Stránka 1 z 1

Prosím o kontrolu logu z RSIT

Napsal: 07 zář 2010 12:43
od kazi21
Dobrý den prosím o kontrolu logu.Dost často stahují, tak bych potřeboval kontrolu.Předem díky

Zde je log z RSIT:

Logfile of random's system information tool 1.08 (written by random/random)
Run by vista at 2010-09-07 14:00:48
Microsoft® Windows Vista™ Ultimate Service Pack 2
System drive C: has 176 GB (38%) free of 466 GB
Total RAM: 3070 MB (56% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:00:52, on 7.9.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Windows\SysWOW64\asam\rundll32.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Program Files\trend micro\vista.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {83821C2B-32A8-4DD7-B6D4-44309A78E668} - C:\Program Files (x86)\Mail.Ru\Agent\Mra\dll\newmrasearch.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [MAgent] "C:\Program Files (x86)\Mail.Ru\Agent\MAgent.exe" -LM
O4 - HKLM\..\Run: [NBAgent] "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] "C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe"
O4 - HKLM\..\Run: [SwitchBoard] "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [RGSC] C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [NokiaOviSuite2] C:\Program Files (x86)\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: Download all by Rapidown... - C:\Program Files (x86)\Rapidown\rapidownGetAll.htm
O8 - Extra context menu item: Download by Rapidown... - C:\Program Files (x86)\Rapidown\rapidownGet.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Mail.Ru ????? - {7558B7E5-7B26-4201-BEDB-00D5FF534523} - C:\Program Files (x86)\Mail.Ru\Agent\magent.exe
O9 - Extra 'Tools' menuitem: Mail.Ru ????? - {7558B7E5-7B26-4201-BEDB-00D5FF534523} - C:\Program Files (x86)\Mail.Ru\Agent\magent.exe
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6.5\ICQ.exe
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://webcam.aicomp.de/kxhcm10.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/f ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: asam (ActivityMon2) - Roman Svihalek, Advanced Software - C:\Windows\SysWOW64\asam\svchost.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11187 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {22E0947D-5F0C-4EDB-8BAC-C88497F23EAE}
taskeng.exe {C683C497-7A19-4E70-8DD4-8B3C51C01C0D}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Windows Defender\MSASCui.exe" -hide
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Windows\ehome\ehtray.exe"
"C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe"
C:\Windows\ehome\ehmsas.exe -Embedding
"C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer.exe" /watchfiles startup
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
C:\Windows\SysWOW64\asam\svchost.exe /servicestart
C:\Windows\system32\svchost.exe -k bthsvcs
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
C:\Windows\SysWOW64\asam\rundll32.exe
"C:\Program Files (x86)\Microsoft LifeCam\MSCamS64.exe"
"C:\Windows\SysWOW64\asam\rundll64.exe" 0001025C
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe"
"C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\UI0Detect.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-758fcbb8-625c-40cb-bab8-571812c6cf58 -SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-891159e0-1515-4ea0-a368-f5f269c454f9 -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-577b2100-f1dc-4fc7-b0c7-4bc1030a3748 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:4ad469de-941f-4f3e-8955-45a676de64ab
"C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe"
{7007A28A-1430-4448-923F-E24DB9BA9668}
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
{C2C436F5-104C-45E5-9D08-3C4851047EC6}
{AE819506-FC84-4710-A263-BF017F20A500}
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\vista\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore1cb0d6187da8935.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\NeroLiveEpgUpdate-vista-PC_vista.job
C:\Windows\tasks\User_Feed_Synchronization-{46834853-4A93-4B6F-8290-4000792C283D}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg64.dll [2010-01-31 319984]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2010-02-22 798771]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-01-31 812528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-01-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2010-02-22 798771]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1584184]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-06-26 16327712]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2716216]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1555968]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 138240]
"SpywareTerminatorUpdate"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-04-14 3037696]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2010-04-06 26102056]
"RGSC"=C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe [2009-12-15 306088]
"uTorrent"=C:\Program Files (x86)\uTorrent\uTorrent.exe [2010-05-17 322352]
"AlcoholAutomount"=C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2009-11-15 33120]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
""= []
"NokiaOviSuite2"=C:\Program Files (x86)\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe [2010-09-02 672632]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"MAgent"=C:\Program Files (x86)\Mail.Ru\Agent\MAgent.exe [2010-05-27 9422016]
"NBAgent"=C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [2010-03-26 1234216]
"LifeCam"=C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [2007-05-17 279912]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"ArcSoft Connection Service"=C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-03-18 207360]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]
"NokiaMServer"=C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"EnableLinkedConnections"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-09-07 13:44:46 ----D---- C:\rsit
2010-09-07 13:44:46 ----D---- C:\Program Files\trend micro
2010-09-06 19:52:47 ----A---- C:\Windows\system32\drivers\pccsmcfdx64.sys
2010-09-06 19:51:45 ----D---- C:\Program Files (x86)\PC Connectivity Solution
2010-09-06 19:45:15 ----D---- C:\ProgramData\NokiaInstallerCache
2010-09-04 22:01:58 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2010-09-04 21:04:07 ----D---- C:\Program Files\2K Games
2010-09-04 20:56:15 ----D---- C:\Program Files (x86)\DAEMON Tools Toolbar
2010-09-04 20:56:01 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2010-09-04 20:54:44 ----D---- C:\Users\vista\AppData\Roaming\DAEMON Tools Lite
2010-09-04 20:53:52 ----D---- C:\ProgramData\DAEMON Tools Lite
2010-09-04 20:43:29 ----A---- C:\Windows\SYSWOW64\BASSMOD.dll
2010-09-03 11:54:53 ----D---- C:\ProgramData\Motive
2010-08-17 15:11:58 ----D---- C:\Windows\SYSWOW64\Res
2010-08-17 15:11:56 ----D---- C:\Windows\SYSWOW64\Maps
2010-08-17 15:11:53 ----D---- C:\Windows\SYSWOW64\Drive
2010-08-11 09:16:15 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-08-11 09:15:48 ----A---- C:\Windows\system32\mshtml.dll
2010-08-11 09:15:47 ----A---- C:\Windows\system32\ieframe.dll
2010-08-11 09:15:46 ----A---- C:\Windows\system32\iertutil.dll
2010-08-11 09:15:45 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2010-08-11 09:15:44 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2010-08-11 09:15:40 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2010-08-11 09:15:39 ----A---- C:\Windows\system32\urlmon.dll
2010-08-11 09:15:38 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2010-08-11 09:15:38 ----A---- C:\Windows\system32\wininet.dll
2010-08-11 09:15:37 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2010-08-11 09:15:37 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2010-08-11 09:15:37 ----A---- C:\Windows\system32\occache.dll
2010-08-11 09:15:37 ----A---- C:\Windows\system32\msfeeds.dll
2010-08-11 09:15:37 ----A---- C:\Windows\system32\iepeers.dll
2010-08-11 09:15:37 ----A---- C:\Windows\system32\iedkcs32.dll
2010-08-11 09:15:36 ----A---- C:\Windows\SYSWOW64\wininet.dll
2010-08-11 09:15:36 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2010-08-11 09:15:36 ----A---- C:\Windows\system32\mstime.dll
2010-08-11 09:15:36 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-08-11 09:15:36 ----A---- C:\Windows\system32\jsproxy.dll
2010-08-11 09:15:36 ----A---- C:\Windows\system32\ieui.dll
2010-08-11 09:15:36 ----A---- C:\Windows\system32\iernonce.dll
2010-08-11 09:15:35 ----A---- C:\Windows\SYSWOW64\occache.dll
2010-08-11 09:15:35 ----A---- C:\Windows\SYSWOW64\mstime.dll
2010-08-11 09:15:35 ----A---- C:\Windows\SYSWOW64\ieui.dll
2010-08-11 09:15:35 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2010-08-11 09:15:35 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2010-08-11 09:15:35 ----A---- C:\Windows\system32\ieUnatt.exe
2010-08-11 09:15:35 ----A---- C:\Windows\system32\iesysprep.dll
2010-08-11 09:15:35 ----A---- C:\Windows\system32\iesetup.dll
2010-08-11 09:15:34 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2010-08-11 09:15:34 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2010-08-11 09:15:34 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2010-08-11 09:15:34 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2010-08-11 09:15:34 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2010-08-11 09:15:34 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2010-08-11 09:15:34 ----A---- C:\Windows\system32\msfeedssync.exe
2010-08-11 09:15:34 ----A---- C:\Windows\system32\ie4uinit.exe
2010-08-11 09:15:32 ----A---- C:\Windows\SYSWOW64\iccvid.dll
2010-08-11 09:15:30 ----A---- C:\Windows\SYSWOW64\schannel.dll
2010-08-11 09:15:30 ----A---- C:\Windows\system32\schannel.dll
2010-08-11 09:15:26 ----A---- C:\Windows\system32\msxml3.dll
2010-08-11 09:15:25 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2010-08-11 09:15:20 ----A---- C:\Windows\system32\win32k.sys
2010-08-11 09:15:18 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-08-11 09:15:16 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-08-11 09:15:16 ----A---- C:\Windows\system32\drivers\srv.sys
2010-08-11 09:15:14 ----A---- C:\Windows\system32\rtutils.dll
2010-08-11 09:15:13 ----A---- C:\Windows\SYSWOW64\rtutils.dll
2010-08-09 21:21:47 ----D---- C:\Users\vista\AppData\Roaming\NeroDigital(TM)

======List of files/folders modified in the last 1 months======

2010-09-07 14:00:50 ----D---- C:\Windows\Temp
2010-09-07 13:59:39 ----D---- C:\ProgramData\Spyware Terminator
2010-09-07 13:59:17 ----D---- C:\Windows\Tasks
2010-09-07 13:58:47 ----D---- C:\Users\vista\AppData\Roaming\Skype
2010-09-07 13:58:44 ----D---- C:\Users\vista\AppData\Roaming\uTorrent
2010-09-07 13:44:46 ----RD---- C:\Program Files
2010-09-07 13:33:08 ----SHD---- C:\System Volume Information
2010-09-07 11:56:37 ----D---- C:\ProgramData\Google Updater
2010-09-07 11:53:29 ----D---- C:\Users\vista\AppData\Roaming\skypePM
2010-09-06 20:11:41 ----D---- C:\Windows\system32\drivers
2010-09-06 20:09:24 ----D---- C:\Windows\System32
2010-09-06 20:09:24 ----D---- C:\Windows
2010-09-06 20:01:52 ----D---- C:\Windows\system32\catroot
2010-09-06 20:00:34 ----D---- C:\ProgramData\OviInstallerCache
2010-09-06 20:00:28 ----SHD---- C:\Windows\Installer
2010-09-06 19:52:47 ----DC---- C:\Windows\system32\DRVSTORE
2010-09-06 19:52:46 ----D---- C:\Windows\inf
2010-09-06 19:51:45 ----D---- C:\Windows\Prefetch
2010-09-06 19:51:45 ----D---- C:\Program Files (x86)
2010-09-06 19:51:24 ----D---- C:\Windows\system32\drivers\UMDF
2010-09-06 19:50:57 ----D---- C:\Windows\system32\catroot2
2010-09-06 19:46:46 ----D---- C:\Program Files (x86)\Nokia
2010-09-06 19:45:15 ----HD---- C:\ProgramData
2010-09-06 18:15:16 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-09-04 22:01:53 ----D---- C:\Windows\SysWOW64
2010-09-04 21:21:58 ----D---- C:\Windows\system32\Tasks
2010-09-04 20:57:07 ----D---- C:\Users\vista\AppData\Roaming\DAEMON Tools
2010-09-04 12:21:47 ----D---- C:\Users\vista\AppData\Roaming\Spyware Terminator
2010-08-31 20:23:46 ----D---- C:\Program Files (x86)\ICQ6.5
2010-08-31 19:00:02 ----D---- C:\Users\vista\AppData\Roaming\ArcSoft
2010-08-28 11:05:35 ----D---- C:\Program Files (x86)\Adobe
2010-08-28 10:58:31 ----D---- C:\Program Files (x86)\Spyware Terminator
2010-08-28 10:56:54 ----D---- C:\Windows\Debug
2010-08-28 10:06:14 ----D---- C:\Program Files\Adobe
2010-08-25 13:52:29 ----RSD---- C:\Windows\Fonts
2010-08-11 21:45:55 ----D---- C:\Windows\Microsoft.NET
2010-08-11 21:45:20 ----RSD---- C:\Windows\assembly
2010-08-11 09:47:47 ----D---- C:\Windows\winsxs
2010-08-11 09:31:15 ----D---- C:\Program Files\Internet Explorer
2010-08-11 09:31:15 ----D---- C:\Program Files (x86)\Internet Explorer
2010-08-11 09:31:13 ----D---- C:\Program Files\Windows Mail
2010-08-11 09:31:13 ----D---- C:\Program Files\Movie Maker
2010-08-11 09:31:13 ----D---- C:\Program Files (x86)\Windows Mail
2010-08-11 09:31:11 ----D---- C:\Windows\SYSWOW64\migration
2010-08-11 09:31:08 ----D---- C:\Windows\system32\migration

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 fvevol;BitLocker Drive Encryption Filter Driver; C:\Windows\System32\DRIVERS\fvevol.sys [2009-04-11 160744]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-06-02 834544]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 136584]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 145336]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-12-18 123200]
R3 Afc;PPdus ASPI Shell; C:\Windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 26112]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-19 115712]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-11 34816]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-02-11 1708192]
R3 NuidFltr;NUID filter driver; C:\Windows\system32\DRIVERS\NuidFltr.sys [2009-05-09 15752]
R3 NVENETFD;NVIDIA nForce 10/100 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmfdx64.sys [2008-08-01 1498016]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-06-26 11515808]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 178176]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2008-01-19 11264]
R3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 98944]
R3 VX1000;VX-1000; C:\Windows\system32\DRIVERS\VX1000.sys [2010-03-12 2060144]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 108544]
S0 BTHidEnum;Bluetooth HID Enumerator; C:\Windows\System32\Drivers\vbtenum.sys []
S0 BTHidMgr;Bluetooth HID Manager Service; C:\Windows\System32\Drivers\BTHidMgr.sys []
S3 an8q8321;an8q8321; C:\Windows\system32\drivers\an8q8321.sys []
S3 arkcc8rs;arkcc8rs; C:\Windows\system32\drivers\arkcc8rs.sys []
S3 BlueletAudio;Bluetooth Audio Service; C:\Windows\system32\DRIVERS\blueletaudio.sys []
S3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\Windows\system32\DRIVERS\BlueletSCOAudio.sys []
S3 BT;Bluetooth PAN Network Adapter; C:\Windows\system32\DRIVERS\btnetdrv.sys []
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\Windows\System32\Drivers\btcusb.sys []
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-04-11 694272]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 6144]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-05-01 33344]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 275456]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 11008]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 7040]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 6656]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 7936]
S3 nmwcdcx64;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbox64.sys [2010-02-26 25088]
S3 nmwcdx64;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmbx64.sys [2010-02-26 19456]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 s816bus;Sony Ericsson Device 816 driver (WDM); C:\Windows\system32\DRIVERS\s816bus.sys [2007-06-19 107048]
S3 s816mdfl;Sony Ericsson Device 816 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s816mdfl.sys [2007-06-19 18472]
S3 s816mdm;Sony Ericsson Device 816 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s816mdm.sys [2007-06-19 143400]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2010-02-26 9216]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 41984]
S3 usbser;USB Modem Driver; C:\Windows\system32\DRIVERS\usbser.sys [2009-04-11 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys [2010-02-26 9216]
S3 VComm;Virtual Serial port driver; C:\Windows\system32\DRIVERS\VComm.sys []
S3 VcommMgr;Bluetooth VComm Manager Service; C:\Windows\System32\Drivers\VcommMgr.sys []
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 46592]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 ActivityMon2;asam; C:\Windows\SysWOW64\asam\svchost.exe [2010-05-31 187392]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-19 27648]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2009-06-17 73728]
R2 MSCamSvc;MSCamSvc; C:\Program Files (x86)\Microsoft LifeCam\MSCamS64.exe [2007-05-17 443752]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-03-25 490280]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-06-26 382496]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2009-08-06 75064]
R2 PnkBstrB;PnkBstrB; C:\Windows\syswow64\PnkBstrB.exe [2010-05-12 103736]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe [2010-04-14 488960]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2010-06-14 615936]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-01-31 135664]
S2 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 183280]
S2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe []
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 23296]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 27648]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2008-01-19 19968]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]

-----------------EOF-----------------

Re: Prosím o kontrolu logu z RSIT

Napsal: 07 zář 2010 20:59
od Roli
Zdravím, tyhle zbytečnosti fixni v HJT :

O4 - HKLM\..\Run: [NBAgent] "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKCU\..\Run: [NokiaOviSuite2] C:\Program Files (x86)\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray


HJT najdeš zde :

C:\Program Files\trend micro\vista.exe

Fix znamená že spustíš HJT Obrázek jako admin

v okně které se ti otevře klikneš na Do a system scan only

v dalším okně najdeš řádky které jsem ti vypsal,

vedle nich je čtvereček do kterého uděláš zatržítko,

pak klikneš na Fix checked které je vlevo dole,

program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.


Přes Start >> Všechny programy >> Příslušenství >> Spustit >> napiš - services.msc >> Enter. Najdi službu :

Služba Google Update

Google Software Updater

Nero BackItUp Scheduler 4.0


klikni na ni pravým myšítkem, zvol vlastnosti, na další kartě nejprve službu zastav tlačítkem Zastavit a u položky Typ spouštění zvol Zakázáno.


Smaž nepotřebné soubory

pomocí CCleaneru

návod :

Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš

Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)

Čištění registru je třeba několikrát zopakovat !


Nakonec použij Mbam z mého podpisu a dej mi sem z něj log dříve než něco smažeš.

Re: Prosím o kontrolu logu z RSIT

Napsal: 08 zář 2010 08:47
od kazi21
Dobré dopoledne
Vše provedeno jak jsi řekl
Zde je log z MBAM:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verze databáze: 4162

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18943

8.9.2010 9:31:09
mbam-log-2010-09-08 (09-31-09).txt

Typ skenu: Úplný sken (C:\|D:\|)
Skenované objekty: 332601
Uplynulý čas: 1 hodina(y), 49 minuta(y), 13 sekunda(y)

Infikované procesy v paměti: 1
Infikované moduly v paměti: 0
Infikované klíče registru: 1
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 3

Infikované procesy v paměti:
C:\Windows\SysWOW64\asam\svchost.exe (Trojan.Dropper) -> No action taken.

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> No action taken.

Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
C:\Windows\SysWOW64\asam\svchost.exe (Trojan.Dropper) -> No action taken.
C:\Users\vista\Documents\Adobe Photoshop CS5 Extended Windows LS6 (CZ_HU_PL_RO_RU_TR_UA)\Adobe.Photoshop.CS5.Extended.v12.0.ONLY.Keymaker-EMBRACE\Adobe.Photoshop.CS5.Extended.v12.0.ONLY.Keymaker-EMBRACE\keygen.exe (Malware.Packer.Gen) -> No action taken.
C:\Windows\System32\asam\svchost.exe (Trojan.Dropper) -> No action taken.

Re: Prosím o kontrolu logu z RSIT

Napsal: 08 zář 2010 21:10
od Roli
Než něco smažeme tak se zeptám, nejedná se náhodou o firemní PC ?

Já jen že tam máš softík pro sledování aktivit.

Re: Prosím o kontrolu logu z RSIT

Napsal: 10 zář 2010 09:14
od kazi21
Dobré dop. Ne nejedná se o firemní PC,Jestli myslis ActivityMon, tak ten jsem měl stahnutý jako trial verzi.Už jsem ji odstranil a řikaš nedostatečně dobře ?Pomužeš pro uplné odstranění.Odinstaloval jsem ho, ale ne dostatečně.

Re: Prosím o kontrolu logu z RSIT

Napsal: 10 zář 2010 21:55
od Roli
Dobře tedy odstraníme všechen nepořádek.

Tak že to co Mbam našel nech smazat.


Přes Start >> Všechny programy >> Příslušenství >> Spustit >> napiš - services.msc >> Enter. Najdi službu :

ActivityMon2

klikni na ni pravým myšítkem, zvol vlastnosti, na další kartě nejprve službu zastav tlačítkem Zastavit a u položky Typ spouštění zvol Zakázáno.


Stáhni OTMoveIt a pravým myšítkem spusť jako admin,

do levého okna aplikace pod Paste Instructions for Items to be Moved zkopíruj tento text:

Kód: Vybrat vše

:processes
explorer.exe       

:files 
C:\*.tmp
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\Windows\SysWOW64\asam

:services
ActivityMon2

:commands
[purity]
[emptytemp]
[start explorer]
klikni na MoveIt! a v pravém zeleném okně aplikace se Ti objeví info o provedene akci, obsah okna zkopíruj sem,

pokud aplikace bude požadovat restart, klikni na YES

v tom případě sem chci zkopírovat obsah logu uloženého na C:\_OTMoveIt\MovedFiles\

Re: Prosím o kontrolu logu z RSIT

Napsal: 11 zář 2010 11:46
od kazi21
Zde je log:

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
File/Folder C:\*.tmp not found.
File/Folder C:\WINDOWS\System32\*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
C:\Windows\SysWOW64\asam\Styles folder moved successfully.
C:\Windows\SysWOW64\asam\Setup folder moved successfully.
C:\Windows\SysWOW64\asam\Microsoft.VC90.MFC folder moved successfully.
C:\Windows\SysWOW64\asam\Microsoft.VC90.CRT folder moved successfully.
C:\Windows\SysWOW64\asam\English folder moved successfully.
C:\Windows\SysWOW64\asam\DataFiles\Screenshots folder moved successfully.
C:\Windows\SysWOW64\asam\DataFiles\Logs folder moved successfully.
C:\Windows\SysWOW64\asam\DataFiles folder moved successfully.
C:\Windows\SysWOW64\asam\Czech folder moved successfully.
C:\Windows\SysWOW64\asam folder moved successfully.
========== SERVICES/DRIVERS ==========
Service ActivityMon2 stopped successfully!
Service ActivityMon2 deleted successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: AppData

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: vista
->Temp folder emptied: 6299768 bytes
->Temporary Internet Files folder emptied: 18777746 bytes
->Java cache emptied: 3586091 bytes
->FireFox cache emptied: 23776508 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 1199 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 44592456 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 1190639 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 94,00 mb


OTM by OldTimer - Version 3.1.15.0 log created on 09112010_123753

Files moved on Reboot...
C:\Users\vista\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\vista\AppData\Local\Temp\~DF41C5.tmp moved successfully.
C:\Users\vista\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\KX2EC4F7\readMessageScreen[1].htm moved successfully.
C:\Users\vista\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FIE4WANR\afr[1].htm moved successfully.
C:\Users\vista\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FIE4WANR\framesetScreen[1].htm moved successfully.
C:\Users\vista\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FGPISFX5\emptyScreen[1].htm moved successfully.

Registry entries deleted on Reboot...

Re: Prosím o kontrolu logu z RSIT

Napsal: 11 zář 2010 19:35
od Roli
Nepořádek je pryč, jak je na tom PC ?

Re: Prosím o kontrolu logu z RSIT

Napsal: 12 zář 2010 19:02
od kazi21
Dobrý večer.Vše okej, počitač se urychlil pri startu aji v provozu.Diky moc za Vaš čas. :)

Re: Prosím o kontrolu logu z RSIT

Napsal: 12 zář 2010 20:46
od Roli
Není zač.