Stránka 1 z 1

Win XP - seka aj po reinstalacii a naformatovani disku

Napsal: 09 zář 2010 11:45
od DanielDevil
Zdravím, kamoška má tento problém, ja osobne som v kontakte s PC nebol, len popisujem čo mi povedala...

Takže vraj jej PC seká, buď hneď po zapnutí alebo už pri načítavaný Windowsu, PC začne pukať a sekať, červené svetielko (asi indikujúce zaťaženie procesora) svieti stále načerveno, pár sekúnd PC ide, potom zas nejde, nepomáha ani reštart, keď jej to začalo robiť preinštalovala win a naformátovala aj disk C, no nepomohlo, skúsila ešte raz a stále nič, pripájam logy

Log z RSIT
Logfile of random's system information tool 1.08 (written by random/random)
Run by Lucinka at 2010-09-08 11:41:45
Systém Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 37 GB (82%) free of 45 GB
Total RAM: 2047 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:41:52, on 8.9.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Lucinka\Application Data\QipGuard\QipGuard.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Lucinka\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lucinka\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lucinka\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lucinka\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lucinka\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lucinka\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\ICQ6.5\ICQ.exe
C:\Documents and Settings\Lucinka\Desktop\RSIT.exe
C:\Program Files\trend micro\Lucinka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://picasa.google.com/support/bin/an ... swer=93773
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Lucinka\Application Data\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QipLI - {6B5863A0-C43F-4C0A-982B-CC0E9125783F} - C:\Documents and Settings\Lucinka\Application Data\Microsoft\Internet Explorer\qstatsrv.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Lucinka\Application Data\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: PandoraTV Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Infium] "C:\Program Files\QIP 2010\qip.exe" /autorun
O4 - HKCU\..\Run: [QIP Internet Guardian] C:\Documents and Settings\Lucinka\Application Data\QipGuard\QipGuard.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Lucinka\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe

--
End of file - 8046 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1972579041-725345543-1004Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1972579041-725345543-1004UA.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-12 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B5863A0-C43F-4C0A-982B-CC0E9125783F}]
QipLI Class - C:\Documents and Settings\Lucinka\Application Data\Microsoft\Internet Explorer\qstatsrv.dll [2010-06-10 48080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Documents and Settings\Lucinka\Application Data\Microsoft\Internet Explorer\qipsearchbar.dll [2010-06-10 149968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
PandoraTV Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-07-11 1174920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-09-08 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-09-08 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - PandoraTV Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-07-11 1174920]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2009-08-16 962808]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-04-12 8429568]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-04-12 81920]
"GamerOSD"=C:\Program Files\ASUS\GamerOSD\GamerOSD.exe [2007-02-14 380928]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-01-30 16116224]
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2007-12-21 1443072]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2008-08-04 36352]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2005-01-12 32768]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2008-06-19 570664]
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2006-02-28 15360]
"Infium"=C:\Program Files\QIP 2010\qip.exe [2010-06-10 5714384]
"QIP Internet Guardian"=C:\Documents and Settings\Lucinka\Application Data\QipGuard\QipGuard.exe [2010-06-10 190416]
"Google Update"=C:\Documents and Settings\Lucinka\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-08 133104]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-06-25 1840424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-19 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2010-09-09 07:11:52 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-09-09 02:29:49 ----N---- C:\WINDOWS\system32\nvuide.exe
2010-09-09 02:29:48 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-09-09 02:29:31 ----A---- C:\WINDOWS\system32\nvunrm.exe
2010-09-09 02:29:22 ----D---- C:\Documents and Settings\Lucinka\Application Data\InstallShield
2010-09-09 02:28:39 ----A---- C:\WINDOWS\gdrv.sys
2010-09-09 02:27:36 ----A---- C:\WINDOWS\system32\drivers\EIO.sys
2010-09-09 02:26:33 ----D---- C:\Program Files\My Company Name
2010-09-09 02:26:26 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2010-09-09 02:26:26 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2010-09-09 02:26:26 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2010-09-09 02:26:26 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2010-09-09 02:26:25 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2010-09-09 02:26:25 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2010-09-09 02:26:25 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2010-09-09 02:26:25 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2010-09-09 02:26:25 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2010-09-09 02:26:25 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2010-09-09 02:26:25 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2010-09-09 02:26:24 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2010-09-09 02:26:24 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2010-09-09 02:26:24 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2010-09-09 02:26:24 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2010-09-09 02:26:05 ----A---- C:\WINDOWS\system32\drivers\asusgsb32.sys
2010-09-09 02:26:03 ----D---- C:\Program Files\ASUS
2010-09-09 02:26:03 ----A---- C:\WINDOWS\system32\drivers\Video3D32.sys
2010-09-09 02:26:03 ----A---- C:\WINDOWS\system32\drivers\Bravo.sys
2010-09-09 02:26:03 ----A---- C:\WINDOWS\system32\drivers\atkkbnt.sys
2010-09-09 02:26:03 ----A---- C:\WINDOWS\system32\ATKOSDMini.DLL
2010-09-09 02:26:03 ----A---- C:\WINDOWS\system32\atkid.ini
2010-09-09 02:26:03 ----A---- C:\WINDOWS\R5ClkLib.dll
2010-09-09 02:26:03 ----A---- C:\WINDOWS\OneTouchVga.dll
2010-09-09 02:26:03 ----A---- C:\WINDOWS\nvgpio.dll
2010-09-09 02:26:03 ----A---- C:\WINDOWS\nvapi9x.dll
2010-09-09 02:26:03 ----A---- C:\WINDOWS\HyperDrive.exe
2010-09-09 02:26:03 ----A---- C:\WINDOWS\EIO64.sys
2010-09-09 02:26:03 ----A---- C:\WINDOWS\EIO.sys
2010-09-09 02:26:03 ----A---- C:\WINDOWS\EIO.dll
2010-09-09 02:26:03 ----A---- C:\WINDOWS\ATKKBService.exe
2010-09-09 02:26:03 ----A---- C:\WINDOWS\atistclk.dll
2010-09-09 02:26:03 ----A---- C:\WINDOWS\atipdlxx.dll
2010-09-09 02:26:03 ----A---- C:\WINDOWS\atillk64.sys
2010-09-09 02:26:03 ----A---- C:\WINDOWS\atikia64.sys
2010-09-09 02:26:03 ----A---- C:\WINDOWS\atidgllk.sys
2010-09-09 02:26:03 ----A---- C:\WINDOWS\aticlocklib.dll
2010-09-09 02:26:03 ----A---- C:\WINDOWS\ASUSRC.dll
2010-09-09 02:26:02 ----A---- C:\WINDOWS\system32\ATKOSDX32.dll
2010-09-09 02:26:02 ----A---- C:\WINDOWS\system32\ATKOGL32.dll
2010-09-09 02:26:02 ----A---- C:\WINDOWS\system32\ATKDispCPL.dll
2010-09-09 02:26:02 ----A---- C:\WINDOWS\system32\ATKDISP.dll
2010-09-09 02:26:02 ----A---- C:\WINDOWS\system32\asrussian.dll
2010-09-09 02:26:02 ----A---- C:\WINDOWS\system32\askorean.dll
2010-09-09 02:26:02 ----A---- C:\WINDOWS\system32\asjapan.dll
2010-09-09 02:26:02 ----A---- C:\WINDOWS\system32\ASCHT.dll
2010-09-09 02:26:02 ----A---- C:\WINDOWS\system32\aschs.dll
2010-09-09 02:26:02 ----A---- C:\WINDOWS\system32\asgerman.dll
2010-09-09 02:26:02 ----A---- C:\WINDOWS\system32\asfrench.dll
2010-09-09 02:26:02 ----A---- C:\WINDOWS\system32\aseng.dll
2010-09-09 02:26:01 ----HD---- C:\Program Files\InstallShield Installation Information
2010-09-09 02:25:15 ----D---- C:\WINDOWS\nview
2010-09-09 02:25:15 ----A---- C:\WINDOWS\system32\nvudisp.exe
2010-09-09 02:24:56 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2010-09-09 02:24:20 ----D---- C:\Program Files\Common Files\InstallShield
2010-09-09 02:20:01 ----D---- C:\WINDOWS\system32\1051
2010-09-09 02:18:35 ----D---- C:\Documents and Settings\Lucinka\Application Data\Identities
2010-09-09 02:18:33 ----HD---- C:\Program Files\Uninstall Information
2010-09-09 02:18:16 ----ASH---- C:\Documents and Settings\Lucinka\Application Data\desktop.ini
2010-09-09 02:18:15 ----SD---- C:\Documents and Settings\Lucinka\Application Data\Microsoft
2010-09-09 02:17:25 ----D---- C:\WINDOWS\SoftwareDistribution
2010-09-09 02:17:22 ----SD---- C:\WINDOWS\system32\Microsoft
2010-09-09 02:17:22 ----D---- C:\WINDOWS\Prefetch
2010-09-09 02:17:22 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-09-09 02:14:25 ----D---- C:\WINDOWS\system32\xircom
2010-09-09 02:14:25 ----D---- C:\Program Files\xerox
2010-09-09 02:14:25 ----D---- C:\Program Files\microsoft frontpage
2010-09-09 02:14:15 ----HD---- C:\WINDOWS\$hf_mig$
2010-09-09 02:14:14 ----N---- C:\WINDOWS\system32\xpsp3res.dll
2010-09-09 02:14:05 ----RASH---- C:\MSDOS.SYS
2010-09-09 02:14:05 ----RASH---- C:\IO.SYS
2010-09-09 02:14:05 ----A---- C:\WINDOWS\control.ini
2010-09-09 02:14:05 ----A---- C:\CONFIG.SYS
2010-09-09 02:14:05 ----A---- C:\AUTOEXEC.BAT
2010-09-09 02:13:57 ----A---- C:\WINDOWS\OEWABLog.txt
2010-09-09 02:13:54 ----A---- C:\WINDOWS\system32\mapi32.dll
2010-09-09 02:13:18 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-09-09 02:13:18 ----RD---- C:\WINDOWS\Offline Web Pages
2010-09-09 02:13:18 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2010-09-09 02:13:13 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2010-09-09 02:13:08 ----HD---- C:\Program Files\WindowsUpdate
2010-09-09 02:12:53 ----D---- C:\WINDOWS\system32\DirectX
2010-09-09 02:12:37 ----A---- C:\WINDOWS\system32\atrace.dll
2010-09-09 02:12:35 ----A---- C:\WINDOWS\system32\desktop.ini
2010-09-09 02:12:35 ----A---- C:\WINDOWS\desktop.ini
2010-09-09 02:12:29 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2010-09-09 02:12:28 ----D---- C:\Program Files\Common Files\Services
2010-09-09 02:12:28 ----A---- C:\WINDOWS\system32\acctres.dll
2010-09-09 02:12:25 ----SD---- C:\WINDOWS\Tasks
2010-09-09 02:12:25 ----D---- C:\Program Files\Common Files\MSSoap
2010-09-09 02:12:25 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2010-09-09 02:12:21 ----D---- C:\WINDOWS\system32\Macromed
2010-09-09 02:12:21 ----D---- C:\WINDOWS\srchasst
2010-09-09 02:12:19 ----A---- C:\WINDOWS\system32\wuweb.dll
2010-09-09 02:12:19 ----A---- C:\WINDOWS\system32\wucltui.dll
2010-09-09 02:12:19 ----A---- C:\WINDOWS\system32\wuauserv.dll
2010-09-09 02:12:19 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2010-09-09 02:12:18 ----A---- C:\WINDOWS\system32\wups.dll
2010-09-09 02:12:18 ----A---- C:\WINDOWS\system32\wuaueng.dll
2010-09-09 02:12:18 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2010-09-09 02:12:18 ----A---- C:\WINDOWS\system32\wuauclt.exe
2010-09-09 02:12:18 ----A---- C:\WINDOWS\system32\wuapi.dll
2010-09-09 02:12:18 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2010-09-09 02:12:18 ----A---- C:\WINDOWS\system32\qmgr.dll
2010-09-09 02:12:18 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2010-09-09 02:12:18 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2010-09-09 02:12:15 ----D---- C:\Program Files\Movie Maker
2010-09-09 02:12:11 ----A---- C:\WINDOWS\system32\safrslv.dll
2010-09-09 02:12:11 ----A---- C:\WINDOWS\system32\safrdm.dll
2010-09-09 02:12:11 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2010-09-09 02:12:11 ----A---- C:\WINDOWS\system32\racpldlg.dll
2010-09-09 02:12:09 ----A---- C:\WINDOWS\system32\fltMc.exe
2010-09-09 02:12:09 ----A---- C:\WINDOWS\system32\fltlib.dll
2010-09-09 02:12:09 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys
2010-09-09 02:12:08 ----D---- C:\WINDOWS\system32\Restore
2010-09-09 02:12:08 ----A---- C:\WINDOWS\system32\srsvc.dll
2010-09-09 02:12:08 ----A---- C:\WINDOWS\system32\srrstr.dll
2010-09-09 02:12:08 ----A---- C:\WINDOWS\system32\srclient.dll
2010-09-09 02:12:08 ----A---- C:\WINDOWS\system32\mnmdd.dll
2010-09-09 02:12:08 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2010-09-09 02:12:08 ----A---- C:\WINDOWS\system32\ils.dll
2010-09-09 02:12:08 ----A---- C:\WINDOWS\system32\drivers\sr.sys
2010-09-09 02:12:07 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2010-09-09 02:12:07 ----A---- C:\WINDOWS\system32\msconf.dll
2010-09-09 02:12:07 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2010-09-09 02:12:05 ----D---- C:\Program Files\NetMeeting
2010-09-09 02:12:05 ----A---- C:\WINDOWS\system32\msoert2.dll
2010-09-09 02:12:05 ----A---- C:\WINDOWS\system32\msoeacct.dll
2010-09-09 02:12:04 ----A---- C:\WINDOWS\system32\inetres.dll
2010-09-09 02:12:04 ----A---- C:\WINDOWS\system32\inetcomm.dll
2010-09-09 02:12:03 ----D---- C:\Program Files\Outlook Express
2010-09-09 02:12:03 ----A---- C:\WINDOWS\system32\schedsvc.dll
2010-09-09 02:12:02 ----A---- C:\WINDOWS\system32\mstinit.exe
2010-09-09 02:12:02 ----A---- C:\WINDOWS\system32\mstask.dll
2010-09-09 02:12:02 ----A---- C:\WINDOWS\system32\isign32.dll
2010-09-09 02:12:02 ----A---- C:\WINDOWS\system32\inetcfg.dll
2010-09-09 02:12:02 ----A---- C:\WINDOWS\system32\icwphbk.dll
2010-09-09 02:12:02 ----A---- C:\WINDOWS\system32\icwdial.dll
2010-09-09 02:11:57 ----D---- C:\Program Files\Internet Explorer
2010-09-09 02:11:57 ----D---- C:\Program Files\Common Files\System
2010-09-09 02:11:48 ----D---- C:\Program Files\ComPlus Applications
2010-09-09 02:11:46 ----A---- C:\WINDOWS\vbaddin.ini
2010-09-09 02:11:46 ----A---- C:\WINDOWS\vb.ini
2010-09-09 02:11:43 ----D---- C:\WINDOWS\Registration
2010-09-09 02:11:22 ----D---- C:\Program Files\Windows Media Player
2010-09-09 02:11:22 ----D---- C:\Program Files\Online Services
2010-09-09 02:11:18 ----D---- C:\Program Files\Messenger
2010-09-09 02:11:15 ----D---- C:\Program Files\MSN Gaming Zone
2010-09-09 02:11:15 ----A---- C:\WINDOWS\system32\write.exe
2010-09-09 02:11:08 ----A---- C:\WINDOWS\system32\sndvol32.exe
2010-09-09 02:11:08 ----A---- C:\WINDOWS\system32\hticons.dll
2010-09-09 02:11:08 ----A---- C:\WINDOWS\system32\avwav.dll
2010-09-09 02:11:08 ----A---- C:\WINDOWS\system32\avtapi.dll
2010-09-09 02:11:08 ----A---- C:\WINDOWS\system32\avmeter.dll
2010-09-09 02:11:07 ----A---- C:\WINDOWS\system32\winchat.exe
2010-09-09 02:11:02 ----A---- C:\WINDOWS\system32\charmap.exe
2010-09-09 02:11:02 ----A---- C:\WINDOWS\system32\getuname.dll
2010-09-09 02:11:01 ----A---- C:\WINDOWS\system32\winmine.exe
2010-09-09 02:11:01 ----A---- C:\WINDOWS\system32\sol.exe
2010-09-09 02:11:01 ----A---- C:\WINDOWS\system32\reset.exe
2010-09-09 02:11:01 ----A---- C:\WINDOWS\system32\mshearts.exe
2010-09-09 02:11:01 ----A---- C:\WINDOWS\system32\freecell.exe
2010-09-09 02:11:01 ----A---- C:\WINDOWS\system32\calc.exe
2010-09-09 02:11:00 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2010-09-09 02:11:00 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2010-09-09 02:11:00 ----A---- C:\WINDOWS\system32\tslabels.ini
2010-09-09 02:11:00 ----A---- C:\WINDOWS\system32\tskill.exe
2010-09-09 02:11:00 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2010-09-09 02:11:00 ----A---- C:\WINDOWS\system32\tscon.exe
2010-09-09 02:11:00 ----A---- C:\WINDOWS\system32\shadow.exe
2010-09-09 02:11:00 ----A---- C:\WINDOWS\system32\rwinsta.exe
2010-09-09 02:11:00 ----A---- C:\WINDOWS\system32\regini.exe
2010-09-09 02:11:00 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2010-09-09 02:11:00 ----A---- C:\WINDOWS\system32\qwinsta.exe
2010-09-09 02:11:00 ----A---- C:\WINDOWS\system32\qappsrv.exe
2010-09-09 02:11:00 ----A---- C:\WINDOWS\system32\msg.exe
2010-09-09 02:11:00 ----A---- C:\WINDOWS\system32\logoff.exe
2010-09-09 02:10:59 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2010-09-09 02:10:59 ----A---- C:\WINDOWS\system32\mtxex.dll
2010-09-09 02:10:59 ----A---- C:\WINDOWS\system32\mtxdm.dll
2010-09-09 02:10:59 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2010-09-09 02:10:59 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2010-09-09 02:10:59 ----A---- C:\WINDOWS\system32\cdmodem.dll
2010-09-09 02:10:58 ----A---- C:\WINDOWS\system32\stclient.dll
2010-09-09 02:10:58 ----A---- C:\WINDOWS\system32\comsnap.dll
2010-09-09 02:10:58 ----A---- C:\WINDOWS\system32\comrepl.dll
2010-09-09 02:10:58 ----A---- C:\WINDOWS\system32\comaddin.dll
2010-09-09 02:10:55 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2010-09-09 02:10:45 ----D---- C:\Program Files\MSN
2010-09-09 02:10:44 ----D---- C:\Program Files\Windows NT
2010-09-09 02:10:44 ----A---- C:\WINDOWS\system32\sndrec32.exe
2010-09-09 02:10:44 ----A---- C:\WINDOWS\system32\mplay32.exe
2010-09-09 02:10:44 ----A---- C:\WINDOWS\system32\hypertrm.dll
2010-09-09 02:10:44 ----A---- C:\WINDOWS\system32\accwiz.exe
2010-09-09 02:10:43 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2010-09-09 02:10:43 ----A---- C:\WINDOWS\system32\spider.exe
2010-09-09 02:10:43 ----A---- C:\WINDOWS\system32\mspaint.exe
2010-09-09 02:10:43 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys
2010-09-09 02:10:43 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys
2010-09-09 02:10:43 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys
2010-09-09 02:10:43 ----A---- C:\WINDOWS\system32\clipbrd.exe
2010-09-09 02:10:42 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2010-09-09 02:10:42 ----A---- C:\WINDOWS\system32\termsrv.dll
2010-09-09 02:10:42 ----A---- C:\WINDOWS\system32\sessmgr.exe
2010-09-09 02:10:42 ----A---- C:\WINDOWS\system32\remotepg.dll
2010-09-09 02:10:42 ----A---- C:\WINDOWS\system32\rdshost.exe
2010-09-09 02:10:42 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2010-09-09 02:10:42 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2010-09-09 02:10:42 ----A---- C:\WINDOWS\system32\rdchost.dll
2010-09-09 02:10:42 ----A---- C:\WINDOWS\system32\mstscax.dll
2010-09-09 02:10:42 ----A---- C:\WINDOWS\system32\mstsc.exe
2010-09-09 02:10:41 ----D---- C:\WINDOWS\system32\MsDtc
2010-09-09 02:10:41 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2010-09-09 02:10:41 ----A---- C:\WINDOWS\system32\rdpclip.exe
2010-09-09 02:10:41 ----A---- C:\WINDOWS\system32\qprocess.exe
2010-09-09 02:10:41 ----A---- C:\WINDOWS\system32\mtxoci.dll
2010-09-09 02:10:41 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2010-09-09 02:10:41 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2010-09-09 02:10:41 ----A---- C:\WINDOWS\system32\icaapi.dll
2010-09-09 02:10:41 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2010-09-09 02:10:40 ----D---- C:\WINDOWS\system32\Com
2010-09-09 02:10:40 ----A---- C:\WINDOWS\system32\xolehlp.dll
2010-09-09 02:10:40 ----A---- C:\WINDOWS\system32\msdtctm.dll
2010-09-09 02:10:40 ----A---- C:\WINDOWS\system32\msdtclog.dll
2010-09-09 02:10:40 ----A---- C:\WINDOWS\system32\msdtc.exe
2010-09-09 02:10:40 ----A---- C:\WINDOWS\system32\colbact.dll
2010-09-09 02:10:39 ----A---- C:\WINDOWS\system32\comuid.dll
2010-09-09 02:10:39 ----A---- C:\WINDOWS\system32\comsvcs.dll
2010-09-09 02:10:39 ----A---- C:\WINDOWS\system32\clbcatex.dll
2010-09-09 02:10:39 ----A---- C:\WINDOWS\system32\catsrvut.dll
2010-09-09 02:10:39 ----A---- C:\WINDOWS\system32\catsrvps.dll
2010-09-09 02:10:39 ----A---- C:\WINDOWS\system32\catsrv.dll
2010-09-09 02:10:38 ----A---- C:\WINDOWS\system32\clbcatq.dll
2010-09-09 02:10:35 ----A---- C:\WINDOWS\system32\servdeps.dll
2010-09-09 02:10:35 ----A---- C:\WINDOWS\system32\mmfutil.dll
2010-09-09 02:10:34 ----A---- C:\WINDOWS\system32\licwmi.dll
2010-09-09 02:10:34 ----A---- C:\WINDOWS\system32\cmprops.dll
2010-09-09 02:10:27 ----A---- C:\WINDOWS\system32\drivers\termdd.sys
2010-09-09 02:10:27 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys
2010-09-08 19:09:39 ----A---- C:\WINDOWS\system32\h323log.txt
2010-09-08 19:05:09 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2010-09-08 19:04:44 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2010-09-08 19:04:08 ----A---- C:\WINDOWS\system32\usbui.dll
2010-09-08 19:03:25 ----A---- C:\WINDOWS\imsins.BAK
2010-09-08 19:03:23 ----SHD---- C:\WINDOWS\Installer
2010-09-08 19:03:23 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-09-08 19:03:22 ----D---- C:\Program Files\Common Files\ODBC
2010-09-08 19:03:22 ----A---- C:\WINDOWS\ODBCINST.INI
2010-09-08 19:03:19 ----RD---- C:\Program Files
2010-09-08 19:03:19 ----D---- C:\Program Files\Common Files\SpeechEngines
2010-09-08 19:03:19 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-09-08 19:03:19 ----D---- C:\Program Files\Common Files
2010-09-08 19:03:17 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2010-09-08 19:03:17 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2010-09-08 19:03:17 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2010-09-08 19:03:15 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2010-09-08 19:03:15 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2010-09-08 19:03:15 ----RA---- C:\WINDOWS\system32\kbdur.dll
2010-09-08 19:03:15 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2010-09-08 19:03:15 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2010-09-08 19:03:15 ----RA---- C:\WINDOWS\system32\kbdru.dll
2010-09-08 19:03:15 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2010-09-08 19:03:15 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2010-09-08 19:03:15 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2010-09-08 19:03:15 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2010-09-08 19:03:15 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2010-09-08 19:03:15 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2010-09-08 19:03:14 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2010-09-08 19:03:14 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2010-09-08 19:03:14 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2010-09-08 19:03:14 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2010-09-08 19:03:14 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2010-09-08 19:03:14 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2010-09-08 19:03:14 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2010-09-08 19:03:12 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2010-09-08 19:03:12 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2010-09-08 19:03:12 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2010-09-08 19:03:12 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2010-09-08 19:03:12 ----RA---- C:\WINDOWS\system32\kbdest.dll
2010-09-08 19:03:11 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2010-09-08 19:03:11 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2010-09-08 19:03:11 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2010-09-08 19:03:11 ----RA---- C:\WINDOWS\system32\kbdro.dll
2010-09-08 19:03:11 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2010-09-08 19:03:11 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2010-09-08 19:03:11 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2010-09-08 19:03:11 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2010-09-08 19:03:11 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2010-09-08 19:03:11 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2010-09-08 19:03:11 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2010-09-08 19:03:11 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2010-09-08 19:03:11 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2010-09-08 19:03:08 ----A---- C:\WINDOWS\system32\spxcoins.dll
2010-09-08 19:03:08 ----A---- C:\WINDOWS\system32\irclass.dll
2010-09-08 19:03:08 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2010-09-08 19:03:08 ----A---- C:\WINDOWS\system32\dgsetup.dll
2010-09-08 19:03:08 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2010-09-08 19:03:06 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2010-09-08 19:03:06 ----A---- C:\WINDOWS\TASKMAN.EXE
2010-09-08 19:03:06 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2010-09-08 19:03:06 ----A---- C:\WINDOWS\system32\batt.dll
2010-09-08 19:03:05 ----A---- C:\WINDOWS\NOTEPAD.EXE
2010-09-08 19:03:01 ----A---- C:\WINDOWS\system32\storprop.dll
2010-09-08 19:02:56 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2010-09-08 19:01:46 ----RA---- C:\WINDOWS\SET25.tmp
2010-09-08 19:01:15 ----RA---- C:\WINDOWS\SET8.tmp
2010-09-08 19:01:13 ----RA---- C:\WINDOWS\SET4.tmp
2010-09-08 19:01:12 ----RA---- C:\WINDOWS\SET3.tmp
2010-09-08 19:01:08 ----D---- C:\WINDOWS\system32\CatRoot2
2010-09-08 19:01:08 ----D---- C:\WINDOWS\system32\CatRoot
2010-09-08 19:01:02 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-09-08 19:00:45 ----A---- C:\WINDOWS\setuplog.txt
2010-09-08 19:00:39 ----SHD---- C:\System Volume Information
2010-09-08 19:00:39 ----D---- C:\Documents and Settings
2010-09-08 18:59:41 ----RSH---- C:\boot.ini
2010-09-08 18:55:02 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-09-08 18:55:02 ----RSD---- C:\WINDOWS\Fonts
2010-09-08 18:55:02 ----RD---- C:\WINDOWS\Web
2010-09-08 18:55:02 ----HD---- C:\WINDOWS\inf
2010-09-08 18:55:02 ----D---- C:\WINDOWS\WinSxS
2010-09-08 18:55:02 ----D---- C:\WINDOWS\twain_32
2010-09-08 18:55:02 ----D---- C:\WINDOWS\Temp
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\wins
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\wbem
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\usmt
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\spool
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\ShellExt
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\Setup
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\ras
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\oobe
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\npp
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\mui
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\inetsrv
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\IME
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\icsxml
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\ias
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\export
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\drivers\etc
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\drivers\disdn
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\drivers
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\dhcp
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\config
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\3com_dmi
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\3076
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\2052
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\1054
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\1042
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\1041
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\1037
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\1033
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\1031
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\1028
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32\1025
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system32
2010-09-08 18:55:02 ----D---- C:\WINDOWS\system
2010-09-08 18:55:02 ----D---- C:\WINDOWS\security
2010-09-08 18:55:02 ----D---- C:\WINDOWS\Resources
2010-09-08 18:55:02 ----D---- C:\WINDOWS\repair
2010-09-08 18:55:02 ----D---- C:\WINDOWS\Provisioning
2010-09-08 18:55:02 ----D---- C:\WINDOWS\pchealth
2010-09-08 18:55:02 ----D---- C:\WINDOWS\PeerNet
2010-09-08 18:55:02 ----D---- C:\WINDOWS\mui
2010-09-08 18:55:02 ----D---- C:\WINDOWS\msapps
2010-09-08 18:55:02 ----D---- C:\WINDOWS\msagent
2010-09-08 18:55:02 ----D---- C:\WINDOWS\Media
2010-09-08 18:55:02 ----D---- C:\WINDOWS\java
2010-09-08 18:55:02 ----D---- C:\WINDOWS\ime
2010-09-08 18:55:02 ----D---- C:\WINDOWS\Help
2010-09-08 18:55:02 ----D---- C:\WINDOWS\Driver Cache
2010-09-08 18:55:02 ----D---- C:\WINDOWS\Debug
2010-09-08 18:55:02 ----D---- C:\WINDOWS\Cursors
2010-09-08 18:55:02 ----D---- C:\WINDOWS\Connection Wizard
2010-09-08 18:55:02 ----D---- C:\WINDOWS\Config
2010-09-08 18:55:02 ----D---- C:\WINDOWS\AppPatch
2010-09-08 18:55:02 ----D---- C:\WINDOWS\addins
2010-09-08 18:55:02 ----D---- C:\WINDOWS
2010-09-08 18:55:02 ----ASH---- C:\pagefile.sys
2010-09-08 18:13:07 ----D---- C:\Documents and Settings\Lucinka\Application Data\WinRAR
2010-09-08 18:12:45 ----D---- C:\Program Files\Webteh
2010-09-08 18:11:57 ----D---- C:\Program Files\WinRAR
2010-09-08 18:11:40 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-09-08 18:11:39 ----D---- C:\Documents and Settings\Lucinka\Application Data\Macromedia
2010-09-08 18:11:39 ----D---- C:\Documents and Settings\Lucinka\Application Data\Adobe
2010-09-08 18:11:21 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-09-08 18:11:18 ----D---- C:\Program Files\Common Files\Adobe
2010-09-08 18:11:18 ----D---- C:\Program Files\Adobe
2010-09-08 18:10:37 ----D---- C:\Program Files\7-Zip
2010-09-08 18:09:46 ----D---- C:\Documents and Settings\All Users\Application Data\CyberLink
2010-09-08 18:09:14 ----D---- C:\Program Files\CyberLink
2010-09-08 18:08:03 ----A---- C:\WINDOWS\system32\wmpns.dll
2010-09-08 18:04:01 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2010-09-08 18:02:36 ----D---- C:\Program Files\Microsoft Works
2010-09-08 18:02:32 ----D---- C:\Program Files\MSBuild
2010-09-08 18:02:26 ----D---- C:\Program Files\Microsoft Visual Studio
2010-09-08 18:02:26 ----D---- C:\Program Files\Common Files\DESIGNER
2010-09-08 18:00:28 ----D---- C:\WINDOWS\SHELLNEW
2010-09-08 18:00:14 ----D---- C:\Program Files\Microsoft Office
2010-09-08 18:00:14 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-09-08 18:00:01 ----RHD---- C:\MSOCache
2010-09-08 17:58:46 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2010-09-08 17:58:41 ----D---- C:\Program Files\TuneUp Utilities 2007
2010-09-08 17:58:41 ----D---- C:\Documents and Settings\Lucinka\Application Data\TuneUp Software
2010-09-08 17:58:32 ----D---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2010-09-08 17:58:31 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-09-08 17:52:33 ----D---- C:\Program Files\ICQ6Toolbar
2010-09-08 17:52:31 ----D---- C:\Documents and Settings\Lucinka\Application Data\Mozilla
2010-09-08 17:52:31 ----D---- C:\Documents and Settings\All Users\Application Data\ICQ
2010-09-08 17:51:46 ----D---- C:\Documents and Settings\Lucinka\Application Data\ICQ
2010-09-08 17:51:31 ----D---- C:\Program Files\ICQ6.5
2010-09-08 17:50:57 ----D---- C:\Documents and Settings\All Users\Application Data\Sun
2010-09-08 17:50:56 ----D---- C:\Program Files\Common Files\Java
2010-09-08 17:50:47 ----A---- C:\WINDOWS\system32\javaws.exe
2010-09-08 17:50:47 ----A---- C:\WINDOWS\system32\javaw.exe
2010-09-08 17:50:47 ----A---- C:\WINDOWS\system32\java.exe
2010-09-08 17:50:47 ----A---- C:\WINDOWS\system32\deployJava1.dll
2010-09-08 17:50:38 ----SHD---- C:\RECYCLER
2010-09-08 17:50:32 ----D---- C:\Program Files\Java
2010-09-08 17:49:38 ----D---- C:\Documents and Settings\Lucinka\Application Data\Sun
2010-09-08 17:48:09 ----D---- C:\Program Files\LimeWire
2010-09-08 17:47:29 ----D---- C:\Documents and Settings\Lucinka\Application Data\Opera
2010-09-08 17:47:24 ----D---- C:\Program Files\Opera
2010-09-08 17:46:40 ----HDC---- C:\WINDOWS\$NtUninstallKB952011$
2010-09-08 17:46:26 ----D---- C:\Program Files\Google
2010-09-08 17:46:01 ----D---- C:\Documents and Settings\Lucinka\Application Data\QipGuard
2010-09-08 17:45:00 ----D---- C:\Documents and Settings\Lucinka\Application Data\QIP
2010-09-08 17:44:47 ----D---- C:\Program Files\QIP 2010
2010-09-08 17:44:22 ----D---- C:\Program Files\uTorrent
2010-09-08 17:44:20 ----D---- C:\Documents and Settings\Lucinka\Application Data\uTorrent
2010-09-08 17:43:36 ----N---- C:\WINDOWS\system32\vxblock.dll
2010-09-08 17:43:36 ----N---- C:\WINDOWS\system32\pxwave.dll
2010-09-08 17:43:36 ----N---- C:\WINDOWS\system32\pxsfs.dll
2010-09-08 17:43:36 ----N---- C:\WINDOWS\system32\pxmas.dll
2010-09-08 17:43:36 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2010-09-08 17:43:36 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2010-09-08 17:43:36 ----N---- C:\WINDOWS\system32\pxdrv.dll
2010-09-08 17:43:36 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2010-09-08 17:43:36 ----N---- C:\WINDOWS\system32\pxafs.dll
2010-09-08 17:43:36 ----N---- C:\WINDOWS\system32\px.dll
2010-09-08 17:43:36 ----N---- C:\WINDOWS\system32\drivers\PxHelp20.sys
2010-09-08 17:43:36 ----N---- C:\WINDOWS\system32\drivers\cdralw2k.sys
2010-09-08 17:43:36 ----N---- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2010-09-08 17:43:34 ----D---- C:\Program Files\Winamp
2010-09-08 17:43:34 ----D---- C:\Documents and Settings\Lucinka\Application Data\Winamp
2010-09-08 17:42:23 ----HDC---- C:\WINDOWS\$NtUninstallKB926239$
2010-09-08 17:42:19 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-09-08 17:42:17 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2010-09-08 17:42:10 ----D---- C:\Program Files\Windows Media Connect 2
2010-09-08 17:42:05 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2010-09-08 17:41:42 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2010-09-08 17:41:25 ----D---- C:\WINDOWS\system32\LogFiles
2010-09-08 17:41:25 ----D---- C:\WINDOWS\system32\drivers\UMDF
2010-09-08 17:41:23 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2010-09-08 17:41:03 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2010-09-08 17:40:37 ----D---- C:\Documents and Settings\Lucinka\Application Data\ESET
2010-09-08 17:38:54 ----D---- C:\Program Files\ESET
2010-09-08 17:38:54 ----D---- C:\Documents and Settings\All Users\Application Data\ESET
2010-09-08 17:38:33 ----A---- C:\WINDOWS\system32\wpa.bak
2010-09-08 17:37:37 ----D---- C:\Program Files\Ask.com
2010-09-08 17:37:22 ----D---- C:\Program Files\The KMPlayer
2010-09-08 17:35:14 ----D---- C:\WINDOWS\system32\Lang
2010-09-08 17:35:13 ----A---- C:\WINDOWS\system32\drivers\splitter.sys
2010-09-08 17:34:00 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys
2010-09-08 17:33:59 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys
2010-09-08 17:33:43 ----R---- C:\WINDOWS\system32\ChCfg.exe
2010-09-08 17:33:12 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys
2010-09-08 17:33:11 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys
2010-09-08 17:33:11 ----A---- C:\WINDOWS\system32\drivers\aec.sys
2010-09-08 17:33:10 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys
2010-09-08 17:33:10 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys
2010-09-08 17:33:09 ----A---- C:\WINDOWS\system32\drivers\MSPQM.sys
2010-09-08 17:33:09 ----A---- C:\WINDOWS\system32\drivers\MSKSSRV.sys
2010-09-08 17:33:08 ----A---- C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2010-09-08 17:33:06 ----D---- C:\WINDOWS\system32\RTCOM
2010-09-08 17:33:04 ----A---- C:\WINDOWS\system32\ksuser.dll
2010-09-08 17:33:04 ----A---- C:\WINDOWS\system32\drivers\drmk.sys
2010-09-08 17:33:01 ----R---- C:\WINDOWS\SoundMan.exe
2010-09-08 17:33:00 ----R---- C:\WINDOWS\SkyTel.exe
2010-09-08 17:32:59 ----R---- C:\WINDOWS\RtlUpd.exe
2010-09-08 17:32:56 ----R---- C:\WINDOWS\RTLCPL.exe
2010-09-08 17:32:54 ----R---- C:\WINDOWS\system32\drivers\RtkHDAud.sys
2010-09-08 17:32:47 ----R---- C:\WINDOWS\RTHDCPL.exe
2010-09-08 17:32:46 ----R---- C:\WINDOWS\MicCal.exe
2010-09-08 17:32:43 ----R---- C:\WINDOWS\Alcmtr.exe
2010-09-08 17:32:42 ----R---- C:\WINDOWS\alcwzrd.exe
2010-09-08 17:32:42 ----D---- C:\Program Files\Realtek
2010-09-08 17:32:39 ----R---- C:\WINDOWS\RtlExUpd.dll
2010-09-08 17:32:39 ----A---- C:\WINDOWS\HideWin.exe
2010-09-08 17:32:21 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2010-09-08 17:32:20 ----HDC---- C:\WINDOWS\$NtUninstallKB888111WXPSP2$
2010-09-08 15:17:29 ----D---- C:\Documents and Settings\Lucinka\Application Data\Nero
2010-09-08 15:17:17 ----A---- C:\WINDOWS\system32\MsiExec.exe.log
2010-09-08 15:16:11 ----D---- C:\Program Files\Nero
2010-09-08 15:16:11 ----D---- C:\Program Files\Common Files\Nero
2010-09-08 15:16:11 ----D---- C:\Documents and Settings\All Users\Application Data\Nero
2010-09-08 11:41:45 ----D---- C:\rsit
2010-09-08 11:41:45 ----D---- C:\Program Files\trend micro
2010-09-08 11:39:20 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2010-09-08 11:39:01 ----D---- C:\WINDOWS\system32\PreInstall
2010-09-08 11:38:59 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2010-09-08 11:38:59 ----D---- C:\WINDOWS\LastGood

======List of files/folders modified in the last 1 months======

2010-09-09 02:13:45 ----ASH---- C:\WINDOWS\fonts\desktop.ini
2010-09-08 19:08:43 ----A---- C:\WINDOWS\system.ini
2010-09-08 18:00:44 ----A---- C:\WINDOWS\win.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2006-10-19 105472]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R1 asuskbnt;Enhanced Display Driver Helper Service; C:\WINDOWS\system32\drivers\atkkbnt.sys [2007-02-15 11136]
R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2007-12-21 30216]
R1 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2007-12-21 53768]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2007-12-21 39944]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2007-12-21 71176]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2007-12-21 30728]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-08 138752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-01-30 4474368]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-04-12 6738656]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-11-28 58368]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-11-28 19968]
R3 Video3D;ASUS Video3D Service; C:\WINDOWS\System32\Drivers\Video3D32.sys [2006-09-29 10752]
S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-29 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-29 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe [2006-11-15 258560]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2009-08-16 222968]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-09-08 153376]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-04-12 163908]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
R2 UxTuneUp;TuneUp Design Expansion; C:\WINDOWS\System32\svchost.exe [2006-02-28 14336]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-25 537896]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2007-12-21 19200]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-27 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-06 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2006-02-28 14336]

-----------------EOF-----------------

Re: Win XP - seka aj po reinstalacii a naformatovani disku

Napsal: 09 zář 2010 11:46
od DanielDevil
Log z Combofix
ComboFix 10-09-08.01 - Lucinka 08.09.2010 12:01:25.1.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.2.1250.421.1033.18.2047.1460 [GMT 2:00]
Running from: c:\documents and settings\Lucinka\Desktop\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\_000110_.tmp.dll
c:\windows\system32\_000114_.tmp.dll

.
((((((((((((((((((((((((( Files Created from 2010-08-08 to 2010-09-08 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-09 00:29 . 2010-09-09 00:29 -------- d-----w- c:\documents and settings\Lucinka\Application Data\InstallShield
2010-09-08 16:09 . 2010-09-08 16:09 -------- d-----w- c:\program files\CyberLink
2010-09-08 16:08 . 2010-09-09 00:24 -------- d-----w- c:\program files\Common Files\InstallShield
2010-09-08 16:04 . 2010-09-08 15:44 -------- d-----w- c:\documents and settings\Lucinka\Application Data\uTorrent
2010-09-08 16:03 . 2010-09-08 16:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-09-08 16:02 . 2010-09-08 16:02 -------- d-----w- c:\program files\Microsoft Works
2010-09-08 16:02 . 2010-09-08 16:02 -------- d-----w- c:\program files\MSBuild
2010-09-08 15:59 . 2010-09-08 15:58 -------- d-----w- c:\program files\TuneUp Utilities 2007
2010-09-08 15:58 . 2010-09-08 15:58 -------- d-----w- c:\documents and settings\Lucinka\Application Data\TuneUp Software
2010-09-08 15:58 . 2010-09-08 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-09-08 15:58 . 2010-09-08 15:58 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-09-08 15:52 . 2010-09-08 15:52 -------- d-----w- c:\program files\ICQ6Toolbar
2010-09-08 15:52 . 2010-09-08 15:52 -------- d-----w- c:\documents and settings\All Users\Application Data\ICQ
2010-09-08 15:51 . 2010-09-08 15:51 503808 ----a-w- c:\documents and settings\Lucinka\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1e7ee666-n\msvcp71.dll
2010-09-08 15:51 . 2010-09-08 15:51 499712 ----a-w- c:\documents and settings\Lucinka\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1e7ee666-n\jmc.dll
2010-09-08 15:51 . 2010-09-08 15:51 348160 ----a-w- c:\documents and settings\Lucinka\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1e7ee666-n\msvcr71.dll
2010-09-08 15:51 . 2010-09-08 15:51 61440 ----a-w- c:\documents and settings\Lucinka\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-24280d3a-n\decora-sse.dll
2010-09-08 15:51 . 2010-09-08 15:51 12800 ----a-w- c:\documents and settings\Lucinka\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-24280d3a-n\decora-d3d.dll
2010-09-08 15:50 . 2010-09-08 15:50 -------- d-----w- c:\program files\Common Files\Java
2010-09-08 15:50 . 2010-09-08 15:50 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-08 15:50 . 2010-09-08 15:50 -------- d-----w- c:\program files\Java
2010-09-08 15:48 . 2010-09-08 15:48 -------- d-----w- c:\program files\LimeWire
2010-09-08 15:46 . 2010-09-08 15:46 -------- d-----w- c:\program files\Google
2010-09-08 15:45 . 2010-09-08 15:45 -------- d-----w- c:\documents and settings\Lucinka\Application Data\QIP
2010-09-08 15:44 . 2010-09-08 15:44 -------- d-----w- c:\program files\uTorrent
2010-09-08 15:44 . 2010-09-08 15:43 -------- d-----w- c:\documents and settings\Lucinka\Application Data\Winamp
2010-09-08 15:43 . 2010-09-08 15:43 -------- d-----w- c:\program files\Winamp
2010-09-08 15:42 . 2010-09-08 15:42 -------- d-----w- c:\program files\Windows Media Connect 2
2010-09-08 15:40 . 2010-09-08 15:40 -------- d-----w- c:\documents and settings\Lucinka\Application Data\ESET
2010-09-08 15:38 . 2010-09-08 15:38 -------- d-----w- c:\program files\ESET
2010-09-08 15:38 . 2010-09-08 15:38 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2010-09-08 15:37 . 2010-09-08 15:37 -------- d-----w- c:\program files\The KMPlayer
2010-09-08 15:37 . 2010-09-08 15:37 -------- d-----w- c:\program files\Ask.com
2010-09-08 15:32 . 2010-09-08 15:32 -------- d-----w- c:\program files\Realtek
2010-09-08 15:32 . 2010-09-08 15:32 315392 ----a-w- c:\windows\HideWin.exe
2010-09-08 15:31 . 2010-09-09 00:28 14656 ----a-w- c:\windows\gdrv.sys
2010-09-08 13:17 . 2010-09-08 13:17 -------- d-----w- c:\documents and settings\Lucinka\Application Data\Nero
2010-09-08 13:16 . 2010-09-08 13:16 -------- d-----w- c:\program files\Common Files\Nero
2010-09-08 13:16 . 2010-09-08 13:16 -------- d-----w- c:\program files\Nero
2010-09-08 13:16 . 2010-09-08 13:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2010-09-08 09:55 . 2010-09-08 15:47 -------- d-----w- c:\program files\Opera
2010-09-08 09:48 . 2010-09-08 09:48 -------- d-----w- c:\documents and settings\Lucinka\Application Data\QipGuard
2010-09-08 09:47 . 2010-09-08 09:47 -------- d-----w- c:\program files\QIP 2010
2010-09-08 09:41 . 2010-09-08 09:41 -------- d-----w- c:\program files\trend micro
2010-09-08 09:40 . 2010-09-08 15:51 -------- d-----w- c:\program files\ICQ6.5
2010-09-08 09:40 . 2010-09-08 15:51 -------- d-----w- c:\documents and settings\Lucinka\Application Data\ICQ
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-07-11 00:28 1174920 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-11 1174920]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-11 1174920]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Lucinka\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-09-08 133104]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"Infium"="c:\program files\QIP 2010\qip.exe" [2010-06-09 5714384]
"QIP Internet Guardian"="c:\documents and settings\Lucinka\Application Data\QipGuard\QipGuard.exe" [2010-06-09 190416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-12 8429568]
"nwiz"="nwiz.exe" [2007-04-12 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-12 81920]
"GamerOSD"="c:\program files\ASUS\GamerOSD\GamerOSD.exe" [2007-02-14 380928]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-30 16116224]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2007-12-21 1443072]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 32768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-06-19 570664]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-02-28 15360]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [21.12.2007 17:21 468224]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [8.9.2010 17:52 222968]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-09-08 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 13:13]

2010-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1972579041-725345543-1004Core.job
- c:\documents and settings\Lucinka\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-08 15:53]

2010-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1972579041-725345543-1004UA.job
- c:\documents and settings\Lucinka\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-08 15:53]

2010-09-08 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-07-11 00:29]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://qip.ru
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Connection Wizard,ShellNext = hxxp://picasa.google.com/support/bin/answer.py?hl=sk&answer=93773
uSearchAssistant = hxxp://search.qip.ru/ie
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-08 12:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-09-08 12:04:00
ComboFix-quarantined-files.txt 2010-09-08 10:03

Pre-Run: 38 339 821 568 bytes free
Post-Run: 39 584 493 568 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer

- - End Of File - - 71C3A25A9A79B8A10C9136B8F55A6525

Re: Win XP - seka aj po reinstalacii a naformatovani disku

Napsal: 09 zář 2010 17:10
od vyosek
Zdravim a pekny vecer preji
Vas log se studuje Obrázek a pracuje se na nem Obrázek.
Prosim o strpeni!Obrázek

Re: Win XP - seka aj po reinstalacii a naformatovani disku

Napsal: 09 zář 2010 17:22
od vyosek
:arrow: Hned na uvod vsak male pokarani, ComboFix je urcen primarne pro radce nikoliv pro bezne uzivatele, jelikoz je vetsinou treba log z nej docistit, coz asi neumite, jelikoz tam jeste fura haveti je...

:arrow: Otevrete bednu PC a zkontrolujte, zda jsou ciste vetraky (ci nejsou zaneseny prachem), pokud ano, tak nejlepe stlacenym vzduchem vyfoukat - zadny vysavac :!: Nebo alespon vyfoukat usty. Pripadne tycinku do usi namocit do lihu (ci slivovice :D ) a opatrne at nic neulomite otrit...

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Folder::
    c:\program files\ICQ6Toolbar
    c:\program files\Ask.com
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Google Update"=-
    "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WinampAgent"=-
    "SunJavaUpdateSched"=-
    "RemoteControl"=-
    "Adobe Reader Speed Launcher"=-
    "NeroFilterCheck"=-
    "NBKeyScan"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{855F3B16-6D32-4fe6-8A56-BBB695989046}"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B5863A0-C43F-4C0A-982B-CC0E9125783F}]
    
    Driver::
    ICQ Service
    
    File::
    c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
    c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1972579041-725345543-1004UA.job
    c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1972579041-725345543-1004Core.job
    C:\Documents and Settings\Lucinka\Application Data\Microsoft\Internet Explorer\qipsearchbar.dll
    C:\Documents and Settings\Lucinka\Application Data\Microsoft\Internet Explorer\qstatsrv.dll
    
    DDS::
    uStart Page = hxxp://qip.ru
    uDefault_Search_URL = hxxp://search.qip.ru
    uSearchAssistant = hxxp://search.qip.ru/ie
    
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: Win XP - seka aj po reinstalacii a naformatovani disku

Napsal: 10 zář 2010 08:14
od james008
Presouvam... to ze se sekaji okna pramalo odpovida zarazeni do sekce antiviry ;-)

Re: Win XP - seka aj po reinstalacii a naformatovani disku

Napsal: 11 zář 2010 08:49
od DanielDevil
tak skúšala to spraviť, ale mala problém vôbec zapnúť pc, vraj to pustila len v núdzovom režíme, nevyplulo jej to žiadny log, potom jej nešiel ani zapnúť, dala niečo windows system recovery alebo tak a dostala sa po čiernu obrazovku kde píše C:Windows ... a chce to tam niečo dopísať

Re: Win XP - seka aj po reinstalacii a naformatovani disku

Napsal: 11 zář 2010 10:37
od vyosek
Mate instalacni CD, zrejme je system nejak napaden...

Re: Win XP - seka aj po reinstalacii a naformatovani disku

Napsal: 11 zář 2010 12:14
od DanielDevil
ved práve to nechápem že to robí aj potom ako 2x preinštalovala windows, dokonca aj naformátovala disk...

Re: Win XP - seka aj po reinstalacii a naformatovani disku

Napsal: 11 zář 2010 13:30
od vyosek
Seka se pri zatezi nebo i v klidu? Doinstalujte SP3...

Re: Win XP - seka aj po reinstalacii a naformatovani disku

Napsal: 14 zář 2010 08:39
od DanielDevil
SP3 má nahodený, vzdala to, že jej kamoš z tej istej dediny má opraváreň PC tak že mu to zanesie...

Re: Win XP - seka aj po reinstalacii a naformatovani disku

Napsal: 14 zář 2010 09:37
od vyosek
Dobra tedy...

Re: Win XP - seka aj po reinstalacii a naformatovani disku

Napsal: 29 zář 2010 08:17
od DanielDevil
len doplním že v oprave jej povedali že chyba je v HDD takže ide kupovať nový

Re: Win XP - seka aj po reinstalacii a naformatovani disku

Napsal: 29 zář 2010 15:14
od vyosek
Muzete provest kontrolu disku pomoci HD Tune http://www.stahuj.centrum.cz/utility_a_ ... g/hd-tune/