pomalé pc - zátěž CPU
Napsal: 06 črc 2010 10:51
Logfile of random's system information tool 1.07 (written by random/random)
Run by Admin at 2010-07-06 11:49:12
Systém Microsoft Windows XP Professional Service Pack 3
System drive F: has 6 GB (8%) free of 76 GB
Total RAM: 1279 MB (60% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:50:01, on 6.7.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Ahead\InCD\InCDsrv.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
F:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
F:\PROGRA~1\GAMING~1\MouseElf.EXE
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Program Files\Ahead\InCD\InCD.exe
F:\Documents and Settings\Admin\Plocha\RSIT.exe
F:\Program Files\trend micro\Admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - F:\Documents and Settings\Admin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - F:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - F:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dll
O2 - BHO: SMART Notebook Download Plugin - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - F:\Program Files\SMART Technologies\Notebook Software\NotebookPlugin.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - F:\Program Files\Norton 360\Engine\3.8.0.41\IPSBHO.DLL
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - F:\Documents and Settings\Admin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - F:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - F:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - F:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [SiSUSBRG] F:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [RemoteControl] "F:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] F:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [mouseElf] F:\PROGRA~1\GAMING~1\MouseElf.EXE
O4 - HKLM\..\Run: [WinFast Schedule] F:\Program Files\WinFast\WFTVFM\WFWIZ.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Config] F:\Program Files\Microsoft Games\Age Of Empires ii\Config.exe
O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - F:\Program Files\QIP\qip.exe (HKCU)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 7367767484
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - F:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - F:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - F:\WINDOWS\system32\browseui.dll
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - F:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - F:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - F:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe
--
End of file - 7098 bytes
======Scheduled tasks folder======
F:\WINDOWS\tasks\User_Feed_Synchronization-{F0616746-75E6-4342-9B03-9BB6703669C1}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - F:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [2003-11-03 54248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - F:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - F:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dll [2009-08-22 378736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67BCF957-85FC-4036-8DC4-D4D80E00A77B}]
CIEDownload Object - F:\Program Files\SMART Technologies\Notebook Software\NotebookPlugin.dll [2009-04-28 529704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - F:\Program Files\Norton 360\Engine\3.8.0.41\IPSBHO.DLL [2009-08-22 107896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - F:\Documents and Settings\Admin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2010-03-03 149968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - F:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26 405504]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - F:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dll [2009-08-22 378736]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - F:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"=F:\WINDOWS\SiSUSBrg.exe [2002-07-12 106496]
"Cmaudio"=RunDll32 cmicnfg.cpl,CMICtrlWnd []
"RemoteControl"=F:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe [2003-12-08 32768]
"NeroFilterCheck"=F:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"mouseElf"=F:\PROGRA~1\GAMING~1\MouseElf.EXE [2005-12-16 475228]
"WinFast Schedule"=F:\Program Files\WinFast\WFTVFM\WFWIZ.exe [2004-06-23 163840]
"NvCplDaemon"=F:\WINDOWS\system32\NvCpl.dll [2006-06-01 7618560]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=F:\WINDOWS\system32\NvMcTray.dll [2006-06-01 86016]
"Config"=F:\Program Files\Microsoft Games\Age Of Empires ii\Config.exe [2006-07-06 151552]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=F:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"PowerBar"= []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - F:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SymEFA.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"F:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="F:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"F:\Program Files\TmNationsForever\TmForever.exe"="F:\Program Files\TmNationsForever\TmForever.exe:*:Enabled:TmForever"
"F:\Program Files\BitTorrent\bittorrent.exe"="F:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"F:\Program Files\EA GAMES\The Battle for Middle-earth (tm)\game.dat"="F:\Program Files\EA GAMES\The Battle for Middle-earth (tm)\game.dat:*:Enabled:The Battle for Middle-earth (tm)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6841b0f1-e8af-11de-8080-000d87968826}]
shell\AutoRun\command - winlogonss\winlogons\MS.exe
shell\open\command - winlogonss\winlogons\MS.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f4b13d90-f46d-11de-80ab-000d87968826}]
shell\AutoRun\command - G:\winlogonss\winlogons\MS.exe
shell\open\command - G:\winlogonss\winlogons\MS.exe
======List of files/folders created in the last 1 months======
2010-07-06 11:49:18 ----D---- F:\Program Files\trend micro
2010-07-06 11:49:12 ----D---- F:\rsit
2010-07-01 22:13:08 ----A---- F:\WINDOWS\atmoUn.exe
2010-07-01 22:13:04 ----D---- F:\Program Files\Viewpoint
2010-07-01 22:13:04 ----D---- F:\Documents and Settings\All Users\Data aplikací\Viewpoint
2010-07-01 17:50:53 ----A---- F:\WINDOWS\DIIUnin.exe
2010-07-01 17:19:25 ----D---- F:\Program Files\Diablo II
2010-06-23 23:18:21 ----D---- F:\Program Files\Common Files\Freedom Scientific
2010-06-23 23:18:17 ----D---- F:\Program Files\Common Files\soft602
======List of files/folders modified in the last 1 months======
2010-07-06 11:49:18 ----RD---- F:\Program Files
2010-07-06 11:49:17 ----D---- F:\WINDOWS\Temp
2010-07-06 11:34:55 ----A---- F:\WINDOWS\wincmd.ini
2010-07-05 23:20:00 ----A---- F:\WINDOWS\SchedLgU.Txt
2010-07-05 22:26:52 ----D---- F:\Documents and Settings\Admin\Data aplikací\vlc
2010-07-05 21:04:14 ----A---- F:\WINDOWS\NeroDigital.ini
2010-07-05 15:15:23 ----D---- F:\WINDOWS\Minidump
2010-07-05 15:14:43 ----D---- F:\WINDOWS
2010-07-04 21:53:40 ----D---- F:\WINDOWS\system32\CatRoot2
2010-07-03 23:23:22 ----D---- F:\Documents and Settings\Admin\Data aplikací\BitTorrent
2010-07-03 00:09:25 ----D---- F:\Documents and Settings\Admin\Data aplikací\BSplayer
2010-07-01 21:26:30 ----D---- F:\WINDOWS\Prefetch
2010-06-28 19:26:35 ----D---- F:\Program Files\Microsoft Games
2010-06-28 16:19:33 ----D---- F:\Program Files\World of Warcraft
2010-06-28 16:04:52 ----HD---- F:\Program Files\InstallShield Installation Information
2010-06-28 16:04:52 ----D---- F:\Program Files\Commandos II
2010-06-28 16:02:29 ----D---- F:\WINDOWS\system32
2010-06-28 09:48:49 ----A---- F:\WINDOWS\Wininit.ini
2010-06-28 08:49:07 ----D---- F:\Program Files\Mozilla Firefox
2010-06-23 23:18:53 ----SHD---- F:\WINDOWS\Installer
2010-06-23 23:18:53 ----SHD---- F:\Config.Msi
2010-06-23 23:18:21 ----D---- F:\Program Files\Common Files
2010-06-12 18:55:54 ----D---- F:\Documents and Settings\Admin\Data aplikací\My Battle for Middle-earth Files
2010-06-09 08:28:37 ----A---- F:\WINDOWS\win.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK7;Ovladač procesoru AMD K7; F:\WINDOWS\System32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 BHDrvx86;Symantec Heuristics Driver; F:\WINDOWS\System32\Drivers\N360\0308000.029\BHDrvx86.sys [2009-08-22 259632]
R1 ccHP;Symantec Hash Provider; F:\WINDOWS\System32\Drivers\N360\0308000.029\ccHPx86.sys [2009-08-22 482432]
R1 cdrbsdrv;cdrbsdrv; F:\WINDOWS\system32\drivers\cdrbsdrv.sys [2004-03-08 13567]
R1 eeCtrl;Symantec Eraser Control driver; \??\F:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 IDSxpx86;IDSxpx86; \??\F:\Documents and Settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100706.002\IDSxpx86.sys []
R1 InCDPass;InCDPass; F:\WINDOWS\System32\DRIVERS\InCDPass.sys [2004-09-07 28544]
R1 SRTSP;Symantec Real Time Storage Protection; F:\WINDOWS\System32\Drivers\N360\0308000.029\SRTSP.SYS [2009-08-22 308272]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); F:\WINDOWS\system32\drivers\N360\0308000.029\SRTSPX.SYS [2009-08-22 43696]
R1 SYMTDI;Symantec Network Dispatch Driver; F:\WINDOWS\System32\Drivers\N360\0308000.029\SYMTDI.SYS [2009-08-22 217136]
R2 BT848;WinFast TV2000 XP WDM Video Capture; F:\WINDOWS\system32\drivers\wf2kvcap.sys [2004-03-12 75829]
R2 tv2ktunr;WinFast TV2000 XP WDM TVTuner; F:\WINDOWS\system32\drivers\wf2ktunr.sys [2004-03-12 33959]
R2 Tv2kXbar;WinFast TV2000 XP WDM Crossbar; F:\WINDOWS\system32\drivers\wf2kxbar.sys [2004-03-12 10005]
R3 cmuda;C-Media WDM Audio Interface; F:\WINDOWS\system32\drivers\cmuda.sys [2003-07-01 733248]
R3 genmcmnUSB;USB Scroll Mouse Driver; F:\WINDOWS\System32\DRIVERS\gflmouhid.sys [2005-07-12 7808]
R3 gHidUsbF;USB Device Enhanced Function Driver; F:\WINDOWS\System32\Drivers\gHidUsbF.Sys [2005-07-11 12800]
R3 HidUsb;Ovladač třídy standardu HID; F:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; F:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 NAVENG;NAVENG; \??\F:\Documents and Settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100705.040\NAVENG.SYS []
R3 NAVEX15;NAVEX15; \??\F:\Documents and Settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100705.040\NAVEX15.SYS []
R3 nv;nv; F:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2006-06-01 3925920]
R3 pfc;Padus ASPI Shell; F:\WINDOWS\system32\drivers\pfc.sys [2003-12-05 10368]
R3 SISNIC;SiS PCI Fast Ethernet Adapter Driver; F:\WINDOWS\System32\DRIVERS\sisnic.sys [2002-07-10 32256]
R3 SymEvent;SymEvent; \??\F:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
R3 SYMFW;Symantec Network Filter Driver; F:\WINDOWS\System32\Drivers\N360\0308000.029\SYMFW.SYS [2009-08-22 89904]
R3 SYMIDS;Symantec Network Filter Driver; F:\WINDOWS\System32\Drivers\N360\0308000.029\SYMIDS.SYS [2009-08-22 33072]
R3 SymIMMP;SymIMMP; F:\WINDOWS\system32\DRIVERS\SymIM.sys [2009-08-22 36400]
R3 SYMNDIS;Symantec Network Filter Driver; F:\WINDOWS\System32\Drivers\N360\0308000.029\SYMNDIS.SYS [2009-08-22 36400]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; F:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 usbhub;Rozbočovač umožnující USB2; F:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; F:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-14 17152]
R3 WFIOCTL;WFIOCTL; \??\F:\Program Files\WinFast\WFTVFM\WFIOCTL.SYS []
R4 InCDfs;InCD File System; F:\WINDOWS\system32\drivers\InCDfs.sys [2004-09-07 91136]
S1 kbdhid;Ovladač klávesnice standardu HID; F:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 a9jhgews;a9jhgews; F:\WINDOWS\system32\drivers\a9jhgews.sys []
S3 aqljvnpo;aqljvnpo; F:\WINDOWS\system32\drivers\aqljvnpo.sys []
S3 CCDECODE;Dekodér Closed Caption; F:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 genmcmn;Scroll Mouse Driver; F:\WINDOWS\System32\DRIVERS\gmfiltr.sys [2005-07-02 16896]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; F:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; F:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; F:\WINDOWS\System32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 SLIP;BDA Slip De-Framer; F:\WINDOWS\System32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; F:\WINDOWS\System32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 SymIM;Symantec Network Security Intermediate Filter Service; F:\WINDOWS\system32\DRIVERS\SymIM.sys [2009-08-22 36400]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; F:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; F:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-14 30208]
S3 usbprint;Třída USB Printer; F:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; F:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WSTCODEC;Dálnopisný kodek světového standardu; F:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; F:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; F:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; F:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 InCDsrv;InCD Helper; F:\Program Files\Ahead\InCD\InCDsrv.exe [2004-09-07 1151090]
R2 N360;Norton 360; F:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe [2009-08-22 117640]
S2 602XML Updater;602Updater; F:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
S2 NVSvc;NVIDIA Display Driver Service; F:\WINDOWS\system32\nvsvc32.exe [2006-06-01 155715]
S3 aspnet_state;ASP.NET State Service; F:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; F:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 odserv;Microsoft Office Diagnostics Service; F:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; F:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; F:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; F:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
-----------------EOF-----------------
Run by Admin at 2010-07-06 11:49:12
Systém Microsoft Windows XP Professional Service Pack 3
System drive F: has 6 GB (8%) free of 76 GB
Total RAM: 1279 MB (60% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:50:01, on 6.7.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Ahead\InCD\InCDsrv.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
F:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
F:\PROGRA~1\GAMING~1\MouseElf.EXE
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Program Files\Ahead\InCD\InCD.exe
F:\Documents and Settings\Admin\Plocha\RSIT.exe
F:\Program Files\trend micro\Admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - F:\Documents and Settings\Admin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - F:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - F:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dll
O2 - BHO: SMART Notebook Download Plugin - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - F:\Program Files\SMART Technologies\Notebook Software\NotebookPlugin.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - F:\Program Files\Norton 360\Engine\3.8.0.41\IPSBHO.DLL
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - F:\Documents and Settings\Admin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - F:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - F:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - F:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [SiSUSBRG] F:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [RemoteControl] "F:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] F:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [mouseElf] F:\PROGRA~1\GAMING~1\MouseElf.EXE
O4 - HKLM\..\Run: [WinFast Schedule] F:\Program Files\WinFast\WFTVFM\WFWIZ.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Config] F:\Program Files\Microsoft Games\Age Of Empires ii\Config.exe
O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - F:\Program Files\QIP\qip.exe (HKCU)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 7367767484
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - F:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - F:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - F:\WINDOWS\system32\browseui.dll
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - F:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - F:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - F:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe
--
End of file - 7098 bytes
======Scheduled tasks folder======
F:\WINDOWS\tasks\User_Feed_Synchronization-{F0616746-75E6-4342-9B03-9BB6703669C1}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - F:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [2003-11-03 54248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - F:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - F:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dll [2009-08-22 378736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67BCF957-85FC-4036-8DC4-D4D80E00A77B}]
CIEDownload Object - F:\Program Files\SMART Technologies\Notebook Software\NotebookPlugin.dll [2009-04-28 529704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - F:\Program Files\Norton 360\Engine\3.8.0.41\IPSBHO.DLL [2009-08-22 107896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - F:\Documents and Settings\Admin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2010-03-03 149968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - F:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26 405504]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - F:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dll [2009-08-22 378736]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - F:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"=F:\WINDOWS\SiSUSBrg.exe [2002-07-12 106496]
"Cmaudio"=RunDll32 cmicnfg.cpl,CMICtrlWnd []
"RemoteControl"=F:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe [2003-12-08 32768]
"NeroFilterCheck"=F:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"mouseElf"=F:\PROGRA~1\GAMING~1\MouseElf.EXE [2005-12-16 475228]
"WinFast Schedule"=F:\Program Files\WinFast\WFTVFM\WFWIZ.exe [2004-06-23 163840]
"NvCplDaemon"=F:\WINDOWS\system32\NvCpl.dll [2006-06-01 7618560]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=F:\WINDOWS\system32\NvMcTray.dll [2006-06-01 86016]
"Config"=F:\Program Files\Microsoft Games\Age Of Empires ii\Config.exe [2006-07-06 151552]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=F:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"PowerBar"= []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - F:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SymEFA.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"F:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="F:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"F:\Program Files\TmNationsForever\TmForever.exe"="F:\Program Files\TmNationsForever\TmForever.exe:*:Enabled:TmForever"
"F:\Program Files\BitTorrent\bittorrent.exe"="F:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"F:\Program Files\EA GAMES\The Battle for Middle-earth (tm)\game.dat"="F:\Program Files\EA GAMES\The Battle for Middle-earth (tm)\game.dat:*:Enabled:The Battle for Middle-earth (tm)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6841b0f1-e8af-11de-8080-000d87968826}]
shell\AutoRun\command - winlogonss\winlogons\MS.exe
shell\open\command - winlogonss\winlogons\MS.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f4b13d90-f46d-11de-80ab-000d87968826}]
shell\AutoRun\command - G:\winlogonss\winlogons\MS.exe
shell\open\command - G:\winlogonss\winlogons\MS.exe
======List of files/folders created in the last 1 months======
2010-07-06 11:49:18 ----D---- F:\Program Files\trend micro
2010-07-06 11:49:12 ----D---- F:\rsit
2010-07-01 22:13:08 ----A---- F:\WINDOWS\atmoUn.exe
2010-07-01 22:13:04 ----D---- F:\Program Files\Viewpoint
2010-07-01 22:13:04 ----D---- F:\Documents and Settings\All Users\Data aplikací\Viewpoint
2010-07-01 17:50:53 ----A---- F:\WINDOWS\DIIUnin.exe
2010-07-01 17:19:25 ----D---- F:\Program Files\Diablo II
2010-06-23 23:18:21 ----D---- F:\Program Files\Common Files\Freedom Scientific
2010-06-23 23:18:17 ----D---- F:\Program Files\Common Files\soft602
======List of files/folders modified in the last 1 months======
2010-07-06 11:49:18 ----RD---- F:\Program Files
2010-07-06 11:49:17 ----D---- F:\WINDOWS\Temp
2010-07-06 11:34:55 ----A---- F:\WINDOWS\wincmd.ini
2010-07-05 23:20:00 ----A---- F:\WINDOWS\SchedLgU.Txt
2010-07-05 22:26:52 ----D---- F:\Documents and Settings\Admin\Data aplikací\vlc
2010-07-05 21:04:14 ----A---- F:\WINDOWS\NeroDigital.ini
2010-07-05 15:15:23 ----D---- F:\WINDOWS\Minidump
2010-07-05 15:14:43 ----D---- F:\WINDOWS
2010-07-04 21:53:40 ----D---- F:\WINDOWS\system32\CatRoot2
2010-07-03 23:23:22 ----D---- F:\Documents and Settings\Admin\Data aplikací\BitTorrent
2010-07-03 00:09:25 ----D---- F:\Documents and Settings\Admin\Data aplikací\BSplayer
2010-07-01 21:26:30 ----D---- F:\WINDOWS\Prefetch
2010-06-28 19:26:35 ----D---- F:\Program Files\Microsoft Games
2010-06-28 16:19:33 ----D---- F:\Program Files\World of Warcraft
2010-06-28 16:04:52 ----HD---- F:\Program Files\InstallShield Installation Information
2010-06-28 16:04:52 ----D---- F:\Program Files\Commandos II
2010-06-28 16:02:29 ----D---- F:\WINDOWS\system32
2010-06-28 09:48:49 ----A---- F:\WINDOWS\Wininit.ini
2010-06-28 08:49:07 ----D---- F:\Program Files\Mozilla Firefox
2010-06-23 23:18:53 ----SHD---- F:\WINDOWS\Installer
2010-06-23 23:18:53 ----SHD---- F:\Config.Msi
2010-06-23 23:18:21 ----D---- F:\Program Files\Common Files
2010-06-12 18:55:54 ----D---- F:\Documents and Settings\Admin\Data aplikací\My Battle for Middle-earth Files
2010-06-09 08:28:37 ----A---- F:\WINDOWS\win.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK7;Ovladač procesoru AMD K7; F:\WINDOWS\System32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 BHDrvx86;Symantec Heuristics Driver; F:\WINDOWS\System32\Drivers\N360\0308000.029\BHDrvx86.sys [2009-08-22 259632]
R1 ccHP;Symantec Hash Provider; F:\WINDOWS\System32\Drivers\N360\0308000.029\ccHPx86.sys [2009-08-22 482432]
R1 cdrbsdrv;cdrbsdrv; F:\WINDOWS\system32\drivers\cdrbsdrv.sys [2004-03-08 13567]
R1 eeCtrl;Symantec Eraser Control driver; \??\F:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 IDSxpx86;IDSxpx86; \??\F:\Documents and Settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100706.002\IDSxpx86.sys []
R1 InCDPass;InCDPass; F:\WINDOWS\System32\DRIVERS\InCDPass.sys [2004-09-07 28544]
R1 SRTSP;Symantec Real Time Storage Protection; F:\WINDOWS\System32\Drivers\N360\0308000.029\SRTSP.SYS [2009-08-22 308272]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); F:\WINDOWS\system32\drivers\N360\0308000.029\SRTSPX.SYS [2009-08-22 43696]
R1 SYMTDI;Symantec Network Dispatch Driver; F:\WINDOWS\System32\Drivers\N360\0308000.029\SYMTDI.SYS [2009-08-22 217136]
R2 BT848;WinFast TV2000 XP WDM Video Capture; F:\WINDOWS\system32\drivers\wf2kvcap.sys [2004-03-12 75829]
R2 tv2ktunr;WinFast TV2000 XP WDM TVTuner; F:\WINDOWS\system32\drivers\wf2ktunr.sys [2004-03-12 33959]
R2 Tv2kXbar;WinFast TV2000 XP WDM Crossbar; F:\WINDOWS\system32\drivers\wf2kxbar.sys [2004-03-12 10005]
R3 cmuda;C-Media WDM Audio Interface; F:\WINDOWS\system32\drivers\cmuda.sys [2003-07-01 733248]
R3 genmcmnUSB;USB Scroll Mouse Driver; F:\WINDOWS\System32\DRIVERS\gflmouhid.sys [2005-07-12 7808]
R3 gHidUsbF;USB Device Enhanced Function Driver; F:\WINDOWS\System32\Drivers\gHidUsbF.Sys [2005-07-11 12800]
R3 HidUsb;Ovladač třídy standardu HID; F:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; F:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 NAVENG;NAVENG; \??\F:\Documents and Settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100705.040\NAVENG.SYS []
R3 NAVEX15;NAVEX15; \??\F:\Documents and Settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100705.040\NAVEX15.SYS []
R3 nv;nv; F:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2006-06-01 3925920]
R3 pfc;Padus ASPI Shell; F:\WINDOWS\system32\drivers\pfc.sys [2003-12-05 10368]
R3 SISNIC;SiS PCI Fast Ethernet Adapter Driver; F:\WINDOWS\System32\DRIVERS\sisnic.sys [2002-07-10 32256]
R3 SymEvent;SymEvent; \??\F:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
R3 SYMFW;Symantec Network Filter Driver; F:\WINDOWS\System32\Drivers\N360\0308000.029\SYMFW.SYS [2009-08-22 89904]
R3 SYMIDS;Symantec Network Filter Driver; F:\WINDOWS\System32\Drivers\N360\0308000.029\SYMIDS.SYS [2009-08-22 33072]
R3 SymIMMP;SymIMMP; F:\WINDOWS\system32\DRIVERS\SymIM.sys [2009-08-22 36400]
R3 SYMNDIS;Symantec Network Filter Driver; F:\WINDOWS\System32\Drivers\N360\0308000.029\SYMNDIS.SYS [2009-08-22 36400]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; F:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 usbhub;Rozbočovač umožnující USB2; F:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; F:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-14 17152]
R3 WFIOCTL;WFIOCTL; \??\F:\Program Files\WinFast\WFTVFM\WFIOCTL.SYS []
R4 InCDfs;InCD File System; F:\WINDOWS\system32\drivers\InCDfs.sys [2004-09-07 91136]
S1 kbdhid;Ovladač klávesnice standardu HID; F:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 a9jhgews;a9jhgews; F:\WINDOWS\system32\drivers\a9jhgews.sys []
S3 aqljvnpo;aqljvnpo; F:\WINDOWS\system32\drivers\aqljvnpo.sys []
S3 CCDECODE;Dekodér Closed Caption; F:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 genmcmn;Scroll Mouse Driver; F:\WINDOWS\System32\DRIVERS\gmfiltr.sys [2005-07-02 16896]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; F:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; F:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; F:\WINDOWS\System32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 SLIP;BDA Slip De-Framer; F:\WINDOWS\System32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; F:\WINDOWS\System32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 SymIM;Symantec Network Security Intermediate Filter Service; F:\WINDOWS\system32\DRIVERS\SymIM.sys [2009-08-22 36400]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; F:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; F:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-14 30208]
S3 usbprint;Třída USB Printer; F:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; F:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WSTCODEC;Dálnopisný kodek světového standardu; F:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; F:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; F:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; F:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 InCDsrv;InCD Helper; F:\Program Files\Ahead\InCD\InCDsrv.exe [2004-09-07 1151090]
R2 N360;Norton 360; F:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe [2009-08-22 117640]
S2 602XML Updater;602Updater; F:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
S2 NVSvc;NVIDIA Display Driver Service; F:\WINDOWS\system32\nvsvc32.exe [2006-06-01 155715]
S3 aspnet_state;ASP.NET State Service; F:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; F:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 odserv;Microsoft Office Diagnostics Service; F:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; F:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; F:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; F:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
-----------------EOF-----------------