----a-r- c:\windows\system32\ffpage32.dll
2010-06-10 09:05 . 2008-10-22 13:06 573440 ----a-r- c:\windows\system32\ffdriver32.Dll
2010-06-10 09:03 . 2008-10-22 13:06 1419232 ----a-r- c:\windows\system32\WdfCoInstaller01005.dll
2010-06-09 20:49 . 2010-05-06 10:35 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-09 10:58 . 2008-04-14 01:51 21504 ----a-w- c:\windows\system32\hidserv.dll
2010-06-09 10:52 . 2010-06-09 10:52 -------- d-----w- c:\program files\Saitek
2010-06-08 00:42 . 2010-06-08 00:42 -------- d-----w- c:\program files\Funcom
2010-06-08 00:27 . 2010-06-08 00:27 -------- d-----w- c:\program files\PowerISO
2010-06-04 23:02 . 2010-06-04 23:02 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-06-04 23:01 . 2010-06-04 23:04 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-06-04 21:56 . 2008-04-13 21:26 12800 ----a-w- c:\windows\system32\drivers\usb8023x.sys
2010-06-04 21:56 . 2008-04-13 21:26 30592 ----a-w- c:\windows\system32\drivers\rndismpx.sys
2010-06-04 21:39 . 2010-06-04 21:39 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-06-03 17:11 . 1999-05-28 08:15 86016 ----a-w- c:\windows\unvise32qt.exe
2010-06-03 17:11 . 2010-06-11 18:48 -------- d-----w- c:\windows\system32\QuickTime
2010-06-03 17:09 . 1998-10-29 14:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-06-02 09:06 . 2008-04-14 04:59 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2010-06-01 09:45 . 2010-06-01 09:45 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-06-01 09:41 . 2010-06-01 09:45 -------- d-----w- C:\246be863765b39d88baee1953d
2010-05-30 10:07 . 2010-05-30 10:07 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2010-05-29 06:02 . 2010-05-30 23:03 -------- d-----w- c:\windows\system32\NtmsData
2010-05-27 18:58 . 2001-10-24 07:54 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-05-27 17:14 . 2008-04-13 21:15 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-05-27 16:11 . 2007-05-10 05:52 405504 ----a-w- c:\windows\stsystra.exe
2010-05-27 16:11 . 2007-04-10 12:32 1601536 ----a-w- c:\windows\system32\stlang.dll
2010-05-27 16:09 . 2007-05-10 05:53 270336 ----a-w- c:\windows\system32\stacapi.dll
2010-05-27 16:09 . 2010-05-27 16:09 -------- d-----w- c:\program files\SigmaTel
2010-05-27 15:40 . 2010-05-27 15:40 -------- d-----w- c:\windows\system32\Dell
2010-05-27 15:07 . 2010-05-27 15:07 -------- d-----w- c:\program files\Broadcom
2010-05-27 14:55 . 2008-04-13 14:45 2944 ----a-w- c:\windows\system32\drivers\drmkaud.sys
2010-05-27 14:55 . 2008-04-13 14:45 172416 ----a-w- c:\windows\system32\drivers\kmixer.sys
2010-05-27 14:55 . 2008-04-13 12:39 142592 ----a-w- c:\windows\system32\drivers\aec.sys
2010-05-27 14:55 . 2008-04-13 14:45 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2010-05-27 14:53 . 2008-04-13 15:17 83072 ----a-w- c:\windows\system32\drivers\wdmaud.sys
2010-05-27 14:51 . 2007-03-30 15:28 172032 ----a-w- c:\windows\system32\igfxres.dll
2010-05-26 09:38 . 2008-04-13 18:46 37888 -c--a-w- c:\windows\system32\dllcache\bthmodem.sys
2010-05-26 09:38 . 2008-04-13 18:46 37888 ----a-w- c:\windows\system32\drivers\bthmodem.sys
2010-05-25 03:17 . 2010-05-25 03:19 -------- d-----w- C:\cb1667bec25e354dc71c2063
2010-05-25 01:07 . 2010-05-25 01:07 -------- d-----w- c:\windows\system32\XPSViewer
2010-05-25 01:07 . 2010-05-25 01:07 -------- d-----w- c:\program files\Reference Assemblies
2010-05-25 01:06 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-05-25 01:06 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-05-25 01:06 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-05-25 01:06 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-05-25 01:06 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-05-25 01:06 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-05-25 01:06 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-05-25 01:06 . 2010-05-25 01:06 -------- d-----w- C:\0e3b0cacd63588c81f6b0e3a25bf48
2010-05-25 01:06 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-05-25 01:06 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-05-24 21:57 . 2010-05-27 15:40 -------- d-----w- c:\program files\Dell
2010-05-24 21:56 . 2010-05-24 21:56 -------- d-----w- c:\program files\Common Files\InstallShield
2010-05-24 21:17 . 2010-05-24 21:17 -------- d-sh--w- c:\documents and settings\Robert\IECompatCache
2010-05-24 21:14 . 2010-05-24 21:14 -------- d-sh--w- c:\documents and settings\Robert\PrivacIE
2010-05-24 21:13 . 2008-04-13 14:45 52864 ----a-w- c:\windows\system32\drivers\DMusic.sys
2010-05-24 21:13 . 2008-04-13 14:45 56576 ----a-w- c:\windows\system32\drivers\swmidi.sys
2010-05-24 21:10 . 2008-04-13 15:15 60800 ----a-w- c:\windows\system32\drivers\sysaudio.sys
2010-05-24 21:07 . 2008-04-13 14:39 5376 ----a-w- c:\windows\system32\drivers\MSPCLOCK.sys
2010-05-24 21:06 . 2010-05-24 21:06 -------- d-----w- c:\program files\IDT
2010-05-24 21:06 . 2008-04-13 23:21 4096 ----a-w- c:\windows\system32\ksuser.dll
2010-05-24 21:06 . 2008-04-13 15:19 146048 ----a-w- c:\windows\system32\drivers\portcls.sys
2010-05-24 20:38 . 2008-04-13 14:45 60160 ----a-w- c:\windows\system32\drivers\drmk.sys
2010-05-24 20:35 . 2010-05-26 20:33 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-05-24 19:46 . 2008-11-01 09:43 684 ----a-w- c:\windows\SetupNodTrialReset.reg
2010-05-24 19:46 . 2008-11-01 08:53 280 ----a-w- c:\windows\NodTrialReset.reg
2010-05-24 19:41 . 2010-05-24 19:41 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-05-24 19:40 . 2010-05-24 19:40 -------- d-sh--w- c:\documents and settings\Robert\IETldCache
2010-05-24 19:18 . 2010-05-06 10:35 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-05-24 19:18 . 2010-05-06 10:35 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-05-24 19:17 . 2010-05-24 19:17 -------- d-----w- c:\windows\ie8updates
2010-05-24 19:17 . 2010-02-16 04:50 64000 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-05-24 19:15 . 2010-05-24 19:17 -------- dc-h--w- c:\windows\ie8
2010-05-24 18:50 . 2010-02-24 11:57 457216 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-05-24 18:34 . 2010-06-13 13:12 -------- d-----w- C:\Downloads
2010-05-24 17:49 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-05-24 17:41 . 2010-05-24 17:41 0 ----a-w- c:\windows\nsreg.dat
2010-05-24 17:39 . 2010-02-16 19:02 2069120 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-05-24 17:39 . 2010-02-16 19:02 2148352 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-05-24 17:39 . 2010-02-16 19:02 2026496 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-05-24 17:25 . 2008-04-21 21:15 216576 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-05-24 17:16 . 2010-05-21 12:14 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-24 17:05 . 2010-05-27 14:49 -------- dc----w- c:\windows\system32\DRVSTORE
2010-05-24 17:05 . 2009-10-26 01:17 4221952 ----a-w- c:\windows\system32\drivers\NETw5x32.sys
2010-05-24 17:05 . 2008-06-20 05:03 2756608 ----a-w- c:\windows\system32\NETw5r32.dll
2010-05-24 17:05 . 2008-06-20 05:02 663552 ----a-w- c:\windows\system32\NETw5c32.dll
2010-05-24 17:05 . 2010-05-24 21:58 -------- d-----w- c:\program files\Intel
2010-05-24 17:05 . 2010-05-24 17:05 -------- d-----w- c:\program files\Common Files\Intel
2010-05-24 17:03 . 2010-05-27 15:04 -------- d-----w- C:\dell
2010-05-24 15:40 . 2008-04-14 07:52 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-05-24 15:37 . 2010-05-24 15:37 -------- d-----w- c:\program files\Windows Defender
2010-05-24 15:37 . 2010-05-24 15:37 -------- d-----w- c:\program files\Notepad++
2010-05-24 15:34 . 2010-05-24 15:34 -------- d-----w- C:\extensions
2010-05-24 15:34 . 2010-05-24 18:40 -------- d-----w- c:\program files\BitComet
2010-05-24 15:34 . 2010-05-24 15:34 -------- d-----w- c:\program files\Total Commander
2010-05-24 15:34 . 2010-05-24 15:34 -------- d-----w- c:\program files\VisualTaskTips
2010-05-24 15:31 . 2010-05-24 18:00 -------- d-----w- c:\program files\Google
2010-05-24 15:31 . 2010-05-24 15:31 -------- d-----w- c:\program files\Skype
2010-05-24 15:31 . 2010-05-24 15:31 -------- d-----w- c:\program files\Common Files\Skype
2010-05-24 15:31 . 2010-05-24 15:31 -------- d-----w- c:\program files\ICQ6
2010-05-24 15:30 . 2010-05-24 15:30 -------- d-----w- c:\program files\7-Zip
2010-05-24 15:24 . 2008-11-10 07:11 32656 ----a-w- c:\windows\system32\msonpmon.dll
2010-05-24 15:24 . 2006-10-26 15:26 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-05-24 15:22 . 2010-05-24 22:34 -------- d-----w- c:\program files\Microsoft Works
2010-05-24 15:22 . 2010-05-24 15:22 -------- d-----w- c:\program files\MSBuild
2010-05-24 15:21 . 2010-05-24 15:21 -------- d-----w- c:\program files\Microsoft.NET
2010-05-24 15:19 . 2003-03-24 11:22 618605 -c--a-w- c:\windows\system32\dllcache\fp4autl.dll
2010-05-24 15:18 . 2010-05-24 15:22 -------- d-----w- c:\windows\SHELLNEW
2010-05-24 15:17 . 2010-05-24 15:17 -------- d-----r- C:\MSOCache
2010-05-24 15:17 . 2010-05-24 15:17 -------- d-----w- c:\program files\IEPro
2010-05-24 15:12 . 2010-06-14 09:04 -------- d-----w- c:\program files\Java
2010-05-24 15:12 . 2010-05-24 15:12 -------- d-----w- c:\program files\Common Files\Java
2010-05-24 15:08 . 2001-08-17 15:29 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
2010-05-24 15:03 . 2010-05-24 15:03 -------- d-----w- c:\windows\IIS Temporary Compressed Files
2010-05-24 15:03 . 2010-06-01 09:44 -------- d-----w- c:\documents and settings\LocalService\Data aplikací
2010-05-24 15:03 . 2010-05-30 10:07 -------- d-sh--w- c:\documents and settings\LocalService

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-14 08:26 . 2001-10-25 15:00 93716 ----a-w- c:\windows\system32\perfc005.dat
2010-06-14 08:26 . 2001-10-25 15:00 476836 ----a-w- c:\windows\system32\perfh005.dat
2010-06-10 09:04 . 2010-06-10 09:04 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_SaiKF620_01005.Wdf
2010-06-10 09:04 . 2010-06-10 09:04 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-06-08 00:42 . 2010-05-24 15:35 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-03 22:30 . 2010-05-24 12:44 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-03 11:27 . 2010-06-12 23:45 227866 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1029.dat
2010-05-31 12:22 . 2010-05-24 12:52 -------- d-----w- c:\program files\Microsoft Games
2010-05-27 14:23 . 2010-05-24 21:06 5820 ----a-w- c:\windows\system32\drivers\sthdae.log
2010-05-24 16:17 . 2010-05-24 12:37 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-05-24 16:17 . 2010-05-24 12:37 2426 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-05-24 16:07 . 2010-05-24 12:38 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-05-24 15:35 . 2010-05-24 15:35 -------- d-----w- c:\program files\Ahead
2010-05-24 15:35 . 2010-05-24 15:35 -------- d-----w- c:\program files\Common Files\Ahead
2010-05-24 15:35 . 2010-05-24 15:35 -------- d-----w- c:\program files\DVD Shrink
2010-05-24 15:34 . 2010-05-24 12:52 -------- d-----w- c:\program files\Vista Components
2010-05-24 15:33 . 2010-05-24 15:33 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-05-24 15:33 . 2010-05-24 15:33 -------- d-----w- c:\program files\IrfanView
2010-05-24 15:33 . 2010-05-24 15:32 -------- d-----w- c:\program files\Common Files\Adobe
2010-05-24 12:53 . 2010-05-24 12:53 -------- d-----w- c:\program files\microsoft frontpage
2010-05-24 12:52 . 2010-05-24 12:23 -------- d-----w- c:\program files\Windows Sidebar
2010-05-24 12:51 . 2010-05-24 12:51 -------- d-----w- c:\program files\Alky for Applications
2010-05-24 12:30 . 2010-05-24 12:30 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2010-05-24 12:27 . 2010-05-24 12:27 -------- d-----w- c:\program files\VistaExperience.org
2010-05-24 12:22 . 2010-05-24 12:21 -------- d-----w- c:\program files\Windows Plus
2010-05-24 12:21 . 2010-05-24 12:21 -------- d-----w- c:\program files\Windows Media Connect 2
2010-05-06 10:35 . 2008-10-16 19:33 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 08:03 . 2008-10-17 14:02 1860352 ----a-w- c:\windows\system32\win32k.sys
2010-04-20 05:32 . 2008-04-14 07:37 285696 ----a-w- c:\windows\system32\atmfd.dll
.

------- Sigcheck -------

[-] 2008-10-19 . 12A799AD9415AE9C8ABCC5F75E9CF034 . 557056 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe

[-] 2008-10-19 . 3AC5A6BB0491CADA4F424978ECCD9A29 . 678400 . . [5.82] . . c:\windows\system32\comctl32.dll

[-] 2008-10-19 . CCB32D10C69A89822E9134C0C4894BE1 . 578560 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll

[-] 2008-10-19 . DD7E25E20AEBD672DAE7E1D911C2D824 . 1589760 . . [6.00.2900.5512] . . c:\windows\explorer.exe

[-] 2008-11-05 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

[-] 2008-10-19 . 0AB43CE7EFFAD6B4914AE3C1B489AAA1 . 66560 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NodTrialReset"="regedit" [X]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2008-11-05 77312]
"DrvIcon"="c:\program files\Vista Components\Vista Drive Icon\DrvIcon.exe" [2007-07-04 45056]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-30 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-30 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-30 138008]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]
"ProfilerU"="c:\program files\Saitek\SD6\Software\ProfilerU.exe" [2009-06-03 237568]
"SaiMfd"="c:\program files\Saitek\SD6\Software\SaiMfd.exe" [2009-06-03 131072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-10-19 66560]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-03 435096]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9920:TCP"= 9920:TCP:BitComet 9920 TCP
"9920:UDP"= 9920:UDP:BitComet 9920 UDP
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5.6.2010 1:02 691696]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 16:49 13592]
S3 SaiKF620;SaiKF620;c:\windows\system32\drivers\SaiKF620.sys [22.10.2008 15:06 106496]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
2009-03-08 00:02 128512 ----a-w- c:\windows\system32\advpack.dll
.
Obsah adresáře 'Naplánované úlohy'

2010-06-14 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-12-09 16:02]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Stáhnout odkaz s použitím BitCometu - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: Stáhnout všechna videa s použitím BitCometu - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: Stáhnout všechny odkazy s použitím BitCometu - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
FF - ProfilePath - c:\documents and settings\Robert\Data aplikací\Mozilla\Firefox\Profiles\kp6omobv.default\
FF - component: c:\documents and settings\Robert\Data aplikací\Mozilla\Firefox\Profiles\kp6omobv.default\extensions\support@lastpass.com\platform\WINNT_x86-msvc\components\lpxpcom.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKCU-Run-Sidebar - c:\program files\Windows Sidebar\sidebar.exe



**************************************************************************
skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory:

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1645522239-2077806209-299502267-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(992)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\cscui.dll

- - - - - - - > 'lsass.exe'(1048)
c:\windows\system32\setupapi.dll
.
Celkový čas: 2010-06-15 00:10:04
ComboFix-quarantined-files.txt 2010-06-14 22:10

Před spuštěním: Volných bajtů: 62 944 747 520
Po spuštění: Volných bajtů: 63 721 213 952

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - A6BF2EB4B9A33FBB79AF9D9A84EEC5E7

Díky moc :) :)

Re: Prosím o kontrolu logu

Napsal: 15 čer 2010 06:44
od JaRon
prescanuj PC s AVPTool

Re: Prosím o kontrolu logu

Napsal: 18 čer 2010 10:49
od katarina69
AVPTool nic nenašel...

Re: Prosím o kontrolu logu

Napsal: 18 čer 2010 10:54
od JaRon
pokial nie su ziadne problemy, tak hotovo :)