Infiltrace Protector.N virus
Napsal: 14 zář 2010 21:02
Dobrý den,
Antivirový program Eset nod antivirus 4.2 mi hlásí infiltraci Protector.N virus v souboru C:\Windows\system32\drivers\cdrom.sys. komentář k nálezu...... Tato skutečnost byla zjištěna při pokusu o přístup k souboru aplikací: C:\Windows\system32\svchost.exe. Vir je uložen v karanténě, nicméně stále mi vyskakuje hlášení Nodu o infiltraci. PC je dosti zpomalené a při některých úkolech na chvíli zamrzá. Dále byly nalezeny další nakažené soubory Trojským koněm, které se jak doufám podařilo vyléčit, či odstranit. Zkoušel jsem aplikovat program Conbofix, ale po spuštění se sám vypne a smaže. Přejměnování na grinder.com nepomohlo a situace se opakuje. Můžete mi prosím pomoci s řešením problému? Předem mnohokrát děkuji. Přikládám Log programu RSIT.
Logfile of random's system information tool 1.08 (written by random/random)
Run by Bronislav Žáček at 2010-08-14 21:34:05
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 114 GB (78%) free of 147 GB
Total RAM: 2047 MB (67% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:34:20, on 14.8.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\dgdersvc.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Citrix\ICA Client\concentr.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Citrix\ICA Client\WFCRUN32.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Citrix\ICA Client\PNAMAIN.EXE
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Bronislav Žáček\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Bronislav Žáček\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Bronislav Žáček\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Bronislav Žáček\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Bronislav Žáček\Dokumenty\Downloads\RSIT.exe
C:\WINDOWS\system32\HPBPRO.EXE
C:\Program Files\trend micro\Bronislav Žáček.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://10.1.112.9/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 217.112.175.67:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.1.1.171;172.22.4.31:8080;10.1.112.3;synot-sd;10.1.29.187;10.1.112.9;maxpower.gamemonitoring.cz;80.251.247.117;citrix-web;10.1.29.*;10.1.1.170;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Freecause Shopping BHO - {998A3C0C-8914-4D2A-AE36-BFA2E5AE6D5D} - C:\Program Files\Digsby Donates\ShoppingBHO.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Digsby Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [viwynni] C:\Documents and Settings\Bronislav Žáček\Data aplikací\Microsoft\buroutubi.exe
O4 - HKCU\..\Run: [wuaucldt] c:\documents and settings\bronislav Žáček\wuaucldt.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: 703q0hc.exe
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Online plug-in.lnk = ?
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 3831363431
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{71C0ACB6-A81D-485C-A092-8C227CDC6015}: NameServer = 10.1.29.132,10.1.29.133
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Device Error Recovery Service (dgdersvc) - Devguru Co., Ltd. - C:\WINDOWS\system32\dgdersvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: PowerUtility TV Recording Reservation (ekeiidyko6koty) - Unknown owner - C:\WINDOWS\system32\weda.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
--
End of file - 9856 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{5FBF80ED-672D-4256-B380-FD88BB024233}.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{E7CA6F26-AD3A-4ECD-ACAD-7C779DAE33F7}.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{FB2531FB-FAEE-437E-A52B-003A43ED731D}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{998A3C0C-8914-4D2A-AE36-BFA2E5AE6D5D}]
Digsby Donates - C:\Program Files\Digsby Donates\ShoppingBHO.dll [2010-07-11 638976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Digsby Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-07-10 1174920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-04 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Digsby Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-07-10 1174920]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-10-25 16855552]
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2007-10-11 1826816]
"ConnectionCenter"=C:\Program Files\Citrix\ICA Client\concentr.exe [2009-09-12 103768]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"StatusClient"=C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe [2002-12-16 36864]
"TomcatStartup"=C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe [2003-03-31 155648]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"KiesTrayAgent"=C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [2010-07-28 3365176]
"Regedit32"=C:\WINDOWS\system32\regedit.exe []
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2215064]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-11-11 1451520]
"BitTorrent DNA"=C:\Program Files\DNA\btdna.exe [2010-08-20 323392]
"KiesTrayAgent"= []
"viwynni"=C:\Documents and Settings\Bronislav Žáček\Data aplikací\Microsoft\buroutubi.exe []
"wuaucldt"=c:\documents and settings\bronislav Žáček\wuaucldt.exe []
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Online plug-in.lnk - C:\WINDOWS\Installer\{B8A2256E-6225-4D9E-B1C9-C26CA1E22FEB}\pnaico.exe.20FBBF0A_A7E5_4BDE_9798_9811C3D135AC.exe
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Documents and Settings\Bronislav Žáček\Nabídka Start\Programy\Po spuštění
703q0hc.exe
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
OpenOffice.org 3.2.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-03-29 126976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ckpNotify]
C:\WINDOWS\system32\ckpNotify.dll [2006-04-09 24674]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe:*:Enabled:VPN-1 SecuRemote/SecureClient service"
"C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.exe:*:Enabled:VPN-1 SecuRemote/SecureClient application"
"C:\Program Files\CheckPoint\SecuRemote\bin\scc.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\scc.exe:*:Enabled:VPN-1 SecuRemote/SecureClient command line"
"C:\Program Files\CheckPoint\SecuRemote\bin\SR_SDS.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\SR_SDS.exe:*:Enabled:VPN-1 SecuRemote/SecureClient SDS agent"
"C:\Program Files\CheckPoint\SecuRemote\bin\SR_Diagnostics.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\SR_Diagnostics.exe:*:Enabled:VPN-1 SecuRemote/SecureClient diagnostics"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\SJphone 1.65\SJphone.exe"="C:\Program Files\SJphone 1.65\SJphone.exe:*:Enabled:SJphone 1.65"
"E:\Chatování\Miranda IM\miranda32.exe"="E:\Chatování\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"E:\Miranda IM\miranda32.exe"="E:\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Documents and Settings\Tomáš Stojaník\Plocha\config.exe"="C:\Documents and Settings\Tomáš Stojaník\Plocha\config.exe:*:Enabled:Konfigurátor SGS Monitorů"
"C:\Documents and Settings\Bronislav Žáček\temp\TeamViewer\Version5\TeamViewer.exe"="C:\Documents and Settings\Bronislav Žáček\temp\TeamViewer\Version5\TeamViewer.exe:*:Enabled:TeamViewer"
"C:\Documents and Settings\Bronislav Žáček\Data aplikací\Microsoft\Internet Explorer\Quick Launch\config.exe"="C:\Documents and Settings\Bronislav Žáček\Data aplikací\Microsoft\Internet Explorer\Quick Launch\config.exe:*:Enabled:Konfigurátor SGS Monitorů"
"C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe"="C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe:*:Enabled:javaw"
"C:\Documents and Settings\Martin Bilík\Plocha\config.exe"="C:\Documents and Settings\Martin Bilík\Plocha\config.exe:*:Enabled:Konfigurátor SGS Monitorů"
"E:\Softík FL\Miranda IM\miranda32.exe"="E:\Softík FL\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Documents and Settings\Miroslav Turčínek\Plocha\config.exe"="C:\Documents and Settings\Miroslav Turčínek\Plocha\config.exe:*:Enabled:Konfigurátor SGS Monitorů"
"C:\Documents and Settings\Bronislav Žáček\Plocha\config.exe"="C:\Documents and Settings\Bronislav Žáček\Plocha\config.exe:*:Enabled:Konfigurátor SGS Monitorů"
"G:\Miranda IM\miranda32.exe"="G:\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA"
"C:\WINDOWS\system32\muzapp.exe"="C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player"
"E:\Chatování\Skype\Phone\Skype.exe"="E:\Chatování\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe:*:Enabled:VPN-1 SecuRemote/SecureClient service"
"C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.exe:*:Enabled:VPN-1 SecuRemote/SecureClient application"
"C:\Program Files\CheckPoint\SecuRemote\bin\scc.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\scc.exe:*:Enabled:VPN-1 SecuRemote/SecureClient command line"
"C:\Program Files\CheckPoint\SecuRemote\bin\SR_SDS.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\SR_SDS.exe:*:Enabled:VPN-1 SecuRemote/SecureClient SDS agent"
"C:\Program Files\CheckPoint\SecuRemote\bin\SR_Diagnostics.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\SR_Diagnostics.exe:*:Enabled:VPN-1 SecuRemote/SecureClient diagnostics"
======List of files/folders created in the last 2 months======
2010-09-13 16:30:45 ----D---- C:\Program Files\ESET
2010-09-13 16:30:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2010-09-13 11:02:10 ----SHD---- C:\$RECYCLE.BIN
2010-09-13 10:01:57 ----D---- C:\Program Files\CCleaner
2010-09-12 23:07:43 ----A---- C:\WINDOWS\system32\CF25374.exe
2010-09-12 22:22:18 ----A---- C:\WINDOWS\system32\CF16478.exe
2010-09-12 22:21:27 ----A---- C:\WINDOWS\system32\CF16312.exe
2010-09-12 21:59:37 ----A---- C:\WINDOWS\system32\CF12008.exe
2010-09-12 21:58:13 ----A---- C:\WINDOWS\system32\CF11747.exe
2010-09-12 21:57:31 ----A---- C:\WINDOWS\system32\CF11616.exe
2010-09-12 21:57:09 ----A---- C:\WINDOWS\system32\CF11485.exe
2010-09-12 20:55:20 ----D---- C:\WINDOWS\temp
2010-09-12 20:53:40 ----A---- C:\WINDOWS\system32\CF31867.exe
2010-09-12 20:52:00 ----A---- C:\WINDOWS\ntbtlog.txt
2010-09-12 20:45:55 ----A---- C:\WINDOWS\system32\CF30362.exe
2010-09-12 20:44:56 ----A---- C:\WINDOWS\system32\CF30169.exe
2010-09-12 20:44:16 ----A---- C:\WINDOWS\system32\CF30032.exe
2010-09-12 07:15:23 ----HDC---- C:\WINDOWS\ie8
2010-09-11 12:44:53 ----D---- C:\WINDOWS\ERDNT
2010-09-11 12:38:16 ----D---- C:\Qoobox
2010-09-05 02:57:14 ----D---- C:\Outlook záloha
2010-08-25 23:53:04 ----A---- C:\WINDOWS\system32\drivers\ssadmdfl.sys
2010-08-25 23:53:04 ----A---- C:\WINDOWS\system32\drivers\ssadcmnt.sys
2010-08-25 23:53:04 ----A---- C:\WINDOWS\system32\drivers\ssadcm.sys
2010-08-25 23:53:03 ----A---- C:\WINDOWS\system32\drivers\ssadmdm.sys
2010-08-25 23:53:01 ----A---- C:\WINDOWS\system32\drivers\ssadwhnt.sys
2010-08-25 23:53:01 ----A---- C:\WINDOWS\system32\drivers\ssadwh.sys
2010-08-25 23:53:01 ----A---- C:\WINDOWS\system32\drivers\ssadbus.sys
2010-08-25 23:51:43 ----A---- C:\WINDOWS\system32\FsUsbExService.Exe
2010-08-25 23:51:43 ----A---- C:\WINDOWS\system32\FsUsbExDisk.Sys
2010-08-25 23:51:43 ----A---- C:\WINDOWS\system32\FsUsbExDevice.Dll
2010-08-25 23:48:50 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\Samsung
2010-08-25 23:48:27 ----D---- C:\Program Files\MarkAny
2010-08-25 23:48:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\Samsung
2010-08-25 23:47:26 ----D---- C:\Program Files\Microsoft.NET
2010-08-25 23:44:27 ----N---- C:\WINDOWS\system32\SET353A.tmp
2010-08-25 23:44:26 ----N---- C:\WINDOWS\system32\SET3539.tmp
2010-08-25 23:44:26 ----N---- C:\WINDOWS\system32\SET3538.tmp
2010-08-25 23:44:26 ----D---- C:\3001944a79da2dc167
2010-08-25 23:42:24 ----SHD---- C:\Config.Msi
2010-08-25 23:40:29 ----D---- C:\9abd0e93463ab4957f491a
2010-08-25 23:09:59 ----D---- C:\Program Files\Samsung
2010-08-25 23:09:55 ----D---- C:\Program Files\Common Files\Samsung
2010-08-20 20:29:41 ----D---- C:\Program Files\DNA
2010-08-20 20:29:41 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\DNA
2010-08-14 21:34:06 ----D---- C:\Program Files\trend micro
2010-08-14 21:34:05 ----D---- C:\rsit
2010-08-13 06:13:43 ----D---- C:\Program Files\Common Files\Java
2010-08-13 06:13:21 ----A---- C:\WINDOWS\system32\javaws.exe
2010-08-13 06:13:21 ----A---- C:\WINDOWS\system32\javaw.exe
2010-08-13 06:13:21 ----A---- C:\WINDOWS\system32\java.exe
2010-08-08 15:52:09 ----D---- C:\spoolerlogs
2010-08-04 22:04:34 ----A---- C:\WINDOWS\system32\ptpusb.dll
2010-08-04 22:04:33 ----A---- C:\WINDOWS\system32\ptpusd.dll
2010-08-04 22:04:32 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys
2010-08-04 11:50:36 ----A---- C:\WINDOWS\system32\drivers\eamon.sys
2010-08-03 13:28:36 ----A---- C:\WINDOWS\system32\drivers\epfwtdir.sys
2010-07-29 13:31:26 ----A---- C:\WINDOWS\system32\drivers\ehdrv.sys
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\muzwmts.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\muzapp.exe
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\muzapp.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\muzaf1.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MTXSYNCICON.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MTTELECHIP.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MSLUR71.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MSFLib.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MSCLib.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MK_Lyric.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MaXMLProto.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MASetupCleaner.exe
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MASetupCaller.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MAMACExtract.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MaJGUILib.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MaDRM.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MACXMLProto.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\issacapi_se-2.3.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\issacapi_pe-2.3.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\issacapi_bs-2.3.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\cis-2.4.dll
2010-07-26 15:17:06 ----A---- C:\WINDOWS\system32\drivers\dgderdrv.sys
2010-07-26 15:17:06 ----A---- C:\WINDOWS\system32\DIFxAPI.dll
2010-07-26 15:17:06 ----A---- C:\WINDOWS\system32\dgdersvc.exe
2010-07-26 15:17:06 ----A---- C:\WINDOWS\system32\dgderapi.dll
2010-07-17 18:03:36 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\TrueCrypt
2010-07-17 18:00:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\TrueCrypt
2010-07-17 18:00:50 ----A---- C:\WINDOWS\system32\drivers\truecrypt.sys
2010-07-17 18:00:44 ----D---- C:\Program Files\TrueCrypt
2010-07-11 10:53:04 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\Digsby
2010-07-11 10:53:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\Digsby
2010-07-11 10:52:28 ----D---- C:\Program Files\Ask.com
2010-07-11 10:51:19 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\FCSB000062215
2010-07-11 10:51:01 ----D---- C:\Program Files\Digsby Donates
2010-07-02 16:22:26 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\gtk-2.0
2010-07-02 15:38:54 ----D---- C:\Program Files\GIMP-2.0
2010-07-01 06:09:21 ----D---- C:\Program Files\Common Files\Adobe
2010-07-01 06:09:21 ----D---- C:\Program Files\Adobe
2010-06-30 16:24:40 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\Real
2010-06-24 16:17:50 ----D---- C:\Program Files\Microsoft Silverlight
======List of files/folders modified in the last 2 months======
2010-09-14 18:32:19 ----A---- C:\WINDOWS\wincmd.ini
2010-09-14 18:15:52 ----SD---- C:\WINDOWS\Tasks
2010-09-14 06:51:30 ----D---- C:\WINDOWS\system32\CatRoot2
2010-09-13 16:31:20 ----SHD---- C:\WINDOWS\Installer
2010-09-13 16:31:13 ----HD---- C:\WINDOWS\inf
2010-09-13 16:31:13 ----D---- C:\WINDOWS\system32\drivers
2010-09-13 16:25:40 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-09-13 16:18:49 ----SHD---- C:\WINDOWS\CSC
2010-09-13 16:10:38 ----D---- C:\WINDOWS\system32
2010-09-13 09:33:35 ----SD---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\Microsoft
2010-09-12 22:35:14 ----D---- C:\WINDOWS\Help
2010-09-12 07:42:56 ----D---- C:\NVIDIA
2010-09-12 07:31:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-09-12 07:19:37 ----D---- C:\WINDOWS\system32\cs-cz
2010-09-12 07:19:37 ----D---- C:\Program Files\Internet Explorer
2010-09-12 07:18:18 ----HD---- C:\WINDOWS\$hf_mig$
2010-09-12 07:18:15 ----A---- C:\WINDOWS\imsins.BAK
2010-09-12 07:17:38 ----D---- C:\WINDOWS\ie8updates
2010-09-12 07:16:45 ----D---- C:\WINDOWS\WBEM
2010-09-12 07:16:37 ----D---- C:\WINDOWS\Media
2010-09-12 07:15:07 ----A---- C:\WINDOWS\system32\MRT.exe
2010-09-10 19:33:44 ----SHD---- C:\RECYCLER
2010-08-30 01:53:05 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\vlc
2010-08-26 02:07:43 ----D---- C:\WINDOWS\Microsoft.NET
2010-08-26 02:07:27 ----RSD---- C:\WINDOWS\assembly
2010-08-25 23:53:31 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-25 23:53:06 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-08-25 23:50:06 ----D---- C:\Program Files\PC Connectivity Solution
2010-08-25 23:47:45 ----D---- C:\WINDOWS\WinSxS
2010-08-25 23:47:40 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-08-25 23:45:30 ----D---- C:\WINDOWS\system32\XPSViewer
2010-08-25 23:45:28 ----D---- C:\WINDOWS\system32\en-us
2010-08-25 23:45:23 ----RSD---- C:\WINDOWS\Fonts
2010-08-25 23:43:36 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-08-25 23:09:55 ----D---- C:\Program Files\Common Files
2010-08-14 21:34:16 ----D---- C:\WINDOWS\Prefetch
2010-08-14 21:34:06 ----RD---- C:\Program Files
2010-08-14 21:32:51 ----D---- C:\WINDOWS
2010-08-14 19:25:15 ----D---- C:\Program Files\Mozilla Firefox
2010-08-14 19:05:30 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\OpenOffice.org2
2010-08-14 19:02:36 ----D---- C:\WINDOWS\system32\drivers\etc
2010-08-14 19:02:35 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-08-13 06:13:18 ----D---- C:\Program Files\Java
2010-08-06 06:04:19 ----D---- C:\Program Files\SJphone 1.65
2010-07-30 18:01:33 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-07-22 18:04:41 ----D---- C:\Documents and Settings
2010-07-22 18:03:34 ----A---- C:\WINDOWS\OEWABLog.txt
2010-07-18 21:03:31 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\DAEMON Tools Lite
2010-07-17 05:00:04 ----A---- C:\WINDOWS\system32\deployJava1.dll
2010-07-05 01:36:41 ----D---- C:\WINDOWS\system
2010-07-01 06:09:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-06-24 17:57:24 ----A---- C:\WINDOWS\system32\ieframe.dll
2010-06-24 16:17:59 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-06-24 14:27:28 ----A---- C:\WINDOWS\system32\wininet.dll
2010-06-24 14:27:28 ----A---- C:\WINDOWS\system32\urlmon.dll
2010-06-24 14:27:27 ----N---- C:\WINDOWS\system32\occache.dll
2010-06-24 14:27:27 ----N---- C:\WINDOWS\system32\mstime.dll
2010-06-24 14:27:26 ----A---- C:\WINDOWS\system32\mshtml.dll
2010-06-24 14:27:24 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2010-06-24 14:27:24 ----A---- C:\WINDOWS\system32\msfeeds.dll
2010-06-24 14:27:24 ----A---- C:\WINDOWS\system32\jsproxy.dll
2010-06-24 14:27:24 ----A---- C:\WINDOWS\system32\iertutil.dll
2010-06-24 14:27:23 ----N---- C:\WINDOWS\system32\iepeers.dll
2010-06-24 14:27:22 ----N---- C:\WINDOWS\system32\iedkcs32.dll
2010-06-23 14:08:09 ----N---- C:\WINDOWS\system32\ie4uinit.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-01-18 77696]
R1 ctxusbm;Citrix USB Monitor Driver; C:\WINDOWS\system32\DRIVERS\ctxusbm.sys [2009-09-08 65584]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2010-08-03 95896]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 truecrypt;truecrypt; C:\WINDOWS\System32\drivers\truecrypt.sys [2010-07-17 223440]
R1 VBoxDrv;VirtualBox Service; C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys [2010-03-25 123856]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [2010-03-25 41680]
R2 CP_OMDRV;Check Point Office Mode Module; C:\WINDOWS\System32\drivers\omdrv.sys [2006-04-09 36400]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2010-08-04 140752]
R2 VNASC;Check Point Virtual Network Adapter - SecureClient; C:\WINDOWS\system32\DRIVERS\vnasc.sys [2006-04-09 109072]
R2 vnccom;vnccom; C:\WINDOWS\System32\Drivers\vnccom.SYS [2004-06-26 6016]
R2 VPN-1;VPN-1 Module; C:\WINDOWS\System32\drivers\vpn.sys [2006-04-09 671472]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l151x86.sys [2008-11-12 37376]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-03-29 2873856]
R3 dgderdrv;dgderdrv; C:\WINDOWS\System32\drivers\dgderdrv.sys [2010-07-26 18136]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 FW1;SecuRemote Miniport; C:\WINDOWS\system32\DRIVERS\fw.sys [2006-04-09 2234320]
R3 HdAudAddService;ATI Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\AtiHdAud.sys [2006-12-29 84992]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-11-01 4620288]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 VBoxNetFlt;VBoxNetFlt Service; C:\WINDOWS\system32\DRIVERS\VBoxNetFlt.sys [2010-03-25 110608]
R3 vncdrv;vncdrv; C:\WINDOWS\system32\DRIVERS\vncdrv.sys [2004-06-26 4736]
S0 cerc6;cerc6; C:\WINDOWS\system32\drivers\cerc6.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-14 17024]
S3 BTHMODEM;Ovladač komunikace modemu Bluetooth; C:\WINDOWS\system32\DRIVERS\bthmodem.sys [2008-04-14 37888]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-14 101120]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-14 18944]
S3 catchme;catchme; \??\C:\DOCUME~1\TOMSTO~1\LOCALS~1\Temp\catchme.sys []
S3 Dot4;Ovladač MS IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-14 206976]
S3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-10-24 23808]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-14 59136]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\ssadbus.sys [2010-06-21 96488]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\WINDOWS\system32\DRIVERS\ssadmdfl.sys [2010-06-21 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\WINDOWS\system32\DRIVERS\ssadmdm.sys [2010-06-21 121576]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp.sys [2010-03-25 99728]
S3 VBoxUSB;VirtualBox USB; C:\WINDOWS\System32\Drivers\VBoxUSB.sys [2010-03-25 31824]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-05-12 691696]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-03-29 536576]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 dgdersvc;Device Error Recovery Service; C:\WINDOWS\system32\dgdersvc.exe [2010-07-26 95568]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-08-12 810144]
R2 FsUsbExService;FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [2010-07-26 217088]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-07-17 153376]
R2 SR_Service;Check Point SecuRemote Service; C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe [2006-04-09 110691]
R2 SR_WatchDog;Check Point SecuRemote WatchDog; C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe [2006-04-09 36964]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-10-27 657408]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-03-28 593920]
S2 ekeiidyko6koty;PowerUtility TV Recording Reservation; C:\WINDOWS\system32\weda.exe []
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-08-12 33584]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2002-08-01 65536]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Antivirový program Eset nod antivirus 4.2 mi hlásí infiltraci Protector.N virus v souboru C:\Windows\system32\drivers\cdrom.sys. komentář k nálezu...... Tato skutečnost byla zjištěna při pokusu o přístup k souboru aplikací: C:\Windows\system32\svchost.exe. Vir je uložen v karanténě, nicméně stále mi vyskakuje hlášení Nodu o infiltraci. PC je dosti zpomalené a při některých úkolech na chvíli zamrzá. Dále byly nalezeny další nakažené soubory Trojským koněm, které se jak doufám podařilo vyléčit, či odstranit. Zkoušel jsem aplikovat program Conbofix, ale po spuštění se sám vypne a smaže. Přejměnování na grinder.com nepomohlo a situace se opakuje. Můžete mi prosím pomoci s řešením problému? Předem mnohokrát děkuji. Přikládám Log programu RSIT.
Logfile of random's system information tool 1.08 (written by random/random)
Run by Bronislav Žáček at 2010-08-14 21:34:05
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 114 GB (78%) free of 147 GB
Total RAM: 2047 MB (67% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:34:20, on 14.8.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\dgdersvc.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Citrix\ICA Client\concentr.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Citrix\ICA Client\WFCRUN32.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Citrix\ICA Client\PNAMAIN.EXE
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Bronislav Žáček\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Bronislav Žáček\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Bronislav Žáček\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Bronislav Žáček\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Bronislav Žáček\Dokumenty\Downloads\RSIT.exe
C:\WINDOWS\system32\HPBPRO.EXE
C:\Program Files\trend micro\Bronislav Žáček.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://10.1.112.9/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 217.112.175.67:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.1.1.171;172.22.4.31:8080;10.1.112.3;synot-sd;10.1.29.187;10.1.112.9;maxpower.gamemonitoring.cz;80.251.247.117;citrix-web;10.1.29.*;10.1.1.170;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Freecause Shopping BHO - {998A3C0C-8914-4D2A-AE36-BFA2E5AE6D5D} - C:\Program Files\Digsby Donates\ShoppingBHO.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Digsby Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [viwynni] C:\Documents and Settings\Bronislav Žáček\Data aplikací\Microsoft\buroutubi.exe
O4 - HKCU\..\Run: [wuaucldt] c:\documents and settings\bronislav Žáček\wuaucldt.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: 703q0hc.exe
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Online plug-in.lnk = ?
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 3831363431
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{71C0ACB6-A81D-485C-A092-8C227CDC6015}: NameServer = 10.1.29.132,10.1.29.133
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Device Error Recovery Service (dgdersvc) - Devguru Co., Ltd. - C:\WINDOWS\system32\dgdersvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: PowerUtility TV Recording Reservation (ekeiidyko6koty) - Unknown owner - C:\WINDOWS\system32\weda.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
--
End of file - 9856 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{5FBF80ED-672D-4256-B380-FD88BB024233}.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{E7CA6F26-AD3A-4ECD-ACAD-7C779DAE33F7}.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{FB2531FB-FAEE-437E-A52B-003A43ED731D}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{998A3C0C-8914-4D2A-AE36-BFA2E5AE6D5D}]
Digsby Donates - C:\Program Files\Digsby Donates\ShoppingBHO.dll [2010-07-11 638976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Digsby Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-07-10 1174920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-04 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Digsby Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-07-10 1174920]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-10-25 16855552]
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2007-10-11 1826816]
"ConnectionCenter"=C:\Program Files\Citrix\ICA Client\concentr.exe [2009-09-12 103768]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"StatusClient"=C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe [2002-12-16 36864]
"TomcatStartup"=C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe [2003-03-31 155648]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"KiesTrayAgent"=C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [2010-07-28 3365176]
"Regedit32"=C:\WINDOWS\system32\regedit.exe []
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2215064]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-11-11 1451520]
"BitTorrent DNA"=C:\Program Files\DNA\btdna.exe [2010-08-20 323392]
"KiesTrayAgent"= []
"viwynni"=C:\Documents and Settings\Bronislav Žáček\Data aplikací\Microsoft\buroutubi.exe []
"wuaucldt"=c:\documents and settings\bronislav Žáček\wuaucldt.exe []
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Online plug-in.lnk - C:\WINDOWS\Installer\{B8A2256E-6225-4D9E-B1C9-C26CA1E22FEB}\pnaico.exe.20FBBF0A_A7E5_4BDE_9798_9811C3D135AC.exe
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Documents and Settings\Bronislav Žáček\Nabídka Start\Programy\Po spuštění
703q0hc.exe
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
OpenOffice.org 3.2.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-03-29 126976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ckpNotify]
C:\WINDOWS\system32\ckpNotify.dll [2006-04-09 24674]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe:*:Enabled:VPN-1 SecuRemote/SecureClient service"
"C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.exe:*:Enabled:VPN-1 SecuRemote/SecureClient application"
"C:\Program Files\CheckPoint\SecuRemote\bin\scc.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\scc.exe:*:Enabled:VPN-1 SecuRemote/SecureClient command line"
"C:\Program Files\CheckPoint\SecuRemote\bin\SR_SDS.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\SR_SDS.exe:*:Enabled:VPN-1 SecuRemote/SecureClient SDS agent"
"C:\Program Files\CheckPoint\SecuRemote\bin\SR_Diagnostics.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\SR_Diagnostics.exe:*:Enabled:VPN-1 SecuRemote/SecureClient diagnostics"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\SJphone 1.65\SJphone.exe"="C:\Program Files\SJphone 1.65\SJphone.exe:*:Enabled:SJphone 1.65"
"E:\Chatování\Miranda IM\miranda32.exe"="E:\Chatování\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"E:\Miranda IM\miranda32.exe"="E:\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Documents and Settings\Tomáš Stojaník\Plocha\config.exe"="C:\Documents and Settings\Tomáš Stojaník\Plocha\config.exe:*:Enabled:Konfigurátor SGS Monitorů"
"C:\Documents and Settings\Bronislav Žáček\temp\TeamViewer\Version5\TeamViewer.exe"="C:\Documents and Settings\Bronislav Žáček\temp\TeamViewer\Version5\TeamViewer.exe:*:Enabled:TeamViewer"
"C:\Documents and Settings\Bronislav Žáček\Data aplikací\Microsoft\Internet Explorer\Quick Launch\config.exe"="C:\Documents and Settings\Bronislav Žáček\Data aplikací\Microsoft\Internet Explorer\Quick Launch\config.exe:*:Enabled:Konfigurátor SGS Monitorů"
"C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe"="C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe:*:Enabled:javaw"
"C:\Documents and Settings\Martin Bilík\Plocha\config.exe"="C:\Documents and Settings\Martin Bilík\Plocha\config.exe:*:Enabled:Konfigurátor SGS Monitorů"
"E:\Softík FL\Miranda IM\miranda32.exe"="E:\Softík FL\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Documents and Settings\Miroslav Turčínek\Plocha\config.exe"="C:\Documents and Settings\Miroslav Turčínek\Plocha\config.exe:*:Enabled:Konfigurátor SGS Monitorů"
"C:\Documents and Settings\Bronislav Žáček\Plocha\config.exe"="C:\Documents and Settings\Bronislav Žáček\Plocha\config.exe:*:Enabled:Konfigurátor SGS Monitorů"
"G:\Miranda IM\miranda32.exe"="G:\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA"
"C:\WINDOWS\system32\muzapp.exe"="C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player"
"E:\Chatování\Skype\Phone\Skype.exe"="E:\Chatování\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe:*:Enabled:VPN-1 SecuRemote/SecureClient service"
"C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.exe:*:Enabled:VPN-1 SecuRemote/SecureClient application"
"C:\Program Files\CheckPoint\SecuRemote\bin\scc.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\scc.exe:*:Enabled:VPN-1 SecuRemote/SecureClient command line"
"C:\Program Files\CheckPoint\SecuRemote\bin\SR_SDS.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\SR_SDS.exe:*:Enabled:VPN-1 SecuRemote/SecureClient SDS agent"
"C:\Program Files\CheckPoint\SecuRemote\bin\SR_Diagnostics.exe"="C:\Program Files\CheckPoint\SecuRemote\bin\SR_Diagnostics.exe:*:Enabled:VPN-1 SecuRemote/SecureClient diagnostics"
======List of files/folders created in the last 2 months======
2010-09-13 16:30:45 ----D---- C:\Program Files\ESET
2010-09-13 16:30:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2010-09-13 11:02:10 ----SHD---- C:\$RECYCLE.BIN
2010-09-13 10:01:57 ----D---- C:\Program Files\CCleaner
2010-09-12 23:07:43 ----A---- C:\WINDOWS\system32\CF25374.exe
2010-09-12 22:22:18 ----A---- C:\WINDOWS\system32\CF16478.exe
2010-09-12 22:21:27 ----A---- C:\WINDOWS\system32\CF16312.exe
2010-09-12 21:59:37 ----A---- C:\WINDOWS\system32\CF12008.exe
2010-09-12 21:58:13 ----A---- C:\WINDOWS\system32\CF11747.exe
2010-09-12 21:57:31 ----A---- C:\WINDOWS\system32\CF11616.exe
2010-09-12 21:57:09 ----A---- C:\WINDOWS\system32\CF11485.exe
2010-09-12 20:55:20 ----D---- C:\WINDOWS\temp
2010-09-12 20:53:40 ----A---- C:\WINDOWS\system32\CF31867.exe
2010-09-12 20:52:00 ----A---- C:\WINDOWS\ntbtlog.txt
2010-09-12 20:45:55 ----A---- C:\WINDOWS\system32\CF30362.exe
2010-09-12 20:44:56 ----A---- C:\WINDOWS\system32\CF30169.exe
2010-09-12 20:44:16 ----A---- C:\WINDOWS\system32\CF30032.exe
2010-09-12 07:15:23 ----HDC---- C:\WINDOWS\ie8
2010-09-11 12:44:53 ----D---- C:\WINDOWS\ERDNT
2010-09-11 12:38:16 ----D---- C:\Qoobox
2010-09-05 02:57:14 ----D---- C:\Outlook záloha
2010-08-25 23:53:04 ----A---- C:\WINDOWS\system32\drivers\ssadmdfl.sys
2010-08-25 23:53:04 ----A---- C:\WINDOWS\system32\drivers\ssadcmnt.sys
2010-08-25 23:53:04 ----A---- C:\WINDOWS\system32\drivers\ssadcm.sys
2010-08-25 23:53:03 ----A---- C:\WINDOWS\system32\drivers\ssadmdm.sys
2010-08-25 23:53:01 ----A---- C:\WINDOWS\system32\drivers\ssadwhnt.sys
2010-08-25 23:53:01 ----A---- C:\WINDOWS\system32\drivers\ssadwh.sys
2010-08-25 23:53:01 ----A---- C:\WINDOWS\system32\drivers\ssadbus.sys
2010-08-25 23:51:43 ----A---- C:\WINDOWS\system32\FsUsbExService.Exe
2010-08-25 23:51:43 ----A---- C:\WINDOWS\system32\FsUsbExDisk.Sys
2010-08-25 23:51:43 ----A---- C:\WINDOWS\system32\FsUsbExDevice.Dll
2010-08-25 23:48:50 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\Samsung
2010-08-25 23:48:27 ----D---- C:\Program Files\MarkAny
2010-08-25 23:48:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\Samsung
2010-08-25 23:47:26 ----D---- C:\Program Files\Microsoft.NET
2010-08-25 23:44:27 ----N---- C:\WINDOWS\system32\SET353A.tmp
2010-08-25 23:44:26 ----N---- C:\WINDOWS\system32\SET3539.tmp
2010-08-25 23:44:26 ----N---- C:\WINDOWS\system32\SET3538.tmp
2010-08-25 23:44:26 ----D---- C:\3001944a79da2dc167
2010-08-25 23:42:24 ----SHD---- C:\Config.Msi
2010-08-25 23:40:29 ----D---- C:\9abd0e93463ab4957f491a
2010-08-25 23:09:59 ----D---- C:\Program Files\Samsung
2010-08-25 23:09:55 ----D---- C:\Program Files\Common Files\Samsung
2010-08-20 20:29:41 ----D---- C:\Program Files\DNA
2010-08-20 20:29:41 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\DNA
2010-08-14 21:34:06 ----D---- C:\Program Files\trend micro
2010-08-14 21:34:05 ----D---- C:\rsit
2010-08-13 06:13:43 ----D---- C:\Program Files\Common Files\Java
2010-08-13 06:13:21 ----A---- C:\WINDOWS\system32\javaws.exe
2010-08-13 06:13:21 ----A---- C:\WINDOWS\system32\javaw.exe
2010-08-13 06:13:21 ----A---- C:\WINDOWS\system32\java.exe
2010-08-08 15:52:09 ----D---- C:\spoolerlogs
2010-08-04 22:04:34 ----A---- C:\WINDOWS\system32\ptpusb.dll
2010-08-04 22:04:33 ----A---- C:\WINDOWS\system32\ptpusd.dll
2010-08-04 22:04:32 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys
2010-08-04 11:50:36 ----A---- C:\WINDOWS\system32\drivers\eamon.sys
2010-08-03 13:28:36 ----A---- C:\WINDOWS\system32\drivers\epfwtdir.sys
2010-07-29 13:31:26 ----A---- C:\WINDOWS\system32\drivers\ehdrv.sys
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\muzwmts.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\muzapp.exe
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\muzapp.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\muzaf1.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MTXSYNCICON.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MTTELECHIP.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MSLUR71.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MSFLib.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MSCLib.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MK_Lyric.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MaXMLProto.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MASetupCleaner.exe
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MASetupCaller.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MAMACExtract.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MaJGUILib.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MaDRM.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\MACXMLProto.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\issacapi_se-2.3.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\issacapi_pe-2.3.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\issacapi_bs-2.3.dll
2010-07-26 15:18:38 ----A---- C:\WINDOWS\system32\cis-2.4.dll
2010-07-26 15:17:06 ----A---- C:\WINDOWS\system32\drivers\dgderdrv.sys
2010-07-26 15:17:06 ----A---- C:\WINDOWS\system32\DIFxAPI.dll
2010-07-26 15:17:06 ----A---- C:\WINDOWS\system32\dgdersvc.exe
2010-07-26 15:17:06 ----A---- C:\WINDOWS\system32\dgderapi.dll
2010-07-17 18:03:36 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\TrueCrypt
2010-07-17 18:00:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\TrueCrypt
2010-07-17 18:00:50 ----A---- C:\WINDOWS\system32\drivers\truecrypt.sys
2010-07-17 18:00:44 ----D---- C:\Program Files\TrueCrypt
2010-07-11 10:53:04 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\Digsby
2010-07-11 10:53:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\Digsby
2010-07-11 10:52:28 ----D---- C:\Program Files\Ask.com
2010-07-11 10:51:19 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\FCSB000062215
2010-07-11 10:51:01 ----D---- C:\Program Files\Digsby Donates
2010-07-02 16:22:26 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\gtk-2.0
2010-07-02 15:38:54 ----D---- C:\Program Files\GIMP-2.0
2010-07-01 06:09:21 ----D---- C:\Program Files\Common Files\Adobe
2010-07-01 06:09:21 ----D---- C:\Program Files\Adobe
2010-06-30 16:24:40 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\Real
2010-06-24 16:17:50 ----D---- C:\Program Files\Microsoft Silverlight
======List of files/folders modified in the last 2 months======
2010-09-14 18:32:19 ----A---- C:\WINDOWS\wincmd.ini
2010-09-14 18:15:52 ----SD---- C:\WINDOWS\Tasks
2010-09-14 06:51:30 ----D---- C:\WINDOWS\system32\CatRoot2
2010-09-13 16:31:20 ----SHD---- C:\WINDOWS\Installer
2010-09-13 16:31:13 ----HD---- C:\WINDOWS\inf
2010-09-13 16:31:13 ----D---- C:\WINDOWS\system32\drivers
2010-09-13 16:25:40 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-09-13 16:18:49 ----SHD---- C:\WINDOWS\CSC
2010-09-13 16:10:38 ----D---- C:\WINDOWS\system32
2010-09-13 09:33:35 ----SD---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\Microsoft
2010-09-12 22:35:14 ----D---- C:\WINDOWS\Help
2010-09-12 07:42:56 ----D---- C:\NVIDIA
2010-09-12 07:31:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-09-12 07:19:37 ----D---- C:\WINDOWS\system32\cs-cz
2010-09-12 07:19:37 ----D---- C:\Program Files\Internet Explorer
2010-09-12 07:18:18 ----HD---- C:\WINDOWS\$hf_mig$
2010-09-12 07:18:15 ----A---- C:\WINDOWS\imsins.BAK
2010-09-12 07:17:38 ----D---- C:\WINDOWS\ie8updates
2010-09-12 07:16:45 ----D---- C:\WINDOWS\WBEM
2010-09-12 07:16:37 ----D---- C:\WINDOWS\Media
2010-09-12 07:15:07 ----A---- C:\WINDOWS\system32\MRT.exe
2010-09-10 19:33:44 ----SHD---- C:\RECYCLER
2010-08-30 01:53:05 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\vlc
2010-08-26 02:07:43 ----D---- C:\WINDOWS\Microsoft.NET
2010-08-26 02:07:27 ----RSD---- C:\WINDOWS\assembly
2010-08-25 23:53:31 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-25 23:53:06 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-08-25 23:50:06 ----D---- C:\Program Files\PC Connectivity Solution
2010-08-25 23:47:45 ----D---- C:\WINDOWS\WinSxS
2010-08-25 23:47:40 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-08-25 23:45:30 ----D---- C:\WINDOWS\system32\XPSViewer
2010-08-25 23:45:28 ----D---- C:\WINDOWS\system32\en-us
2010-08-25 23:45:23 ----RSD---- C:\WINDOWS\Fonts
2010-08-25 23:43:36 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-08-25 23:09:55 ----D---- C:\Program Files\Common Files
2010-08-14 21:34:16 ----D---- C:\WINDOWS\Prefetch
2010-08-14 21:34:06 ----RD---- C:\Program Files
2010-08-14 21:32:51 ----D---- C:\WINDOWS
2010-08-14 19:25:15 ----D---- C:\Program Files\Mozilla Firefox
2010-08-14 19:05:30 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\OpenOffice.org2
2010-08-14 19:02:36 ----D---- C:\WINDOWS\system32\drivers\etc
2010-08-14 19:02:35 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-08-13 06:13:18 ----D---- C:\Program Files\Java
2010-08-06 06:04:19 ----D---- C:\Program Files\SJphone 1.65
2010-07-30 18:01:33 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-07-22 18:04:41 ----D---- C:\Documents and Settings
2010-07-22 18:03:34 ----A---- C:\WINDOWS\OEWABLog.txt
2010-07-18 21:03:31 ----D---- C:\Documents and Settings\Bronislav Žáček\Data aplikací\DAEMON Tools Lite
2010-07-17 05:00:04 ----A---- C:\WINDOWS\system32\deployJava1.dll
2010-07-05 01:36:41 ----D---- C:\WINDOWS\system
2010-07-01 06:09:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-06-24 17:57:24 ----A---- C:\WINDOWS\system32\ieframe.dll
2010-06-24 16:17:59 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-06-24 14:27:28 ----A---- C:\WINDOWS\system32\wininet.dll
2010-06-24 14:27:28 ----A---- C:\WINDOWS\system32\urlmon.dll
2010-06-24 14:27:27 ----N---- C:\WINDOWS\system32\occache.dll
2010-06-24 14:27:27 ----N---- C:\WINDOWS\system32\mstime.dll
2010-06-24 14:27:26 ----A---- C:\WINDOWS\system32\mshtml.dll
2010-06-24 14:27:24 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2010-06-24 14:27:24 ----A---- C:\WINDOWS\system32\msfeeds.dll
2010-06-24 14:27:24 ----A---- C:\WINDOWS\system32\jsproxy.dll
2010-06-24 14:27:24 ----A---- C:\WINDOWS\system32\iertutil.dll
2010-06-24 14:27:23 ----N---- C:\WINDOWS\system32\iepeers.dll
2010-06-24 14:27:22 ----N---- C:\WINDOWS\system32\iedkcs32.dll
2010-06-23 14:08:09 ----N---- C:\WINDOWS\system32\ie4uinit.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-01-18 77696]
R1 ctxusbm;Citrix USB Monitor Driver; C:\WINDOWS\system32\DRIVERS\ctxusbm.sys [2009-09-08 65584]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2010-08-03 95896]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 truecrypt;truecrypt; C:\WINDOWS\System32\drivers\truecrypt.sys [2010-07-17 223440]
R1 VBoxDrv;VirtualBox Service; C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys [2010-03-25 123856]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [2010-03-25 41680]
R2 CP_OMDRV;Check Point Office Mode Module; C:\WINDOWS\System32\drivers\omdrv.sys [2006-04-09 36400]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2010-08-04 140752]
R2 VNASC;Check Point Virtual Network Adapter - SecureClient; C:\WINDOWS\system32\DRIVERS\vnasc.sys [2006-04-09 109072]
R2 vnccom;vnccom; C:\WINDOWS\System32\Drivers\vnccom.SYS [2004-06-26 6016]
R2 VPN-1;VPN-1 Module; C:\WINDOWS\System32\drivers\vpn.sys [2006-04-09 671472]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l151x86.sys [2008-11-12 37376]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-03-29 2873856]
R3 dgderdrv;dgderdrv; C:\WINDOWS\System32\drivers\dgderdrv.sys [2010-07-26 18136]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 FW1;SecuRemote Miniport; C:\WINDOWS\system32\DRIVERS\fw.sys [2006-04-09 2234320]
R3 HdAudAddService;ATI Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\AtiHdAud.sys [2006-12-29 84992]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-11-01 4620288]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 VBoxNetFlt;VBoxNetFlt Service; C:\WINDOWS\system32\DRIVERS\VBoxNetFlt.sys [2010-03-25 110608]
R3 vncdrv;vncdrv; C:\WINDOWS\system32\DRIVERS\vncdrv.sys [2004-06-26 4736]
S0 cerc6;cerc6; C:\WINDOWS\system32\drivers\cerc6.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-14 17024]
S3 BTHMODEM;Ovladač komunikace modemu Bluetooth; C:\WINDOWS\system32\DRIVERS\bthmodem.sys [2008-04-14 37888]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-14 101120]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-14 18944]
S3 catchme;catchme; \??\C:\DOCUME~1\TOMSTO~1\LOCALS~1\Temp\catchme.sys []
S3 Dot4;Ovladač MS IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-14 206976]
S3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-10-24 23808]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-14 59136]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\ssadbus.sys [2010-06-21 96488]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\WINDOWS\system32\DRIVERS\ssadmdfl.sys [2010-06-21 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\WINDOWS\system32\DRIVERS\ssadmdm.sys [2010-06-21 121576]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp.sys [2010-03-25 99728]
S3 VBoxUSB;VirtualBox USB; C:\WINDOWS\System32\Drivers\VBoxUSB.sys [2010-03-25 31824]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-05-12 691696]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-03-29 536576]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 dgdersvc;Device Error Recovery Service; C:\WINDOWS\system32\dgdersvc.exe [2010-07-26 95568]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-08-12 810144]
R2 FsUsbExService;FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [2010-07-26 217088]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-07-17 153376]
R2 SR_Service;Check Point SecuRemote Service; C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe [2006-04-09 110691]
R2 SR_WatchDog;Check Point SecuRemote WatchDog; C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe [2006-04-09 36964]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-10-27 657408]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-03-28 593920]
S2 ekeiidyko6koty;PowerUtility TV Recording Reservation; C:\WINDOWS\system32\weda.exe []
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-08-12 33584]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2002-08-01 65536]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------