Prosím preventivku
Napsal: 02 lis 2010 12:54
V poslednom čase sa môj počítač správa akosi inač, tak by som chcel preventivku, či to ne nejaká háveď, alebo len comp strárne. PS. pred pár dňami som omylom klikol na jeden vir, ale mozilla ma nepustila, ale eset vir nasiel.
Ďakujem.
Logfile of random's system information tool 1.08 (written by random/random)
Run by Jojo at 2010-11-02 12:57:01
Microsoft Windows 7 Home Premium
System drive C: has 21 GB (21%) free of 100 GB
Total RAM: 3326 MB (65% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:57:05, on 2. 11. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\ICQ6.5\ICQ.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Rockstar Games\Rockstar Games Social Club\1_0_0_0\RGSC.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe
C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Rockstar Games\GTA San Andreas 2\samp.exe
C:\Users\Jojo\Downloads\RSIT.exe
C:\Program Files\trend micro\Jojo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1708250
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Free Lunch Design Toolbar - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFree.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Free Lunch Design Toolbar - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFree.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: Free Lunch Design Toolbar - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFree.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [reset] regedit /s reset.reg
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: RollerCoaster Tycoon 3 Registration.lnk = Jojo\AppData\Local\Temp\{6D335775-A22E-46F5-BC63-68B659261B7B}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{92EAFE1C-75B1-46F8-8050-65FEB530FAC5}: NameServer = 172.16.0.2,195.168.1.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{92EAFE1C-75B1-46F8-8050-65FEB530FAC5}: NameServer = 172.16.0.2,195.168.1.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{92EAFE1C-75B1-46F8-8050-65FEB530FAC5}: NameServer = 172.16.0.2,195.168.1.4
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
--
End of file - 8293 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21 328248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
Free Lunch Design Toolbar - C:\Program Files\Free_Lunch_Design\tbFree.dll [2009-05-20 2085400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-09-15 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21 509496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2009-06-01 962808]
{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - Free Lunch Design Toolbar - C:\Program Files\Free_Lunch_Design\tbFree.dll [2009-05-20 2085400]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-06-25 7547424]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"VirtualCloneDrive"=C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2004-08-20 45056]
"reset"=regedit /s reset.reg []
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-02-26 2140880]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-09-02 13351304]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"RGSC"=C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe [2008-11-14 305064]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Users\Jojo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
RollerCoaster Tycoon 3 Registration.lnk - C:\Users\Jojo\AppData\Local\Temp\{6D335775-A22E-46F5-BC63-68B659261B7B}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-11-01 22:57:54 ----A---- C:\Windows\system32\javaws.exe
2010-11-01 22:57:54 ----A---- C:\Windows\system32\javaw.exe
2010-11-01 22:57:54 ----A---- C:\Windows\system32\java.exe
2010-10-27 16:47:49 ----A---- C:\Windows\system32\D3DX9_42.dll
2010-10-27 16:47:49 ----A---- C:\Windows\system32\d3dx10_42.dll
2010-10-27 06:06:07 ----A---- C:\Windows\system32\msdri.dll
2010-10-27 06:06:07 ----A---- C:\Windows\system32\CPFilters.dll
2010-10-27 06:06:02 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2010-10-26 13:46:46 ----D---- C:\Program Files\Algodoo Phun Edition
2010-10-25 17:51:19 ----A---- C:\Windows\system32\mfc71.dll
2010-10-25 17:49:59 ----A---- C:\Windows\system32\CmdLineExt.dll
2010-10-25 17:33:38 ----A---- C:\Windows\system32\XAudio2_1.dll
2010-10-25 17:33:38 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2010-10-25 17:33:38 ----A---- C:\Windows\system32\xactengine3_1.dll
2010-10-25 17:33:38 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2010-10-25 17:33:38 ----A---- C:\Windows\system32\D3DX9_38.dll
2010-10-25 17:33:38 ----A---- C:\Windows\system32\d3dx10_38.dll
2010-10-25 17:33:38 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2010-10-25 17:33:37 ----A---- C:\Windows\system32\XAudio2_0.dll
2010-10-25 17:33:37 ----A---- C:\Windows\system32\xactengine3_0.dll
2010-10-25 17:33:37 ----A---- C:\Windows\system32\xactengine2_10.dll
2010-10-25 17:33:37 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2010-10-25 17:33:37 ----A---- C:\Windows\system32\d3dx9_36.dll
2010-10-25 17:33:37 ----A---- C:\Windows\system32\d3dx10_36.dll
2010-10-25 17:33:37 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2010-10-25 17:33:36 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2010-10-25 17:19:03 ----A---- C:\Windows\system32\D3DX9_37.dll
2010-10-25 17:19:03 ----A---- C:\Windows\system32\d3dx10_37.dll
2010-10-25 17:19:03 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2010-10-25 17:18:42 ----D---- C:\Windows\system32\xlive
2010-10-25 17:18:42 ----D---- C:\Program Files\Microsoft Games for Windows - LIVE
2010-10-18 13:42:14 ----D---- C:\ProgramData\WEBREG
2010-10-18 13:34:16 ----D---- C:\ProgramData\HP Product Assistant
2010-10-18 13:33:11 ----D---- C:\Program Files\Common Files\HP
2010-10-18 13:32:54 ----D---- C:\Program Files\Common Files\Hewlett-Packard
2010-10-18 13:31:59 ----A---- C:\Windows\system32\hposwia_d02c.dll
2010-10-18 13:31:59 ----A---- C:\Windows\system32\hpost_d02c.dll
2010-10-18 13:31:59 ----A---- C:\Windows\system32\hposc_d02a.dll
2010-10-18 13:31:55 ----A---- C:\Windows\system32\hppldcoi.dll
2010-10-18 13:31:53 ----A---- C:\Windows\system32\hpzids01.dll
2010-10-18 13:31:50 ----A---- C:\Windows\system32\hpf3l70v.dll
2010-10-18 13:31:09 ----HD---- C:\Config.Msi
2010-10-18 13:29:42 ----D---- C:\Program Files\HP
2010-10-18 13:12:07 ----D---- C:\ProgramData\HP
2010-10-14 14:45:07 ----A---- C:\Windows\system32\ole32.dll
2010-10-14 14:45:02 ----A---- C:\Windows\system32\iertutil.dll
2010-10-14 14:45:01 ----A---- C:\Windows\system32\mshtml.dll
2010-10-14 14:44:59 ----A---- C:\Windows\system32\msfeeds.dll
2010-10-14 14:44:59 ----A---- C:\Windows\system32\ieframe.dll
2010-10-14 14:44:58 ----A---- C:\Windows\system32\wininet.dll
2010-10-14 14:44:58 ----A---- C:\Windows\system32\urlmon.dll
2010-10-14 14:44:58 ----A---- C:\Windows\system32\mstime.dll
2010-10-14 14:44:58 ----A---- C:\Windows\system32\licmgr10.dll
2010-10-14 14:44:58 ----A---- C:\Windows\system32\iedkcs32.dll
2010-10-14 14:44:57 ----A---- C:\Windows\system32\mshtmled.dll
2010-10-14 14:44:57 ----A---- C:\Windows\system32\msfeedssync.exe
2010-10-14 14:44:57 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-10-14 14:44:57 ----A---- C:\Windows\system32\jsproxy.dll
2010-10-14 14:44:57 ----A---- C:\Windows\system32\ieui.dll
2010-10-14 14:44:57 ----A---- C:\Windows\system32\iepeers.dll
2010-10-14 14:44:55 ----A---- C:\Windows\system32\t2embed.dll
2010-10-14 14:44:54 ----A---- C:\Windows\system32\schannel.dll
2010-10-14 14:44:53 ----A---- C:\Windows\system32\comctl32.dll
2010-10-14 14:44:52 ----A---- C:\Windows\system32\mfc40u.dll
2010-10-14 14:44:52 ----A---- C:\Windows\system32\mfc40.dll
2010-10-14 14:44:46 ----A---- C:\Windows\system32\wmp.dll
2010-10-14 14:44:45 ----A---- C:\Windows\system32\wmploc.DLL
2010-10-14 14:44:45 ----A---- C:\Windows\system32\win32k.sys
2010-10-14 14:44:44 ----A---- C:\Windows\system32\srvsvc.dll
2010-10-14 14:44:44 ----A---- C:\Windows\system32\drivers\srvnet.sys
2010-10-14 14:44:44 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-10-14 14:44:44 ----A---- C:\Windows\system32\drivers\srv.sys
2010-10-14 14:44:43 ----A---- C:\Windows\system32\wmpmde.dll
2010-10-14 14:44:43 ----A---- C:\Windows\system32\StructuredQuery.dll
2010-10-08 16:37:06 ----D---- C:\Program Files\MTA San Andreas
======List of files/folders modified in the last 1 months======
2010-11-02 12:57:05 ----D---- C:\Windows\Temp
2010-11-02 12:57:05 ----D---- C:\Program Files\trend micro
2010-11-02 12:55:14 ----D---- C:\Users\Jojo\AppData\Roaming\Skype
2010-11-02 12:45:30 ----D---- C:\Windows\system32\config
2010-11-02 12:31:24 ----D---- C:\Windows\System32
2010-11-02 12:31:24 ----D---- C:\Windows\inf
2010-11-02 12:31:24 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-11-02 12:27:02 ----D---- C:\ProgramData\NVIDIA
2010-11-02 11:37:53 ----D---- C:\Users\Jojo\AppData\Roaming\vlc
2010-11-02 10:07:35 ----D---- C:\Users\Jojo\AppData\Roaming\skypePM
2010-11-01 22:58:03 ----SHD---- C:\Windows\Installer
2010-11-01 22:57:54 ----SHD---- C:\System Volume Information
2010-11-01 22:57:53 ----D---- C:\Program Files\Java
2010-10-31 18:25:11 ----D---- C:\Windows\system32\catroot2
2010-10-30 21:25:14 ----D---- C:\Users\Jojo\AppData\Roaming\ICQ
2010-10-28 12:57:06 ----D---- C:\Program Files\Mozilla Firefox
2010-10-27 19:45:21 ----D---- C:\Windows\Microsoft.NET
2010-10-27 19:44:44 ----RSD---- C:\Windows\assembly
2010-10-27 18:47:51 ----D---- C:\Windows\system32\drivers
2010-10-27 18:47:50 ----D---- C:\Windows\winsxs
2010-10-27 16:47:20 ----D---- C:\Windows\ehome
2010-10-27 16:47:10 ----D---- C:\Windows\AppPatch
2010-10-27 06:05:56 ----D---- C:\Windows\system32\catroot
2010-10-26 13:46:46 ----RD---- C:\Program Files
2010-10-25 17:50:19 ----HD---- C:\ProgramData
2010-10-25 17:37:02 ----HD---- C:\Program Files\InstallShield Installation Information
2010-10-25 17:36:11 ----D---- C:\Program Files\Rockstar Games
2010-10-25 17:33:16 ----D---- C:\Windows
2010-10-19 10:41:44 ----N---- C:\Windows\system32\MpSigStub.exe
2010-10-18 13:40:09 ----A---- C:\Windows\win.ini
2010-10-18 13:35:35 ----D---- C:\Windows\twain_32
2010-10-18 13:34:24 ----RSD---- C:\Windows\Fonts
2010-10-18 13:33:11 ----D---- C:\Program Files\Common Files
2010-10-18 13:32:00 ----D---- C:\Windows\system32\DriverStore
2010-10-14 17:45:55 ----D---- C:\Windows\system32\migration
2010-10-14 17:45:55 ----D---- C:\Program Files\Internet Explorer
2010-10-14 17:45:54 ----D---- C:\Program Files\Windows Media Player
2010-10-14 17:44:07 ----D---- C:\ProgramData\Microsoft Help
2010-10-14 17:41:32 ----D---- C:\Windows\debug
2010-10-14 17:41:30 ----A---- C:\Windows\system32\MRT.exe
2010-10-14 17:40:36 ----D---- C:\Program Files\LG PC Suite II
2010-10-14 12:43:49 ----RD---- C:\Users
2010-10-14 12:43:49 ----D---- C:\Users\Jojo\AppData\Roaming\uTorrent
2010-10-12 19:26:04 ----D---- C:\Users\Jojo\AppData\Roaming\Audacity
2010-10-09 08:36:39 ----D---- C:\Windows\system32\sk-SK
2010-10-08 16:36:45 ----D---- C:\Program Files\Common Files\microsoft shared
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-02-20 691696]
R0 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2004-09-02 22656]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-02-26 114984]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-02-26 133512]
R2 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2004-07-21 9856]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-02-26 134488]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-02-26 41312]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 ElbyDelay;ElbyDelay; C:\Windows\System32\Drivers\ElbyDelay.sys [2004-02-12 3968]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2010-02-26 32584]
R3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2010-11-02 17488]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-06-25 2375776]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-30 187392]
S3 agw8kspb;agw8kspb; C:\Windows\system32\drivers\agw8kspb.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 131072]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2009-07-14 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 36864]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 usbbus;LGE Mobile Composite USB Device; C:\Windows\system32\DRIVERS\lgusbbus.sys [2010-01-21 13056]
S3 UsbDiag;LGE Mobile USB Serial Port; C:\Windows\system32\DRIVERS\lgusbdiag.sys [2010-01-21 20864]
S3 USBModem;LGE Mobile USB Modem; C:\Windows\system32\DRIVERS\lgusbmodem.sys [2010-01-21 24960]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-02-26 810120]
R2 ES lite Service;ES lite Service for program management.; C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE [2009-03-02 68136]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2009-06-01 222968]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-09-27 215656]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-09-27 240232]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-19 135664]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-02-26 33560]
S3 getPlusHelper;@C:\Program Files\NOS\bin\getPlus_Helper.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-02 1343400]
-----------------EOF-----------------

Logfile of random's system information tool 1.08 (written by random/random)
Run by Jojo at 2010-11-02 12:57:01
Microsoft Windows 7 Home Premium
System drive C: has 21 GB (21%) free of 100 GB
Total RAM: 3326 MB (65% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:57:05, on 2. 11. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\ICQ6.5\ICQ.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Rockstar Games\Rockstar Games Social Club\1_0_0_0\RGSC.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe
C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Rockstar Games\GTA San Andreas 2\samp.exe
C:\Users\Jojo\Downloads\RSIT.exe
C:\Program Files\trend micro\Jojo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1708250
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Free Lunch Design Toolbar - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFree.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Free Lunch Design Toolbar - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFree.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: Free Lunch Design Toolbar - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFree.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [reset] regedit /s reset.reg
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: RollerCoaster Tycoon 3 Registration.lnk = Jojo\AppData\Local\Temp\{6D335775-A22E-46F5-BC63-68B659261B7B}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{92EAFE1C-75B1-46F8-8050-65FEB530FAC5}: NameServer = 172.16.0.2,195.168.1.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{92EAFE1C-75B1-46F8-8050-65FEB530FAC5}: NameServer = 172.16.0.2,195.168.1.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{92EAFE1C-75B1-46F8-8050-65FEB530FAC5}: NameServer = 172.16.0.2,195.168.1.4
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
--
End of file - 8293 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21 328248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
Free Lunch Design Toolbar - C:\Program Files\Free_Lunch_Design\tbFree.dll [2009-05-20 2085400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-09-15 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21 509496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2009-06-01 962808]
{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - Free Lunch Design Toolbar - C:\Program Files\Free_Lunch_Design\tbFree.dll [2009-05-20 2085400]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-06-25 7547424]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"VirtualCloneDrive"=C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2004-08-20 45056]
"reset"=regedit /s reset.reg []
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-02-26 2140880]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-09-02 13351304]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"RGSC"=C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe [2008-11-14 305064]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Users\Jojo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
RollerCoaster Tycoon 3 Registration.lnk - C:\Users\Jojo\AppData\Local\Temp\{6D335775-A22E-46F5-BC63-68B659261B7B}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-11-01 22:57:54 ----A---- C:\Windows\system32\javaws.exe
2010-11-01 22:57:54 ----A---- C:\Windows\system32\javaw.exe
2010-11-01 22:57:54 ----A---- C:\Windows\system32\java.exe
2010-10-27 16:47:49 ----A---- C:\Windows\system32\D3DX9_42.dll
2010-10-27 16:47:49 ----A---- C:\Windows\system32\d3dx10_42.dll
2010-10-27 06:06:07 ----A---- C:\Windows\system32\msdri.dll
2010-10-27 06:06:07 ----A---- C:\Windows\system32\CPFilters.dll
2010-10-27 06:06:02 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2010-10-26 13:46:46 ----D---- C:\Program Files\Algodoo Phun Edition
2010-10-25 17:51:19 ----A---- C:\Windows\system32\mfc71.dll
2010-10-25 17:49:59 ----A---- C:\Windows\system32\CmdLineExt.dll
2010-10-25 17:33:38 ----A---- C:\Windows\system32\XAudio2_1.dll
2010-10-25 17:33:38 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2010-10-25 17:33:38 ----A---- C:\Windows\system32\xactengine3_1.dll
2010-10-25 17:33:38 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2010-10-25 17:33:38 ----A---- C:\Windows\system32\D3DX9_38.dll
2010-10-25 17:33:38 ----A---- C:\Windows\system32\d3dx10_38.dll
2010-10-25 17:33:38 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2010-10-25 17:33:37 ----A---- C:\Windows\system32\XAudio2_0.dll
2010-10-25 17:33:37 ----A---- C:\Windows\system32\xactengine3_0.dll
2010-10-25 17:33:37 ----A---- C:\Windows\system32\xactengine2_10.dll
2010-10-25 17:33:37 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2010-10-25 17:33:37 ----A---- C:\Windows\system32\d3dx9_36.dll
2010-10-25 17:33:37 ----A---- C:\Windows\system32\d3dx10_36.dll
2010-10-25 17:33:37 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2010-10-25 17:33:36 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2010-10-25 17:19:03 ----A---- C:\Windows\system32\D3DX9_37.dll
2010-10-25 17:19:03 ----A---- C:\Windows\system32\d3dx10_37.dll
2010-10-25 17:19:03 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2010-10-25 17:18:42 ----D---- C:\Windows\system32\xlive
2010-10-25 17:18:42 ----D---- C:\Program Files\Microsoft Games for Windows - LIVE
2010-10-18 13:42:14 ----D---- C:\ProgramData\WEBREG
2010-10-18 13:34:16 ----D---- C:\ProgramData\HP Product Assistant
2010-10-18 13:33:11 ----D---- C:\Program Files\Common Files\HP
2010-10-18 13:32:54 ----D---- C:\Program Files\Common Files\Hewlett-Packard
2010-10-18 13:31:59 ----A---- C:\Windows\system32\hposwia_d02c.dll
2010-10-18 13:31:59 ----A---- C:\Windows\system32\hpost_d02c.dll
2010-10-18 13:31:59 ----A---- C:\Windows\system32\hposc_d02a.dll
2010-10-18 13:31:55 ----A---- C:\Windows\system32\hppldcoi.dll
2010-10-18 13:31:53 ----A---- C:\Windows\system32\hpzids01.dll
2010-10-18 13:31:50 ----A---- C:\Windows\system32\hpf3l70v.dll
2010-10-18 13:31:09 ----HD---- C:\Config.Msi
2010-10-18 13:29:42 ----D---- C:\Program Files\HP
2010-10-18 13:12:07 ----D---- C:\ProgramData\HP
2010-10-14 14:45:07 ----A---- C:\Windows\system32\ole32.dll
2010-10-14 14:45:02 ----A---- C:\Windows\system32\iertutil.dll
2010-10-14 14:45:01 ----A---- C:\Windows\system32\mshtml.dll
2010-10-14 14:44:59 ----A---- C:\Windows\system32\msfeeds.dll
2010-10-14 14:44:59 ----A---- C:\Windows\system32\ieframe.dll
2010-10-14 14:44:58 ----A---- C:\Windows\system32\wininet.dll
2010-10-14 14:44:58 ----A---- C:\Windows\system32\urlmon.dll
2010-10-14 14:44:58 ----A---- C:\Windows\system32\mstime.dll
2010-10-14 14:44:58 ----A---- C:\Windows\system32\licmgr10.dll
2010-10-14 14:44:58 ----A---- C:\Windows\system32\iedkcs32.dll
2010-10-14 14:44:57 ----A---- C:\Windows\system32\mshtmled.dll
2010-10-14 14:44:57 ----A---- C:\Windows\system32\msfeedssync.exe
2010-10-14 14:44:57 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-10-14 14:44:57 ----A---- C:\Windows\system32\jsproxy.dll
2010-10-14 14:44:57 ----A---- C:\Windows\system32\ieui.dll
2010-10-14 14:44:57 ----A---- C:\Windows\system32\iepeers.dll
2010-10-14 14:44:55 ----A---- C:\Windows\system32\t2embed.dll
2010-10-14 14:44:54 ----A---- C:\Windows\system32\schannel.dll
2010-10-14 14:44:53 ----A---- C:\Windows\system32\comctl32.dll
2010-10-14 14:44:52 ----A---- C:\Windows\system32\mfc40u.dll
2010-10-14 14:44:52 ----A---- C:\Windows\system32\mfc40.dll
2010-10-14 14:44:46 ----A---- C:\Windows\system32\wmp.dll
2010-10-14 14:44:45 ----A---- C:\Windows\system32\wmploc.DLL
2010-10-14 14:44:45 ----A---- C:\Windows\system32\win32k.sys
2010-10-14 14:44:44 ----A---- C:\Windows\system32\srvsvc.dll
2010-10-14 14:44:44 ----A---- C:\Windows\system32\drivers\srvnet.sys
2010-10-14 14:44:44 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-10-14 14:44:44 ----A---- C:\Windows\system32\drivers\srv.sys
2010-10-14 14:44:43 ----A---- C:\Windows\system32\wmpmde.dll
2010-10-14 14:44:43 ----A---- C:\Windows\system32\StructuredQuery.dll
2010-10-08 16:37:06 ----D---- C:\Program Files\MTA San Andreas
======List of files/folders modified in the last 1 months======
2010-11-02 12:57:05 ----D---- C:\Windows\Temp
2010-11-02 12:57:05 ----D---- C:\Program Files\trend micro
2010-11-02 12:55:14 ----D---- C:\Users\Jojo\AppData\Roaming\Skype
2010-11-02 12:45:30 ----D---- C:\Windows\system32\config
2010-11-02 12:31:24 ----D---- C:\Windows\System32
2010-11-02 12:31:24 ----D---- C:\Windows\inf
2010-11-02 12:31:24 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-11-02 12:27:02 ----D---- C:\ProgramData\NVIDIA
2010-11-02 11:37:53 ----D---- C:\Users\Jojo\AppData\Roaming\vlc
2010-11-02 10:07:35 ----D---- C:\Users\Jojo\AppData\Roaming\skypePM
2010-11-01 22:58:03 ----SHD---- C:\Windows\Installer
2010-11-01 22:57:54 ----SHD---- C:\System Volume Information
2010-11-01 22:57:53 ----D---- C:\Program Files\Java
2010-10-31 18:25:11 ----D---- C:\Windows\system32\catroot2
2010-10-30 21:25:14 ----D---- C:\Users\Jojo\AppData\Roaming\ICQ
2010-10-28 12:57:06 ----D---- C:\Program Files\Mozilla Firefox
2010-10-27 19:45:21 ----D---- C:\Windows\Microsoft.NET
2010-10-27 19:44:44 ----RSD---- C:\Windows\assembly
2010-10-27 18:47:51 ----D---- C:\Windows\system32\drivers
2010-10-27 18:47:50 ----D---- C:\Windows\winsxs
2010-10-27 16:47:20 ----D---- C:\Windows\ehome
2010-10-27 16:47:10 ----D---- C:\Windows\AppPatch
2010-10-27 06:05:56 ----D---- C:\Windows\system32\catroot
2010-10-26 13:46:46 ----RD---- C:\Program Files
2010-10-25 17:50:19 ----HD---- C:\ProgramData
2010-10-25 17:37:02 ----HD---- C:\Program Files\InstallShield Installation Information
2010-10-25 17:36:11 ----D---- C:\Program Files\Rockstar Games
2010-10-25 17:33:16 ----D---- C:\Windows
2010-10-19 10:41:44 ----N---- C:\Windows\system32\MpSigStub.exe
2010-10-18 13:40:09 ----A---- C:\Windows\win.ini
2010-10-18 13:35:35 ----D---- C:\Windows\twain_32
2010-10-18 13:34:24 ----RSD---- C:\Windows\Fonts
2010-10-18 13:33:11 ----D---- C:\Program Files\Common Files
2010-10-18 13:32:00 ----D---- C:\Windows\system32\DriverStore
2010-10-14 17:45:55 ----D---- C:\Windows\system32\migration
2010-10-14 17:45:55 ----D---- C:\Program Files\Internet Explorer
2010-10-14 17:45:54 ----D---- C:\Program Files\Windows Media Player
2010-10-14 17:44:07 ----D---- C:\ProgramData\Microsoft Help
2010-10-14 17:41:32 ----D---- C:\Windows\debug
2010-10-14 17:41:30 ----A---- C:\Windows\system32\MRT.exe
2010-10-14 17:40:36 ----D---- C:\Program Files\LG PC Suite II
2010-10-14 12:43:49 ----RD---- C:\Users
2010-10-14 12:43:49 ----D---- C:\Users\Jojo\AppData\Roaming\uTorrent
2010-10-12 19:26:04 ----D---- C:\Users\Jojo\AppData\Roaming\Audacity
2010-10-09 08:36:39 ----D---- C:\Windows\system32\sk-SK
2010-10-08 16:36:45 ----D---- C:\Program Files\Common Files\microsoft shared
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-02-20 691696]
R0 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2004-09-02 22656]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-02-26 114984]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-02-26 133512]
R2 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2004-07-21 9856]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-02-26 134488]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-02-26 41312]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 ElbyDelay;ElbyDelay; C:\Windows\System32\Drivers\ElbyDelay.sys [2004-02-12 3968]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2010-02-26 32584]
R3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2010-11-02 17488]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-06-25 2375776]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-30 187392]
S3 agw8kspb;agw8kspb; C:\Windows\system32\drivers\agw8kspb.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 131072]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2009-07-14 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 36864]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 usbbus;LGE Mobile Composite USB Device; C:\Windows\system32\DRIVERS\lgusbbus.sys [2010-01-21 13056]
S3 UsbDiag;LGE Mobile USB Serial Port; C:\Windows\system32\DRIVERS\lgusbdiag.sys [2010-01-21 20864]
S3 USBModem;LGE Mobile USB Modem; C:\Windows\system32\DRIVERS\lgusbmodem.sys [2010-01-21 24960]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-02-26 810120]
R2 ES lite Service;ES lite Service for program management.; C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE [2009-03-02 68136]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2009-06-01 222968]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-09-27 215656]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-09-27 240232]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-19 135664]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-02-26 33560]
S3 getPlusHelper;@C:\Program Files\NOS\bin\getPlus_Helper.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-02 1343400]
-----------------EOF-----------------