mavcrt.dll + Perflib_Perfdata_6fc.dat
Napsal: 07 črc 2010 12:35
Omlouvám se, že vás opět otravuji, ale včéra jsem stáhnul jeden key generátor z uloz.to, po stáhnutí jsem ho ovšem projel nodem pro jistotu nic to nenašlo tak jsem řikal, že je vše v pohodě, ale neni. Dnes nod vypsal, že poslal do karentény podezřelé soubory ten keygen.exe a pak nějaký chybné soubory v C:\Documents and Settings bez infekce. Pak když jsem chtěl promazat složku C:\Documents and Settings\Claymore\Local Settings\Temp tak to napsalo, že jedne soubor se používá Perflib_Perfdata_6fc.dat tak jsem ho vygoogloval a našel jsem si na to prográm Prevx z officiálních stránek jsem ho stáhnul a ten našel Malware v systemu32 v souboru mavcrt.dll, ale chce to licenci na vyčištění. Bůh ví co tam dál je a co nod32 nenašel, moc děkuji za pomoc.
// Perflib_Perfdata_6fc.dat - už tam neni..
// ani mavcrt.dll neni tak kde má být, počítač jsem projel Spyware terminátorem a nic to nenašlo, ted to projizdim Malwarebytem.
// Malware našel ten keygen.exe v koši a nebyl aktivní tak jsem jen vysypal koš, přes to prosím o kontrolu logu. (dám nový z RSIT)
Logfile of random's system information tool 1.07 (written by random/random)
Run by Claymore at 2010-07-07 14:28:14
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 7 GB (18%) free of 38 GB
Total RAM: 1023 MB (53% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:28:18, on 7.7.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Claymore\Plocha\RSIT.exe
C:\Program Files\trend micro\Claymore.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60347
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/homepage.aspx?tbid=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.2\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
--
End of file - 8844 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-06-25 1241552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-03-31 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-03-31 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-04-12 1018616]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-11-24 953800]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-06-25 1241552]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"=C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe [2004-06-03 131072]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-16 13529088]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-05-16 86016]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-02-06 2021400]
"SpywareTerminator"=C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe [2010-07-07 2176512]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"ICQ"=C:\Program Files\ICQ7.2\ICQ.exe [2010-06-11 133368]
"SpywareTerminatorUpdate"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-07-07 3037696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Claymore\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe /c []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2010-03-09 26100520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Claymore^Nabídka Start^Programy^Po spuštění^WinMySQLadmin.lnk]
C:\Documents and Settings\Claymore\Plocha\PaikProductions Blizzlike Repack\Server\mysql\bin\winmysqladmin.exe []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vds]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Documents and Settings\Claymore\Plocha\announce_trailer_en_us.exe"="C:\Documents and Settings\Claymore\Plocha\announce_trailer_en_us.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Metin2_CZ\metin2client.bin"="C:\Program Files\Metin2_CZ\metin2client.bin:*:Enabled:metin2client"
"C:\Program Files\ItalongjuMT2\ItalongjuMt2.exe"="C:\Program Files\ItalongjuMT2\ItalongjuMt2.exe:*:Enabled:ItalongjuMt2"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Gamesy\KnightShift\KnightShift.ex2"="C:\Gamesy\KnightShift\KnightShift.ex2:*:Enabled:KnightShift"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"
"C:\Program Files\Counter-Strike 1.6\hl.exe"="C:\Program Files\Counter-Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\HLSW\hlsw.exe"="C:\Program Files\HLSW\hlsw.exe:*:Enabled:HLSW Application"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Documents and Settings\Claymore\Plocha\Hell_Gaming_Server\TrinityCore.exe"="C:\Documents and Settings\Claymore\Plocha\Hell_Gaming_Server\TrinityCore.exe:*:Enabled:TrinityCore"
"C:\Documents and Settings\Claymore\Plocha\Server\Hell_Gaming_Server\TrinityCore.exe"="C:\Documents and Settings\Claymore\Plocha\Server\Hell_Gaming_Server\TrinityCore.exe:*:Enabled:TrinityCore"
"C:\Documents and Settings\Claymore\Plocha\Server\8269\TrinityCore.exe"="C:\Documents and Settings\Claymore\Plocha\Server\8269\TrinityCore.exe:*:Enabled:TrinityCore"
"C:\Documents and Settings\Claymore\Plocha\MaNGOS Repack Ver.6.33\Server\apache\bin\apache.exe"="C:\Documents and Settings\Claymore\Plocha\MaNGOS Repack Ver.6.33\Server\apache\bin\apache.exe:*:Enabled:Apache HTTP Server"
"C:\Documents and Settings\Claymore\Plocha\MaNGOS Repack Ver.6.33\Server\mysql\bin\mysqld.exe"="C:\Documents and Settings\Claymore\Plocha\MaNGOS Repack Ver.6.33\Server\mysql\bin\mysqld.exe:*:Enabled:mysqld"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"C:\Documents and Settings\Claymore\Plocha\Blacknight-mt2 client 1.2\lib\game\Game.exe"="C:\Documents and Settings\Claymore\Plocha\Blacknight-mt2 client 1.2\lib\game\Game.exe:*:Enabled:Game"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2010-07-07 14:01:53 ----D---- C:\Program Files\Crawler
2010-07-07 14:01:45 ----D---- C:\Documents and Settings\Claymore\Data aplikací\Spyware Terminator
2010-07-07 14:01:42 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2010-07-07 14:01:38 ----D---- C:\Program Files\Spyware Terminator
2010-07-07 13:39:18 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-07-07 13:35:17 ----D---- C:\rsit
2010-07-07 13:24:33 ----D---- C:\Documents and Settings\All Users\Data aplikací\PrevxCSI
2010-07-07 13:24:32 ----A---- C:\WINDOWS\wininit.ini
2010-07-07 07:50:44 ----SHD---- C:\found.000
2010-07-06 12:27:32 ----D---- C:\Program Files\Ventrilo
2010-07-06 12:27:17 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-07-06 12:12:51 ----A---- C:\WINDOWS\UPGRADE.TXT
2010-07-06 11:46:55 ----D---- C:\Program Files\VS Revo Group
2010-07-06 11:28:10 ----D---- C:\Program Files\Yamicsoft
2010-07-06 10:25:35 ----D---- C:\Program Files\Counter-Strike 1.6
2010-07-06 10:09:35 ----D---- C:\Program Files\Hamachi(3)
2010-07-06 02:39:07 ----D---- C:\Program Files\Hamachi(2)
2010-07-05 20:16:38 ----D---- C:\Documents and Settings\Claymore\Data aplikací\Malwarebytes
2010-07-05 20:15:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-07-01 08:47:19 ----D---- C:\Program Files\IObit
2010-06-27 03:01:26 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-06-27 03:01:07 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-06-26 18:33:26 ----D---- C:\Program Files\CCleaner
2010-06-25 13:55:38 ----D---- C:\WINDOWS\Prefetch
2010-06-25 13:40:26 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-06-25 13:40:09 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-06-25 13:39:47 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-06-25 13:39:30 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-06-25 13:39:18 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-06-25 13:39:06 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-06-25 13:38:55 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-06-25 13:38:43 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-06-25 13:38:28 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-06-25 13:38:15 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-06-25 13:37:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-06-25 13:37:44 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-06-25 13:37:31 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-06-25 13:37:12 ----HDC---- C:\WINDOWS\$NtUninstallKB977165-v2$
2010-06-25 13:36:56 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-06-25 13:36:43 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-06-25 13:36:31 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-06-25 13:36:18 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-06-25 13:36:02 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-06-25 13:35:46 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-06-25 13:35:29 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-06-25 13:35:12 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-06-25 13:34:54 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-06-25 13:34:37 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-06-25 13:34:19 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-06-25 13:34:00 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-06-25 13:33:43 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-06-25 13:33:24 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-06-25 13:33:07 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-06-25 13:32:54 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-06-25 13:32:41 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-06-25 13:32:31 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-06-25 13:32:19 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-06-25 13:31:57 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-06-25 13:31:43 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-06-25 13:31:27 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-06-25 13:31:13 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-06-25 13:31:00 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-06-25 13:30:35 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-06-25 13:30:24 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-06-25 13:29:16 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-06-25 13:29:05 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-06-25 13:28:45 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-06-25 13:28:35 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-06-25 13:28:27 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-06-25 13:28:24 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-06-25 13:28:15 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2010-06-25 13:28:14 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-06-25 13:28:06 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-06-25 13:28:02 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-06-25 13:27:56 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-06-25 13:27:52 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-06-25 13:27:47 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-06-25 13:27:42 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-06-25 13:27:33 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-06-25 13:27:21 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-06-25 13:27:20 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-06-25 13:27:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-06-25 13:26:45 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2010-06-25 13:26:32 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-06-25 13:26:22 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-06-25 13:26:04 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-06-25 13:25:51 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-06-25 13:12:51 ----D---- C:\WINDOWS\l2schemas
2010-06-25 13:12:50 ----D---- C:\WINDOWS\system32\cs
2010-06-25 13:12:50 ----D---- C:\WINDOWS\system32\bits
2010-06-25 10:29:27 ----D---- C:\Program Files\trend micro
2010-06-25 09:36:20 ----D---- C:\WINDOWS\pss
2010-06-23 13:35:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\McAfee
2010-06-20 13:04:07 ----A---- C:\WINDOWS\system32\wshirda.dll
2010-06-20 13:04:07 ----A---- C:\WINDOWS\system32\irmon.dll
2010-06-20 13:04:07 ----A---- C:\WINDOWS\system32\irftp.exe
2010-06-12 11:36:57 ----D---- C:\Documents and Settings\Claymore\Data aplikací\Apple Computer
2010-06-11 21:21:33 ----A---- C:\WINDOWS\system32\unrar.dll
2010-06-11 21:21:25 ----D---- C:\Program Files\K-Lite Codec Pack
2010-06-11 20:24:16 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-06-11 20:22:58 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2010-06-11 19:12:30 ----D---- C:\Program Files\ICQ7.2
2010-06-11 06:36:13 ----HDC---- C:\WINDOWS\$NtUninstallKB980218_0$
2010-06-11 06:35:08 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-06-11 06:34:33 ----HDC---- C:\WINDOWS\$NtUninstallKB979559_0$
2010-06-11 06:23:33 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-11 06:23:03 ----HDC---- C:\WINDOWS\$NtUninstallKB979482_0$
2010-06-11 06:22:38 ----HDC---- C:\WINDOWS\$NtUninstallKB975562_0$
2010-06-10 16:27:21 ----D---- C:\Documents and Settings\Claymore\Data aplikací\Facebook
======List of files/folders modified in the last 1 months======
2010-07-07 14:27:09 ----D---- C:\WINDOWS\Temp
2010-07-07 14:22:54 ----D---- C:\WINDOWS\system32
2010-07-07 14:22:28 ----D---- C:\WINDOWS\system32\drivers
2010-07-07 14:01:53 ----RD---- C:\Program Files
2010-07-07 13:48:21 ----D---- C:\Documents and Settings\Claymore\Data aplikací\Skype
2010-07-07 13:24:32 ----D---- C:\WINDOWS
2010-07-07 12:48:45 ----D---- C:\Documents and Settings\Claymore\Data aplikací\skypePM
2010-07-07 08:31:22 ----D---- C:\Documents and Settings\Claymore\Data aplikací\ICQ
2010-07-07 07:11:48 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-07-06 12:27:35 ----SHD---- C:\WINDOWS\Installer
2010-07-06 12:27:17 ----D---- C:\Program Files\Common Files
2010-07-06 12:20:03 ----D---- C:\WINDOWS\SxsCaPendDel
2010-07-06 12:17:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-07-06 12:01:55 ----D---- C:\WINDOWS\system32\CatRoot
2010-07-06 12:01:53 ----D---- C:\WINDOWS\system32\CatRoot2
2010-07-06 11:52:50 ----D---- C:\Program Files\Common Files\Adobe
2010-07-06 11:52:50 ----D---- C:\Documents and Settings\Claymore\Data aplikací\Adobe
2010-07-06 11:49:54 ----D---- C:\Documents and Settings\Claymore\Data aplikací\Hamachi
2010-07-06 11:28:19 ----SD---- C:\Documents and Settings\Claymore\Data aplikací\Microsoft
2010-07-06 10:46:11 ----SD---- C:\WINDOWS\Tasks
2010-07-06 10:27:17 ----D---- C:\WINDOWS\system32\config
2010-07-06 10:26:50 ----D---- C:\WINDOWS\system32\wbem
2010-07-06 10:26:46 ----D---- C:\WINDOWS\Registration
2010-07-06 10:26:18 ----D---- C:\Gamesy
2010-07-06 10:25:11 ----D---- C:\Program Files\Mozilla Firefox
2010-07-06 10:25:05 ----HD---- C:\WINDOWS\inf
2010-06-29 09:36:58 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-06-27 03:04:14 ----D---- C:\WINDOWS\Debug
2010-06-27 03:00:55 ----HD---- C:\WINDOWS\$hf_mig$
2010-06-26 18:42:20 ----D---- C:\WINDOWS\Microsoft.NET
2010-06-26 18:42:16 ----RSD---- C:\WINDOWS\assembly
2010-06-25 14:02:20 ----SH---- C:\boot.ini
2010-06-25 14:02:20 ----A---- C:\WINDOWS\win.ini
2010-06-25 14:02:20 ----A---- C:\WINDOWS\system.ini
2010-06-25 13:55:01 ----D---- C:\WINDOWS\system32\Setup
2010-06-25 13:55:01 ----D---- C:\WINDOWS\AppPatch
2010-06-25 13:54:59 ----RSD---- C:\WINDOWS\Fonts
2010-06-25 13:38:34 ----D---- C:\Program Files\Outlook Express
2010-06-25 13:36:33 ----D---- C:\Program Files\Movie Maker
2010-06-25 13:26:06 ----D---- C:\Program Files\Messenger
2010-06-25 13:17:53 ----D---- C:\WINDOWS\security
2010-06-25 13:14:03 ----D---- C:\WINDOWS\WinSxS
2010-06-25 13:13:43 ----D---- C:\WINDOWS\ehome
2010-06-25 13:13:37 ----D---- C:\WINDOWS\system32\inetsrv
2010-06-25 13:13:37 ----D---- C:\WINDOWS\network diagnostic
2010-06-25 13:13:37 ----D---- C:\WINDOWS\Help
2010-06-25 13:13:36 ----D---- C:\WINDOWS\ime
2010-06-25 13:12:54 ----D---- C:\WINDOWS\system32\usmt
2010-06-25 13:12:54 ----D---- C:\WINDOWS\system32\cs-CZ
2010-06-25 13:12:52 ----D---- C:\Program Files\Internet Explorer
2010-06-25 13:12:50 ----D---- C:\WINDOWS\PeerNet
2010-06-25 12:57:43 ----D---- C:\WINDOWS\system32\Restore
2010-06-25 12:57:42 ----D---- C:\WINDOWS\system32\npp
2010-06-25 12:57:37 ----D---- C:\WINDOWS\msagent
2010-06-25 12:57:27 ----D---- C:\WINDOWS\srchasst
2010-06-25 12:57:23 ----D---- C:\Program Files\NetMeeting
2010-06-25 12:57:14 ----D---- C:\WINDOWS\system32\Com
2010-06-25 12:57:04 ----D---- C:\Program Files\Windows Media Player
2010-06-25 12:57:02 ----D---- C:\Program Files\Windows NT
2010-06-25 12:56:46 ----D---- C:\Program Files\Common Files\System
2010-06-25 12:55:10 ----D---- C:\WINDOWS\system32\oobe
2010-06-25 12:55:07 ----D---- C:\WINDOWS\system
2010-06-25 12:32:03 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-06-25 12:31:38 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-06-22 08:28:25 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-06-20 12:40:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-06-12 06:53:43 ----D---- C:\Program Files\ICQ6Toolbar
2010-06-11 20:23:14 ----D---- C:\Program Files\Windows Media Connect 2
2010-06-11 19:15:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\ICQ
2010-06-11 19:13:24 ----HD---- C:\Program Files\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2009-02-06 93336]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-02-06 113448]
R3 BthEnum;Služba Bluetooth Enumerator; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-05-15 25280]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-11-18 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-16 6557408]
R3 nvax;Service for NVIDIA(R) nForce(TM) Audio Enumerator; C:\WINDOWS\system32\drivers\nvax.sys [2004-05-25 48640]
R3 NVENET;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENET.sys [2004-01-29 93764]
R3 nvnforce;Service for NVIDIA(R) nForce(TM) Audio; C:\WINDOWS\system32\drivers\nvapu.sys [2004-05-25 396032]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
S3 a8tvreq5;a8tvreq5; C:\WINDOWS\system32\drivers\a8tvreq5.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 EraserUtilDrvI9;EraserUtilDrvI9; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys []
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-02-06 727720]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-04-12 246520]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-03-31 153376]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-16 159812]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-07-07 488960]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-02-06 20680]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-03-27 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
// Perflib_Perfdata_6fc.dat - už tam neni..
// ani mavcrt.dll neni tak kde má být, počítač jsem projel Spyware terminátorem a nic to nenašlo, ted to projizdim Malwarebytem.
// Malware našel ten keygen.exe v koši a nebyl aktivní tak jsem jen vysypal koš, přes to prosím o kontrolu logu. (dám nový z RSIT)
Logfile of random's system information tool 1.07 (written by random/random)
Run by Claymore at 2010-07-07 14:28:14
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 7 GB (18%) free of 38 GB
Total RAM: 1023 MB (53% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:28:18, on 7.7.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Claymore\Plocha\RSIT.exe
C:\Program Files\trend micro\Claymore.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60347
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/homepage.aspx?tbid=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.2\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
--
End of file - 8844 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-06-25 1241552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-03-31 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-03-31 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-04-12 1018616]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-11-24 953800]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-06-25 1241552]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"=C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe [2004-06-03 131072]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-16 13529088]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-05-16 86016]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-02-06 2021400]
"SpywareTerminator"=C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe [2010-07-07 2176512]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"ICQ"=C:\Program Files\ICQ7.2\ICQ.exe [2010-06-11 133368]
"SpywareTerminatorUpdate"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-07-07 3037696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Claymore\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe /c []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2010-03-09 26100520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Claymore^Nabídka Start^Programy^Po spuštění^WinMySQLadmin.lnk]
C:\Documents and Settings\Claymore\Plocha\PaikProductions Blizzlike Repack\Server\mysql\bin\winmysqladmin.exe []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vds]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Documents and Settings\Claymore\Plocha\announce_trailer_en_us.exe"="C:\Documents and Settings\Claymore\Plocha\announce_trailer_en_us.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Metin2_CZ\metin2client.bin"="C:\Program Files\Metin2_CZ\metin2client.bin:*:Enabled:metin2client"
"C:\Program Files\ItalongjuMT2\ItalongjuMt2.exe"="C:\Program Files\ItalongjuMT2\ItalongjuMt2.exe:*:Enabled:ItalongjuMt2"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Gamesy\KnightShift\KnightShift.ex2"="C:\Gamesy\KnightShift\KnightShift.ex2:*:Enabled:KnightShift"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"
"C:\Program Files\Counter-Strike 1.6\hl.exe"="C:\Program Files\Counter-Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\HLSW\hlsw.exe"="C:\Program Files\HLSW\hlsw.exe:*:Enabled:HLSW Application"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Documents and Settings\Claymore\Plocha\Hell_Gaming_Server\TrinityCore.exe"="C:\Documents and Settings\Claymore\Plocha\Hell_Gaming_Server\TrinityCore.exe:*:Enabled:TrinityCore"
"C:\Documents and Settings\Claymore\Plocha\Server\Hell_Gaming_Server\TrinityCore.exe"="C:\Documents and Settings\Claymore\Plocha\Server\Hell_Gaming_Server\TrinityCore.exe:*:Enabled:TrinityCore"
"C:\Documents and Settings\Claymore\Plocha\Server\8269\TrinityCore.exe"="C:\Documents and Settings\Claymore\Plocha\Server\8269\TrinityCore.exe:*:Enabled:TrinityCore"
"C:\Documents and Settings\Claymore\Plocha\MaNGOS Repack Ver.6.33\Server\apache\bin\apache.exe"="C:\Documents and Settings\Claymore\Plocha\MaNGOS Repack Ver.6.33\Server\apache\bin\apache.exe:*:Enabled:Apache HTTP Server"
"C:\Documents and Settings\Claymore\Plocha\MaNGOS Repack Ver.6.33\Server\mysql\bin\mysqld.exe"="C:\Documents and Settings\Claymore\Plocha\MaNGOS Repack Ver.6.33\Server\mysql\bin\mysqld.exe:*:Enabled:mysqld"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"C:\Documents and Settings\Claymore\Plocha\Blacknight-mt2 client 1.2\lib\game\Game.exe"="C:\Documents and Settings\Claymore\Plocha\Blacknight-mt2 client 1.2\lib\game\Game.exe:*:Enabled:Game"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2010-07-07 14:01:53 ----D---- C:\Program Files\Crawler
2010-07-07 14:01:45 ----D---- C:\Documents and Settings\Claymore\Data aplikací\Spyware Terminator
2010-07-07 14:01:42 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2010-07-07 14:01:38 ----D---- C:\Program Files\Spyware Terminator
2010-07-07 13:39:18 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-07-07 13:35:17 ----D---- C:\rsit
2010-07-07 13:24:33 ----D---- C:\Documents and Settings\All Users\Data aplikací\PrevxCSI
2010-07-07 13:24:32 ----A---- C:\WINDOWS\wininit.ini
2010-07-07 07:50:44 ----SHD---- C:\found.000
2010-07-06 12:27:32 ----D---- C:\Program Files\Ventrilo
2010-07-06 12:27:17 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-07-06 12:12:51 ----A---- C:\WINDOWS\UPGRADE.TXT
2010-07-06 11:46:55 ----D---- C:\Program Files\VS Revo Group
2010-07-06 11:28:10 ----D---- C:\Program Files\Yamicsoft
2010-07-06 10:25:35 ----D---- C:\Program Files\Counter-Strike 1.6
2010-07-06 10:09:35 ----D---- C:\Program Files\Hamachi(3)
2010-07-06 02:39:07 ----D---- C:\Program Files\Hamachi(2)
2010-07-05 20:16:38 ----D---- C:\Documents and Settings\Claymore\Data aplikací\Malwarebytes
2010-07-05 20:15:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-07-01 08:47:19 ----D---- C:\Program Files\IObit
2010-06-27 03:01:26 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-06-27 03:01:07 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-06-26 18:33:26 ----D---- C:\Program Files\CCleaner
2010-06-25 13:55:38 ----D---- C:\WINDOWS\Prefetch
2010-06-25 13:40:26 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-06-25 13:40:09 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-06-25 13:39:47 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-06-25 13:39:30 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-06-25 13:39:18 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-06-25 13:39:06 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-06-25 13:38:55 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-06-25 13:38:43 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-06-25 13:38:28 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-06-25 13:38:15 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-06-25 13:37:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-06-25 13:37:44 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-06-25 13:37:31 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-06-25 13:37:12 ----HDC---- C:\WINDOWS\$NtUninstallKB977165-v2$
2010-06-25 13:36:56 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-06-25 13:36:43 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-06-25 13:36:31 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-06-25 13:36:18 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-06-25 13:36:02 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-06-25 13:35:46 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-06-25 13:35:29 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-06-25 13:35:12 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-06-25 13:34:54 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-06-25 13:34:37 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-06-25 13:34:19 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-06-25 13:34:00 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-06-25 13:33:43 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-06-25 13:33:24 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-06-25 13:33:07 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-06-25 13:32:54 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-06-25 13:32:41 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-06-25 13:32:31 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-06-25 13:32:19 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-06-25 13:31:57 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-06-25 13:31:43 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-06-25 13:31:27 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-06-25 13:31:13 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-06-25 13:31:00 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-06-25 13:30:35 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-06-25 13:30:24 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-06-25 13:29:16 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-06-25 13:29:05 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-06-25 13:28:45 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-06-25 13:28:35 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-06-25 13:28:27 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-06-25 13:28:24 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-06-25 13:28:15 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2010-06-25 13:28:14 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-06-25 13:28:06 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-06-25 13:28:02 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-06-25 13:27:56 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-06-25 13:27:52 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-06-25 13:27:47 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-06-25 13:27:42 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-06-25 13:27:33 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-06-25 13:27:21 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-06-25 13:27:20 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-06-25 13:27:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-06-25 13:26:45 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2010-06-25 13:26:32 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-06-25 13:26:22 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-06-25 13:26:04 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-06-25 13:25:51 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-06-25 13:12:51 ----D---- C:\WINDOWS\l2schemas
2010-06-25 13:12:50 ----D---- C:\WINDOWS\system32\cs
2010-06-25 13:12:50 ----D---- C:\WINDOWS\system32\bits
2010-06-25 10:29:27 ----D---- C:\Program Files\trend micro
2010-06-25 09:36:20 ----D---- C:\WINDOWS\pss
2010-06-23 13:35:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\McAfee
2010-06-20 13:04:07 ----A---- C:\WINDOWS\system32\wshirda.dll
2010-06-20 13:04:07 ----A---- C:\WINDOWS\system32\irmon.dll
2010-06-20 13:04:07 ----A---- C:\WINDOWS\system32\irftp.exe
2010-06-12 11:36:57 ----D---- C:\Documents and Settings\Claymore\Data aplikací\Apple Computer
2010-06-11 21:21:33 ----A---- C:\WINDOWS\system32\unrar.dll
2010-06-11 21:21:25 ----D---- C:\Program Files\K-Lite Codec Pack
2010-06-11 20:24:16 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-06-11 20:22:58 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2010-06-11 19:12:30 ----D---- C:\Program Files\ICQ7.2
2010-06-11 06:36:13 ----HDC---- C:\WINDOWS\$NtUninstallKB980218_0$
2010-06-11 06:35:08 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-06-11 06:34:33 ----HDC---- C:\WINDOWS\$NtUninstallKB979559_0$
2010-06-11 06:23:33 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-11 06:23:03 ----HDC---- C:\WINDOWS\$NtUninstallKB979482_0$
2010-06-11 06:22:38 ----HDC---- C:\WINDOWS\$NtUninstallKB975562_0$
2010-06-10 16:27:21 ----D---- C:\Documents and Settings\Claymore\Data aplikací\Facebook
======List of files/folders modified in the last 1 months======
2010-07-07 14:27:09 ----D---- C:\WINDOWS\Temp
2010-07-07 14:22:54 ----D---- C:\WINDOWS\system32
2010-07-07 14:22:28 ----D---- C:\WINDOWS\system32\drivers
2010-07-07 14:01:53 ----RD---- C:\Program Files
2010-07-07 13:48:21 ----D---- C:\Documents and Settings\Claymore\Data aplikací\Skype
2010-07-07 13:24:32 ----D---- C:\WINDOWS
2010-07-07 12:48:45 ----D---- C:\Documents and Settings\Claymore\Data aplikací\skypePM
2010-07-07 08:31:22 ----D---- C:\Documents and Settings\Claymore\Data aplikací\ICQ
2010-07-07 07:11:48 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-07-06 12:27:35 ----SHD---- C:\WINDOWS\Installer
2010-07-06 12:27:17 ----D---- C:\Program Files\Common Files
2010-07-06 12:20:03 ----D---- C:\WINDOWS\SxsCaPendDel
2010-07-06 12:17:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-07-06 12:01:55 ----D---- C:\WINDOWS\system32\CatRoot
2010-07-06 12:01:53 ----D---- C:\WINDOWS\system32\CatRoot2
2010-07-06 11:52:50 ----D---- C:\Program Files\Common Files\Adobe
2010-07-06 11:52:50 ----D---- C:\Documents and Settings\Claymore\Data aplikací\Adobe
2010-07-06 11:49:54 ----D---- C:\Documents and Settings\Claymore\Data aplikací\Hamachi
2010-07-06 11:28:19 ----SD---- C:\Documents and Settings\Claymore\Data aplikací\Microsoft
2010-07-06 10:46:11 ----SD---- C:\WINDOWS\Tasks
2010-07-06 10:27:17 ----D---- C:\WINDOWS\system32\config
2010-07-06 10:26:50 ----D---- C:\WINDOWS\system32\wbem
2010-07-06 10:26:46 ----D---- C:\WINDOWS\Registration
2010-07-06 10:26:18 ----D---- C:\Gamesy
2010-07-06 10:25:11 ----D---- C:\Program Files\Mozilla Firefox
2010-07-06 10:25:05 ----HD---- C:\WINDOWS\inf
2010-06-29 09:36:58 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-06-27 03:04:14 ----D---- C:\WINDOWS\Debug
2010-06-27 03:00:55 ----HD---- C:\WINDOWS\$hf_mig$
2010-06-26 18:42:20 ----D---- C:\WINDOWS\Microsoft.NET
2010-06-26 18:42:16 ----RSD---- C:\WINDOWS\assembly
2010-06-25 14:02:20 ----SH---- C:\boot.ini
2010-06-25 14:02:20 ----A---- C:\WINDOWS\win.ini
2010-06-25 14:02:20 ----A---- C:\WINDOWS\system.ini
2010-06-25 13:55:01 ----D---- C:\WINDOWS\system32\Setup
2010-06-25 13:55:01 ----D---- C:\WINDOWS\AppPatch
2010-06-25 13:54:59 ----RSD---- C:\WINDOWS\Fonts
2010-06-25 13:38:34 ----D---- C:\Program Files\Outlook Express
2010-06-25 13:36:33 ----D---- C:\Program Files\Movie Maker
2010-06-25 13:26:06 ----D---- C:\Program Files\Messenger
2010-06-25 13:17:53 ----D---- C:\WINDOWS\security
2010-06-25 13:14:03 ----D---- C:\WINDOWS\WinSxS
2010-06-25 13:13:43 ----D---- C:\WINDOWS\ehome
2010-06-25 13:13:37 ----D---- C:\WINDOWS\system32\inetsrv
2010-06-25 13:13:37 ----D---- C:\WINDOWS\network diagnostic
2010-06-25 13:13:37 ----D---- C:\WINDOWS\Help
2010-06-25 13:13:36 ----D---- C:\WINDOWS\ime
2010-06-25 13:12:54 ----D---- C:\WINDOWS\system32\usmt
2010-06-25 13:12:54 ----D---- C:\WINDOWS\system32\cs-CZ
2010-06-25 13:12:52 ----D---- C:\Program Files\Internet Explorer
2010-06-25 13:12:50 ----D---- C:\WINDOWS\PeerNet
2010-06-25 12:57:43 ----D---- C:\WINDOWS\system32\Restore
2010-06-25 12:57:42 ----D---- C:\WINDOWS\system32\npp
2010-06-25 12:57:37 ----D---- C:\WINDOWS\msagent
2010-06-25 12:57:27 ----D---- C:\WINDOWS\srchasst
2010-06-25 12:57:23 ----D---- C:\Program Files\NetMeeting
2010-06-25 12:57:14 ----D---- C:\WINDOWS\system32\Com
2010-06-25 12:57:04 ----D---- C:\Program Files\Windows Media Player
2010-06-25 12:57:02 ----D---- C:\Program Files\Windows NT
2010-06-25 12:56:46 ----D---- C:\Program Files\Common Files\System
2010-06-25 12:55:10 ----D---- C:\WINDOWS\system32\oobe
2010-06-25 12:55:07 ----D---- C:\WINDOWS\system
2010-06-25 12:32:03 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-06-25 12:31:38 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-06-22 08:28:25 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-06-20 12:40:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-06-12 06:53:43 ----D---- C:\Program Files\ICQ6Toolbar
2010-06-11 20:23:14 ----D---- C:\Program Files\Windows Media Connect 2
2010-06-11 19:15:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\ICQ
2010-06-11 19:13:24 ----HD---- C:\Program Files\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2009-02-06 93336]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-02-06 113448]
R3 BthEnum;Služba Bluetooth Enumerator; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-05-15 25280]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-11-18 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-16 6557408]
R3 nvax;Service for NVIDIA(R) nForce(TM) Audio Enumerator; C:\WINDOWS\system32\drivers\nvax.sys [2004-05-25 48640]
R3 NVENET;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENET.sys [2004-01-29 93764]
R3 nvnforce;Service for NVIDIA(R) nForce(TM) Audio; C:\WINDOWS\system32\drivers\nvapu.sys [2004-05-25 396032]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
S3 a8tvreq5;a8tvreq5; C:\WINDOWS\system32\drivers\a8tvreq5.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 EraserUtilDrvI9;EraserUtilDrvI9; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys []
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-02-06 727720]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-04-12 246520]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-03-31 153376]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-16 159812]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-07-07 488960]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-02-06 20680]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-03-27 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------