Prosim o kontrolu logu-PC posiela SPAM
Napsal: 19 čer 2010 13:36
Moj PC posiela velke mnozstvo spamu. Uz som pouzil NOD, Eset online scanner, Spyware Terminator, AdAware, pricom najdene infiltracie som vymazal alebo ulozil do karanteny. Mam k PC pripojeny este 1TB externy HDD, aj ten mi preskenovali vyssie uvedene programy. Aj napriek tomu mi po zapnuti spamu zacne PC posielat kopec spamu. Chcel by preto som poprosit o kontrologu logu z RSIT. Vopred dakujem.
Logfile of random's system information tool 1.07 (written by random/random)
Run by mam-desktop at 2010-06-19 14:16:26
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 9 GB (8%) free of 118 GB
Total RAM: 2047 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:16:40, on 19.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\eBoostr\eBoostrCP.exe
C:\Program Files\Ardaco\QSign\zepapp.exe
C:\Program Files\ArsClip\ArsClip.exe
C:\Lib\Vtlac.exe
C:\WINDOWS\system32\dkvcm.exe
C:\Program Files\eBoostr\EBstrSvc.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\WINDOWS\System32\dkcktkn.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\SpeedProject\SpeedCommander 12\SpeedCommander.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\mam-desktop\Local Settings\Application Data\Opera\Opera\temporary_downloads\RSIT.exe
C:\Program Files\trend micro\mam-desktop.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.obcan.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-01-07:8080
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DkAutoReg.exe] C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe
O4 - HKLM\..\Run: [DkStartup] C:\Program Files\SafeNet\iKey 2000 Series Software\DkStartup.exe
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.1\ICQ.exe" silent loginmode=4
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ArsClip.lnk = C:\Program Files\ArsClip\ArsClip.exe
O4 - Startup: Vtlac.lnk = C:\Lib\Vtlac.exe
O4 - Global Startup: eBoostr Control Panel.lnk = C:\Program Files\eBoostr\eBoostrCP.exe
O4 - Global Startup: QSign 3.4.lnk = C:\Program Files\Ardaco\QSign\zepapp.exe
O8 - Extra context menu item: Download with Mipony - file://C:\Program Files\MiPony\Browser\IEContext.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Převést výběr do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést výběr do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: WebTran - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: &Nastaviť prekladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} (ICApki Class) - http://download.ica.cz/icapki.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DkWLNP - DkWLNP.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Datakey's Log Service (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
O23 - Service: Datakey's Token Service (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
O23 - Service: Datakey's Virtual Channel Monitor (DkVcm) - Datakey, Inc. - C:\WINDOWS\system32\dkvcm.exe
O23 - Service: eBoostr Service (EBOOSTRSVC) - eBoostr.com - C:\Program Files\eBoostr\EBstrSvc.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
--
End of file - 9488 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\PROGRA~1\PCTRAN~1\webie.dll [2004-05-13 319488]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 225280]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-03-01 1443072]
"DkAutoReg.exe"=C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe [2004-11-23 245760]
"DkStartup"=C:\Program Files\SafeNet\iKey 2000 Series Software\DkStartup.exe [2004-11-23 217088]
"MaxMenuMgr"=C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe [2009-09-25 185640]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"ICQ"=C:\Program Files\ICQ7.1\ICQ.exe [2010-06-08 133368]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2004-12-14 483328]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-11-16 139264]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe [2009-10-28 257440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
C:\Program Files\Efficasoft Mobile Express\MobileExpress.exe [2008-12-16 1040384]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-06-16 3037696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
C:\WINDOWS\system32\sti_ci.dll [2008-04-14 136704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
C:\WINDOWS\XPize\XPizeReloader.exe [2007-07-19 110139]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
C:\PROGRA~1\OVIFIL~1\OVIFIL~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
C:\PROGRA~1\WI459E~1\WINDOW~1.EXE [2008-05-26 123904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2
"ose"=3
"odserv"=3
"NBService"=3
"JavaQuickStarterService"=2
"ABBYY.Licensing.FineReader.Professional.9.0"=2
"WSearch"=2
"Themes"=2
"RDSessMgr"=3
"wscsvc"=2
"helpsvc"=2
"SysmonLog"=3
"CiSvc"=3
"ERSvc"=2
C:\Documents and Settings\All Users\Ponuka Štart\Programy\Pri spustení
eBoostr Control Panel.lnk - C:\Program Files\eBoostr\eBoostrCP.exe
QSign 3.4.lnk - C:\Program Files\Ardaco\QSign\zepapp.exe
C:\Documents and Settings\mam-desktop\Start Menu\Programs\Startup
ArsClip.lnk - C:\Program Files\ArsClip\ArsClip.exe
Vtlac.lnk - C:\Lib\Vtlac.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DkWLNP]
C:\WINDOWS\system32\DkWLNP.dll [2004-11-23 57344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Ardaco\QSign\zepapp.exe"="C:\Program Files\Ardaco\QSign\zepapp.exe:*:Enabled:QSign"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console"
"C:\Program Files\ESET\ESET Smart Security\egui.exe"="C:\Program Files\ESET\ESET Smart Security\egui.exe:*:Enabled:ESET Smart Security"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
======List of files/folders created in the last 1 months======
2010-06-19 14:16:26 ----D---- C:\rsit
2010-06-19 14:16:26 ----D---- C:\Program Files\trend micro
2010-06-19 13:52:50 ----A---- C:\ComboFix.txt
2010-06-19 13:41:03 ----A---- C:\Boot.bak
2010-06-19 13:40:59 ----RASHD---- C:\cmdcons
2010-06-19 13:37:14 ----A---- C:\WINDOWS\zip.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\SWSC.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\SWREG.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\sed.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\PEV.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\NIRCMD.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\MBR.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\grep.exe
2010-06-19 13:37:03 ----D---- C:\WINDOWS\ERDNT
2010-06-19 13:34:30 ----AD---- C:\Qoobox
2010-06-19 12:05:37 ----A---- C:\WINDOWS\ntbtlog.txt
2010-06-19 12:05:23 ----A---- C:\WINDOWS\system32\TURegOpt.exe
2010-06-19 12:05:13 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2010-06-19 12:04:16 ----D---- C:\Documents and Settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 12:02:55 ----D---- C:\Program Files\TuneUp Utilities 2010
2010-06-19 12:01:59 ----D---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2010-06-19 11:59:01 ----SHD---- C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 11:25:16 ----D---- C:\Program Files\CCleaner
2010-06-16 21:03:51 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-06-16 21:02:45 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-06-16 21:01:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-06-16 20:25:14 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-06-16 20:15:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-16 20:14:52 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-06-16 20:14:04 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-06-16 19:19:17 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2010-06-16 19:17:59 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 19:17:44 ----D---- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2010-06-16 19:17:25 ----D---- C:\Program Files\Spyware Terminator
2010-06-02 11:16:18 ----A---- C:\WINDOWS\ModemLog_Nokia E63 USB Modem #3.txt
2010-05-31 12:54:57 ----D---- C:\Documents and Settings\All Users\Application Data\eboostr
2010-05-31 12:54:41 ----D---- C:\Program Files\eBoostr
2010-05-28 11:05:05 ----D---- C:\Program Files\ICQ6Toolbar
2010-05-28 11:04:46 ----D---- C:\Documents and Settings\All Users\Application Data\ICQ
2010-05-28 11:04:26 ----D---- C:\Documents and Settings\mam-desktop\Application Data\ICQ
2010-05-28 11:04:12 ----D---- C:\Program Files\ICQ7.1
2010-05-27 10:17:54 ----HDC---- C:\WINDOWS\$NtUninstallKB963093$
2010-05-27 10:16:07 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-05-25 16:12:31 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 15:56:41 ----D---- C:\Program Files\Windows Desktop Search
2010-05-25 15:55:51 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$
2010-05-25 15:55:10 ----HDC---- C:\WINDOWS\$NtUninstallKB915800-v4$
2010-05-25 08:29:43 ----D---- C:\Documents and Settings\All Users\Application Data\ODIR
2010-05-25 00:32:33 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-05-25 00:31:34 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2010-05-24 17:25:19 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 17:22:23 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-05-24 17:21:03 ----HDC---- C:\WINDOWS\$NtUninstallWudf01007$
2010-05-24 16:58:57 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2010-05-24 16:57:24 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2010-05-24 12:35:08 ----HDC---- C:\WINDOWS\$NtUninstallWdf01009$
2010-05-23 21:40:54 ----D---- C:\Program Files\7-Zip
2010-05-22 12:33:15 ----D---- C:\Documents and Settings\All Users\Application Data\Nokia
2010-05-22 12:32:19 ----D---- C:\Program Files\PC Connectivity Solution
2010-05-22 12:31:01 ----A---- C:\WINDOWS\system32\wdfcoinstaller01009.dll
2010-05-22 12:31:01 ----A---- C:\WINDOWS\system32\nmwcdcocls.dll
2010-05-22 12:29:32 ----D---- C:\Program Files\Common Files\Nokia
======List of files/folders modified in the last 1 months======
2010-06-19 14:16:26 ----RD---- C:\Program Files
2010-06-19 13:51:43 ----SD---- C:\WINDOWS\Tasks
2010-06-19 13:50:08 ----D---- C:\WINDOWS
2010-06-19 13:50:08 ----A---- C:\WINDOWS\system.ini
2010-06-19 13:49:46 ----D---- C:\WINDOWS\Temp
2010-06-19 13:49:24 ----D---- C:\WINDOWS\system32
2010-06-19 13:48:12 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Skype
2010-06-19 13:46:35 ----D---- C:\WINDOWS\system32\drivers
2010-06-19 13:46:35 ----D---- C:\WINDOWS\AppPatch
2010-06-19 13:46:32 ----D---- C:\Program Files\Common Files
2010-06-19 13:43:01 ----D---- C:\WINDOWS\system32\CatRoot2
2010-06-19 13:41:03 ----RASH---- C:\boot.ini
2010-06-19 13:37:49 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-06-19 13:21:37 ----D---- C:\Program Files\ArsClip
2010-06-19 13:18:12 ----SHD---- C:\WINDOWS\Installer
2010-06-19 13:17:47 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-06-19 12:57:23 ----D---- C:\Documents and Settings\mam-desktop\Application Data\skypePM
2010-06-19 12:55:38 ----D---- C:\Program Files\Internet Explorer
2010-06-19 12:28:15 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-06-19 12:28:07 ----D---- C:\WINDOWS\system32\inetsrv
2010-06-19 12:05:25 ----D---- C:\WINDOWS\system32\config
2010-06-19 11:39:18 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Media Player Classic
2010-06-19 11:37:08 ----D---- C:\WINDOWS\Debug
2010-06-19 11:37:07 ----D---- C:\WINDOWS\Minidump
2010-06-19 11:25:45 ----D---- C:\WINDOWS\Prefetch
2010-06-19 11:13:18 ----HD---- C:\Program Files\InstallShield Installation Information
2010-06-19 11:03:42 ----A---- C:\WINDOWS\NeroDigital.ini
2010-06-18 06:05:01 ----D---- C:\PU
2010-06-18 00:05:13 ----D---- C:\Lib
2010-06-17 04:51:58 ----D---- C:\WINDOWS\Microsoft.NET
2010-06-17 04:49:35 ----RSD---- C:\WINDOWS\assembly
2010-06-17 00:06:52 ----HD---- C:\WINDOWS\inf
2010-06-16 21:40:20 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-06-16 21:40:08 ----D---- C:\Program Files\ESET
2010-06-16 21:04:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-06-16 21:02:36 ----HD---- C:\WINDOWS\$hf_mig$
2010-06-16 20:58:34 ----D---- C:\WINDOWS\ie8updates
2010-06-16 20:13:38 ----D---- C:\WINDOWS\system32\CatRoot
2010-06-16 20:05:08 ----D---- C:\WINDOWS\WinSxS
2010-06-08 11:38:05 ----D---- C:\PUA
2010-06-06 21:22:41 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-06-06 21:22:22 ----D---- C:\WINDOWS\security
2010-06-06 21:20:39 ----A---- C:\WINDOWS\win.ini
2010-06-06 21:16:16 ----D---- C:\WINDOWS\Help
2010-06-06 16:07:54 ----D---- C:\WINDOWS\pss
2010-06-04 15:18:23 ----A---- C:\WINDOWS\wdict32.INI
2010-06-02 19:34:36 ----HD---- C:\WINDOWS\XPize
2010-06-02 19:34:05 ----D---- C:\Program Files\WinRAR
2010-06-02 19:34:05 ----D---- C:\Program Files\Windows Media Player
2010-06-02 19:34:05 ----D---- C:\Program Files\Outlook Express
2010-06-02 19:34:05 ----D---- C:\Program Files\Common Files\System
2010-06-02 19:34:04 ----D---- C:\WINDOWS\system32\usmt
2010-06-02 19:34:04 ----D---- C:\WINDOWS\system32\Restore
2010-06-02 19:22:47 ----D---- C:\Program Files\Adobe
2010-06-02 19:12:09 ----D---- C:\Program Files\Microsoft ActiveSync
2010-06-02 18:47:34 ----D---- C:\Program Files\Efficasoft Mobile Express
2010-05-28 21:37:34 ----A---- C:\WINDOWS\system32\MRT.exe
2010-05-28 14:35:21 ----SD---- C:\Documents and Settings\mam-desktop\Application Data\Microsoft
2010-05-28 11:04:47 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Mozilla
2010-05-25 15:56:48 ----D---- C:\WINDOWS\system32\en-US
2010-05-25 15:56:40 ----HD---- C:\WINDOWS\system32\GroupPolicy
2010-05-25 15:56:40 ----D---- C:\WINDOWS\system32\wbem
2010-05-25 00:57:16 ----A---- C:\WINDOWS\system32\fmod.dll
2010-05-24 17:25:10 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Nokia
2010-05-24 17:22:55 ----D---- C:\Documents and Settings\mam-desktop\Application Data\PC Suite
2010-05-24 17:20:27 ----D---- C:\Documents and Settings\All Users\Application Data\PC Suite
2010-05-24 17:10:32 ----D---- C:\Program Files\Nokia
2010-05-24 16:57:39 ----D---- C:\WINDOWS\system32\LogFiles
2010-05-22 12:28:25 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-05-22 12:26:25 ----D---- C:\Documents and Settings\All Users\Application Data\Installations
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-03-01 29704]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2008-03-01 54280]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [1997-12-22 23936]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-03-01 39944]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2008-03-01 71176]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2008-03-01 30728]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 iKeyEnum;Rainbow iKey Enumerator; C:\WINDOWS\system32\DRIVERS\ikeyenum.sys [2004-03-16 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader; C:\WINDOWS\system32\DRIVERS\ikeyifd.sys [2004-03-16 17928]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\vinyl97.sys [2005-04-08 179968]
S3 catchme;catchme; \??\C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\catchme.sys []
S3 mbr;mbr; \??\C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\mbr.sys []
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RnbToken;Rainbow iKey Token Service; C:\WINDOWS\system32\DRIVERS\rnbtoken.sys [2004-03-16 18536]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 DkTknSrv;Datakey's Token Service; C:\WINDOWS\System32\dkcktkn.exe [2004-11-23 638976]
R2 DkVcm;Datakey's Virtual Channel Monitor; C:\WINDOWS\system32\dkvcm.exe [2004-11-23 122880]
R2 EBOOSTRSVC;eBoostr Service; C:\Program Files\eBoostr\EBstrSvc.exe [2010-05-31 634488]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 FreeAgentGoNext Service;Seagate Service; C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-09-25 189736]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-06-16 488960]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-05-07 1051976]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 DkLogger;Datakey's Log Service; C:\WINDOWS\System32\DkLog.exe [2004-11-23 102400]
S2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-03-01 19200]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-04-27 611840]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-06-19 435016]
S4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
S4 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
S4 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
-----------------EOF-----------------
Logfile of random's system information tool 1.07 (written by random/random)
Run by mam-desktop at 2010-06-19 14:16:26
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 9 GB (8%) free of 118 GB
Total RAM: 2047 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:16:40, on 19.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\eBoostr\eBoostrCP.exe
C:\Program Files\Ardaco\QSign\zepapp.exe
C:\Program Files\ArsClip\ArsClip.exe
C:\Lib\Vtlac.exe
C:\WINDOWS\system32\dkvcm.exe
C:\Program Files\eBoostr\EBstrSvc.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\WINDOWS\System32\dkcktkn.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\SpeedProject\SpeedCommander 12\SpeedCommander.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\mam-desktop\Local Settings\Application Data\Opera\Opera\temporary_downloads\RSIT.exe
C:\Program Files\trend micro\mam-desktop.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.obcan.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-01-07:8080
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DkAutoReg.exe] C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe
O4 - HKLM\..\Run: [DkStartup] C:\Program Files\SafeNet\iKey 2000 Series Software\DkStartup.exe
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.1\ICQ.exe" silent loginmode=4
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ArsClip.lnk = C:\Program Files\ArsClip\ArsClip.exe
O4 - Startup: Vtlac.lnk = C:\Lib\Vtlac.exe
O4 - Global Startup: eBoostr Control Panel.lnk = C:\Program Files\eBoostr\eBoostrCP.exe
O4 - Global Startup: QSign 3.4.lnk = C:\Program Files\Ardaco\QSign\zepapp.exe
O8 - Extra context menu item: Download with Mipony - file://C:\Program Files\MiPony\Browser\IEContext.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Převést výběr do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést výběr do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: WebTran - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: &Nastaviť prekladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} (ICApki Class) - http://download.ica.cz/icapki.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DkWLNP - DkWLNP.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Datakey's Log Service (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
O23 - Service: Datakey's Token Service (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
O23 - Service: Datakey's Virtual Channel Monitor (DkVcm) - Datakey, Inc. - C:\WINDOWS\system32\dkvcm.exe
O23 - Service: eBoostr Service (EBOOSTRSVC) - eBoostr.com - C:\Program Files\eBoostr\EBstrSvc.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
--
End of file - 9488 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\PROGRA~1\PCTRAN~1\webie.dll [2004-05-13 319488]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 225280]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-03-01 1443072]
"DkAutoReg.exe"=C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe [2004-11-23 245760]
"DkStartup"=C:\Program Files\SafeNet\iKey 2000 Series Software\DkStartup.exe [2004-11-23 217088]
"MaxMenuMgr"=C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe [2009-09-25 185640]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"ICQ"=C:\Program Files\ICQ7.1\ICQ.exe [2010-06-08 133368]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2004-12-14 483328]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-11-16 139264]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe [2009-10-28 257440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
C:\Program Files\Efficasoft Mobile Express\MobileExpress.exe [2008-12-16 1040384]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-06-16 3037696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
C:\WINDOWS\system32\sti_ci.dll [2008-04-14 136704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
C:\WINDOWS\XPize\XPizeReloader.exe [2007-07-19 110139]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
C:\PROGRA~1\OVIFIL~1\OVIFIL~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
C:\PROGRA~1\WI459E~1\WINDOW~1.EXE [2008-05-26 123904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2
"ose"=3
"odserv"=3
"NBService"=3
"JavaQuickStarterService"=2
"ABBYY.Licensing.FineReader.Professional.9.0"=2
"WSearch"=2
"Themes"=2
"RDSessMgr"=3
"wscsvc"=2
"helpsvc"=2
"SysmonLog"=3
"CiSvc"=3
"ERSvc"=2
C:\Documents and Settings\All Users\Ponuka Štart\Programy\Pri spustení
eBoostr Control Panel.lnk - C:\Program Files\eBoostr\eBoostrCP.exe
QSign 3.4.lnk - C:\Program Files\Ardaco\QSign\zepapp.exe
C:\Documents and Settings\mam-desktop\Start Menu\Programs\Startup
ArsClip.lnk - C:\Program Files\ArsClip\ArsClip.exe
Vtlac.lnk - C:\Lib\Vtlac.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DkWLNP]
C:\WINDOWS\system32\DkWLNP.dll [2004-11-23 57344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Ardaco\QSign\zepapp.exe"="C:\Program Files\Ardaco\QSign\zepapp.exe:*:Enabled:QSign"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console"
"C:\Program Files\ESET\ESET Smart Security\egui.exe"="C:\Program Files\ESET\ESET Smart Security\egui.exe:*:Enabled:ESET Smart Security"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
======List of files/folders created in the last 1 months======
2010-06-19 14:16:26 ----D---- C:\rsit
2010-06-19 14:16:26 ----D---- C:\Program Files\trend micro
2010-06-19 13:52:50 ----A---- C:\ComboFix.txt
2010-06-19 13:41:03 ----A---- C:\Boot.bak
2010-06-19 13:40:59 ----RASHD---- C:\cmdcons
2010-06-19 13:37:14 ----A---- C:\WINDOWS\zip.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\SWSC.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\SWREG.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\sed.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\PEV.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\NIRCMD.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\MBR.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\grep.exe
2010-06-19 13:37:03 ----D---- C:\WINDOWS\ERDNT
2010-06-19 13:34:30 ----AD---- C:\Qoobox
2010-06-19 12:05:37 ----A---- C:\WINDOWS\ntbtlog.txt
2010-06-19 12:05:23 ----A---- C:\WINDOWS\system32\TURegOpt.exe
2010-06-19 12:05:13 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2010-06-19 12:04:16 ----D---- C:\Documents and Settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 12:02:55 ----D---- C:\Program Files\TuneUp Utilities 2010
2010-06-19 12:01:59 ----D---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2010-06-19 11:59:01 ----SHD---- C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 11:25:16 ----D---- C:\Program Files\CCleaner
2010-06-16 21:03:51 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-06-16 21:02:45 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-06-16 21:01:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-06-16 20:25:14 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-06-16 20:15:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-16 20:14:52 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-06-16 20:14:04 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-06-16 19:19:17 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2010-06-16 19:17:59 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 19:17:44 ----D---- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2010-06-16 19:17:25 ----D---- C:\Program Files\Spyware Terminator
2010-06-02 11:16:18 ----A---- C:\WINDOWS\ModemLog_Nokia E63 USB Modem #3.txt
2010-05-31 12:54:57 ----D---- C:\Documents and Settings\All Users\Application Data\eboostr
2010-05-31 12:54:41 ----D---- C:\Program Files\eBoostr
2010-05-28 11:05:05 ----D---- C:\Program Files\ICQ6Toolbar
2010-05-28 11:04:46 ----D---- C:\Documents and Settings\All Users\Application Data\ICQ
2010-05-28 11:04:26 ----D---- C:\Documents and Settings\mam-desktop\Application Data\ICQ
2010-05-28 11:04:12 ----D---- C:\Program Files\ICQ7.1
2010-05-27 10:17:54 ----HDC---- C:\WINDOWS\$NtUninstallKB963093$
2010-05-27 10:16:07 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-05-25 16:12:31 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 15:56:41 ----D---- C:\Program Files\Windows Desktop Search
2010-05-25 15:55:51 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$
2010-05-25 15:55:10 ----HDC---- C:\WINDOWS\$NtUninstallKB915800-v4$
2010-05-25 08:29:43 ----D---- C:\Documents and Settings\All Users\Application Data\ODIR
2010-05-25 00:32:33 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-05-25 00:31:34 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2010-05-24 17:25:19 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 17:22:23 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-05-24 17:21:03 ----HDC---- C:\WINDOWS\$NtUninstallWudf01007$
2010-05-24 16:58:57 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2010-05-24 16:57:24 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2010-05-24 12:35:08 ----HDC---- C:\WINDOWS\$NtUninstallWdf01009$
2010-05-23 21:40:54 ----D---- C:\Program Files\7-Zip
2010-05-22 12:33:15 ----D---- C:\Documents and Settings\All Users\Application Data\Nokia
2010-05-22 12:32:19 ----D---- C:\Program Files\PC Connectivity Solution
2010-05-22 12:31:01 ----A---- C:\WINDOWS\system32\wdfcoinstaller01009.dll
2010-05-22 12:31:01 ----A---- C:\WINDOWS\system32\nmwcdcocls.dll
2010-05-22 12:29:32 ----D---- C:\Program Files\Common Files\Nokia
======List of files/folders modified in the last 1 months======
2010-06-19 14:16:26 ----RD---- C:\Program Files
2010-06-19 13:51:43 ----SD---- C:\WINDOWS\Tasks
2010-06-19 13:50:08 ----D---- C:\WINDOWS
2010-06-19 13:50:08 ----A---- C:\WINDOWS\system.ini
2010-06-19 13:49:46 ----D---- C:\WINDOWS\Temp
2010-06-19 13:49:24 ----D---- C:\WINDOWS\system32
2010-06-19 13:48:12 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Skype
2010-06-19 13:46:35 ----D---- C:\WINDOWS\system32\drivers
2010-06-19 13:46:35 ----D---- C:\WINDOWS\AppPatch
2010-06-19 13:46:32 ----D---- C:\Program Files\Common Files
2010-06-19 13:43:01 ----D---- C:\WINDOWS\system32\CatRoot2
2010-06-19 13:41:03 ----RASH---- C:\boot.ini
2010-06-19 13:37:49 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-06-19 13:21:37 ----D---- C:\Program Files\ArsClip
2010-06-19 13:18:12 ----SHD---- C:\WINDOWS\Installer
2010-06-19 13:17:47 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-06-19 12:57:23 ----D---- C:\Documents and Settings\mam-desktop\Application Data\skypePM
2010-06-19 12:55:38 ----D---- C:\Program Files\Internet Explorer
2010-06-19 12:28:15 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-06-19 12:28:07 ----D---- C:\WINDOWS\system32\inetsrv
2010-06-19 12:05:25 ----D---- C:\WINDOWS\system32\config
2010-06-19 11:39:18 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Media Player Classic
2010-06-19 11:37:08 ----D---- C:\WINDOWS\Debug
2010-06-19 11:37:07 ----D---- C:\WINDOWS\Minidump
2010-06-19 11:25:45 ----D---- C:\WINDOWS\Prefetch
2010-06-19 11:13:18 ----HD---- C:\Program Files\InstallShield Installation Information
2010-06-19 11:03:42 ----A---- C:\WINDOWS\NeroDigital.ini
2010-06-18 06:05:01 ----D---- C:\PU
2010-06-18 00:05:13 ----D---- C:\Lib
2010-06-17 04:51:58 ----D---- C:\WINDOWS\Microsoft.NET
2010-06-17 04:49:35 ----RSD---- C:\WINDOWS\assembly
2010-06-17 00:06:52 ----HD---- C:\WINDOWS\inf
2010-06-16 21:40:20 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-06-16 21:40:08 ----D---- C:\Program Files\ESET
2010-06-16 21:04:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-06-16 21:02:36 ----HD---- C:\WINDOWS\$hf_mig$
2010-06-16 20:58:34 ----D---- C:\WINDOWS\ie8updates
2010-06-16 20:13:38 ----D---- C:\WINDOWS\system32\CatRoot
2010-06-16 20:05:08 ----D---- C:\WINDOWS\WinSxS
2010-06-08 11:38:05 ----D---- C:\PUA
2010-06-06 21:22:41 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-06-06 21:22:22 ----D---- C:\WINDOWS\security
2010-06-06 21:20:39 ----A---- C:\WINDOWS\win.ini
2010-06-06 21:16:16 ----D---- C:\WINDOWS\Help
2010-06-06 16:07:54 ----D---- C:\WINDOWS\pss
2010-06-04 15:18:23 ----A---- C:\WINDOWS\wdict32.INI
2010-06-02 19:34:36 ----HD---- C:\WINDOWS\XPize
2010-06-02 19:34:05 ----D---- C:\Program Files\WinRAR
2010-06-02 19:34:05 ----D---- C:\Program Files\Windows Media Player
2010-06-02 19:34:05 ----D---- C:\Program Files\Outlook Express
2010-06-02 19:34:05 ----D---- C:\Program Files\Common Files\System
2010-06-02 19:34:04 ----D---- C:\WINDOWS\system32\usmt
2010-06-02 19:34:04 ----D---- C:\WINDOWS\system32\Restore
2010-06-02 19:22:47 ----D---- C:\Program Files\Adobe
2010-06-02 19:12:09 ----D---- C:\Program Files\Microsoft ActiveSync
2010-06-02 18:47:34 ----D---- C:\Program Files\Efficasoft Mobile Express
2010-05-28 21:37:34 ----A---- C:\WINDOWS\system32\MRT.exe
2010-05-28 14:35:21 ----SD---- C:\Documents and Settings\mam-desktop\Application Data\Microsoft
2010-05-28 11:04:47 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Mozilla
2010-05-25 15:56:48 ----D---- C:\WINDOWS\system32\en-US
2010-05-25 15:56:40 ----HD---- C:\WINDOWS\system32\GroupPolicy
2010-05-25 15:56:40 ----D---- C:\WINDOWS\system32\wbem
2010-05-25 00:57:16 ----A---- C:\WINDOWS\system32\fmod.dll
2010-05-24 17:25:10 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Nokia
2010-05-24 17:22:55 ----D---- C:\Documents and Settings\mam-desktop\Application Data\PC Suite
2010-05-24 17:20:27 ----D---- C:\Documents and Settings\All Users\Application Data\PC Suite
2010-05-24 17:10:32 ----D---- C:\Program Files\Nokia
2010-05-24 16:57:39 ----D---- C:\WINDOWS\system32\LogFiles
2010-05-22 12:28:25 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-05-22 12:26:25 ----D---- C:\Documents and Settings\All Users\Application Data\Installations
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-03-01 29704]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2008-03-01 54280]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [1997-12-22 23936]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-03-01 39944]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2008-03-01 71176]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2008-03-01 30728]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 iKeyEnum;Rainbow iKey Enumerator; C:\WINDOWS\system32\DRIVERS\ikeyenum.sys [2004-03-16 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader; C:\WINDOWS\system32\DRIVERS\ikeyifd.sys [2004-03-16 17928]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\vinyl97.sys [2005-04-08 179968]
S3 catchme;catchme; \??\C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\catchme.sys []
S3 mbr;mbr; \??\C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\mbr.sys []
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RnbToken;Rainbow iKey Token Service; C:\WINDOWS\system32\DRIVERS\rnbtoken.sys [2004-03-16 18536]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 DkTknSrv;Datakey's Token Service; C:\WINDOWS\System32\dkcktkn.exe [2004-11-23 638976]
R2 DkVcm;Datakey's Virtual Channel Monitor; C:\WINDOWS\system32\dkvcm.exe [2004-11-23 122880]
R2 EBOOSTRSVC;eBoostr Service; C:\Program Files\eBoostr\EBstrSvc.exe [2010-05-31 634488]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 FreeAgentGoNext Service;Seagate Service; C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-09-25 189736]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-06-16 488960]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-05-07 1051976]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 DkLogger;Datakey's Log Service; C:\WINDOWS\System32\DkLog.exe [2004-11-23 102400]
S2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-03-01 19200]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-04-27 611840]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-06-19 435016]
S4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
S4 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
S4 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
-----------------EOF-----------------