Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

vypinanie zvukovky, conficker (?)

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
mexexe
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 13 lis 2010 14:02

vypinanie zvukovky, conficker (?)

#1 Příspěvek od mexexe »

Ahoj, prosim o pomoc. Mal som (a pravdepodobne este mam) v PC Confickera, teraz sa prejavuje len obcas, ked NOD prerusi spojenie so strankou kt. sa chce spojit. Vacsi problem je vsak v tom, ze sa mi vypina zvukovka po dlhsom pouzivani PC (2-3 hodiny, niekedy aj hned). Dlhsiu dobu mi vyhadzovalo aj vypnutie Generic host process win32 pri zapnuti XPcka (SP2), na to som dnes stiahol nejaku zaplatu, takze uz je (dufam) pokoj, pre dnesok je to OK.
Snazim sa PC pravidelne cistit CCcleanerom, cistil som ho NODom, Kasperskym, Conficker removerami a pod, stiahol som vsetky zaplaty "proti confickeru" ale nic... lezie mi to uz trochu na nervy, trva to uz vyse mesiaca.
Vopred dakujem. :worship:

pripajam log:
Logfile of random's system information tool 1.08 (written by random/random)
Run by maros at 2010-11-13 14:04:40
Microsoft Windows XP Professional Service Pack 2
System drive D: has 3 GB (13%) free of 22 GB
Total RAM: 3294 MB (82% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:04:41, on 13. 11. 2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
D:\Program Files\Analog Devices\Core\smax4pnp.exe
D:\WINDOWS\PixArt\PAC207\Monitor.exe
D:\Program Files\Eset\nod32kui.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\ADVANC~1\wh_exec.exe
D:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\WINDOWS\system32\RUNDLL32.EXE
D:\Program Files\Calibrize\CalibrizeResume.exe
D:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
D:\PROGRA~1\ESRI\License\arcgis9x\lmgrd.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\PROGRA~1\ESRI\License\arcgis9x\ARCGIS.exe
D:\Program Files\Eset\nod32krn.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Mozilla Firefox\plugin-container.exe
D:\Documents and Settings\maros\Desktop\RSIT(2).exe
D:\Program Files\trend micro\maros.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://google.sk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {95289393-33EA-4F8D-B952-483415B9C955} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - D:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "D:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] D:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] D:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Monitor] D:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [FineReader7NewsReaderPro] "D:\Program Files\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe"
O4 - HKLM\..\Run: [nod32kui] "D:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WheelMouse] D:\ADVANC~1\wh_exec.exe
O4 - HKLM\..\Run: [Adobe ARM] "D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [CGFLoader] D:\Program Files\Calibrize\CalibrizeLoader.exe
O4 - HKCU\..\Run: [CalibrizeResume] D:\Program Files\Calibrize\CalibrizeResume.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Juice.lnk = D:\Program Files\Juice\Juice.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Juice.lnk = D:\Program Files\Juice\Juice.exe (User 'Default user')
O4 - Startup: Juice.lnk = D:\Program Files\Juice\Juice.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: Append to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - D:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - D:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan ... stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc ... oscan8.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDow ... rtScan.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: ArcGIS License Manager - Unknown owner - D:\PROGRA~1\ESRI\License\arcgis9x\lmgrd.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - D:\WINDOWS\ATKKBService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c98246f88f9210) (gupdate1c98246f88f9210) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - D:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - D:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PEVSystemStart - Unknown owner - D:\ComboFix\PEV.cfxxe (file missing)
O23 - Service: ServiceLayer - Nokia. - D:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 9972 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\AppleSoftwareUpdate.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2010-09-23 61888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2010-09-23 320928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-09-15 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53}]
Google Gears Helper - D:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll [2010-02-23 2121728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-09-15 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2010-09-23 320928]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"=D:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
"Acrobat Assistant 8.0"=D:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [2010-09-23 624056]
"SoundMAXPnP"=D:\Program Files\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
"NeroFilterCheck"=D:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"Monitor"=D:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"NvCplDaemon"=D:\WINDOWS\system32\NvCpl.dll [2006-10-22 7700480]
"nwiz"=nwiz.exe /install []
"FineReader7NewsReaderPro"=D:\Program Files\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe [2003-12-10 278528]
"nod32kui"=D:\Program Files\Eset\nod32kui.exe [2008-12-16 949376]
"TkBellExe"=D:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-12-19 185872]
"WheelMouse"=D:\ADVANC~1\wh_exec.exe [2007-03-11 86016]
"Adobe ARM"=D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-21 932288]
"Adobe Reader Speed Launcher"=D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2010-09-24 40368]
"SunJavaUpdateSched"=D:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"NvMediaCenter"=D:\WINDOWS\system32\NvMcTray.dll [2006-10-22 86016]
"UserFaultCheck"=D:\WINDOWS\system32\dumprep 0 -u []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CGFLoader"=D:\Program Files\Calibrize\CalibrizeLoader.exe [2007-11-26 1961984]
"CalibrizeResume"=D:\Program Files\Calibrize\CalibrizeResume.exe [2007-11-26 413696]

D:\Documents and Settings\All Users\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - D:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe

D:\Documents and Settings\maros\Start Menu\Programs\Startup
Juice.lnk - D:\Program Files\Juice\Juice.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll [2009-01-30 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=475
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=475
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\Bonjour\mDNSResponder.exe"="D:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"D:\Program Files\uTorrent\uTorrent.exe"="D:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"D:\WINDOWS\system32\dplaysvr.exe"="D:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"M:\games\age\age2_x1.exe"="M:\games\age\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"D:\Program Files\totalcmd\TOTALCMD.EXE"="D:\Program Files\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"D:\Program Files\Opera\opera.exe"="D:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"D:\Program Files\Skype\Phone\Skype.exe"="D:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2010-11-13 14:03:14 ----D---- D:\rsit
2010-11-13 14:03:14 ----D---- D:\Program Files\trend micro
2010-11-13 13:01:18 ----HDC---- D:\WINDOWS\$NtUninstallKB894391$
2010-11-13 12:52:05 ----ASH---- D:\hiberfil.sys
2010-11-13 12:40:21 ----D---- D:\WINDOWS\pss
2010-11-13 09:02:20 ----AD---- D:\WINDOWS\rundll16.exe
2010-11-13 09:02:20 ----AD---- D:\WINDOWS\logo1_.exe
2010-11-13 08:55:16 ----ASH---- D:\pagefile.sys
2010-11-13 00:46:25 ----AD---- D:\WINDOWS\VDLL.DLL
2010-11-13 00:46:25 ----AD---- D:\WINDOWS\system32\runouce.exe
2010-11-13 00:46:25 ----AD---- D:\WINDOWS\RUNDL132.EXE
2010-11-13 00:46:25 ----AD---- D:\WINDOWS\logo_1.exe
2010-11-13 00:44:27 ----A---- D:\WINDOWS\system32\msvcr80.dll
2010-11-13 00:44:26 ----A---- D:\WINDOWS\system32\msvcp80.dll
2010-11-13 00:44:25 ----A---- D:\WINDOWS\system32\eEmpty.exe
2010-11-13 00:44:23 ----A---- D:\WINDOWS\system32\TASKMGR.COM
2010-11-13 00:44:23 ----A---- D:\WINDOWS\system32\T.COM
2010-11-13 00:44:23 ----A---- D:\WINDOWS\REGEDIT.COM
2010-11-13 00:44:23 ----A---- D:\WINDOWS\R.COM
2010-11-13 00:44:21 ----D---- D:\Program Files\Common Files\MicroWorld
2010-11-13 00:44:17 ----D---- D:\Documents and Settings\All Users\Application Data\MicroWorld
2010-11-12 17:18:10 ----HDC---- D:\WINDOWS\$NtUninstallKB923414$
2010-11-12 17:17:12 ----HDC---- D:\WINDOWS\$NtUninstallKB885250$
2010-11-12 16:39:01 ----D---- D:\Program Files\Altap Salamander
2010-11-12 16:29:11 ----D---- D:\Documents and Settings\All Users\Application Data\Panda Security
2010-11-12 16:29:07 ----D---- D:\Program Files\Panda USB Vaccine
2010-11-06 16:32:19 ----A---- D:\del.txt
2010-11-06 16:23:53 ----SHD---- D:\RECYCLER
2010-11-06 16:18:18 ----A---- D:\WINDOWS\system32\tmp.txt
2010-11-06 15:48:34 ----A---- D:\WINDOWS\NIRCMD.exe.mwt
2010-11-06 15:02:04 ----D---- D:\Documents and Settings\All Users\Application Data\McAfee Security Scan
2010-11-06 15:01:55 ----D---- D:\Program Files\McAfee Security Scan
2010-11-06 14:57:28 ----SHD---- D:\Config.Msi
2010-10-31 01:20:08 ----D---- D:\Documents and Settings\maros\Application Data\RSSRadio.local
2010-10-31 01:20:08 ----D---- D:\Documents and Settings\maros\Application Data\RSSRadio
2010-10-31 01:19:47 ----D---- D:\Program Files\Dorada Software
2010-10-31 01:08:28 ----D---- D:\Program Files\Winamp Detect
2010-10-25 13:25:23 ----A---- D:\WINDOWS\system32\javaws.exe
2010-10-25 13:25:23 ----A---- D:\WINDOWS\system32\javaw.exe
2010-10-25 13:25:23 ----A---- D:\WINDOWS\system32\java.exe
2010-10-17 11:54:53 ----D---- D:\Documents and Settings\All Users\Application Data\McAfee
2010-10-16 18:28:20 ----HDC---- D:\WINDOWS\$NtUninstallKB926239$
2010-10-16 18:28:15 ----N---- D:\WINDOWS\system32\spmsg.dll
2010-10-16 18:28:05 ----HDC---- D:\WINDOWS\$NtUninstallMSCompPackV1$
2010-10-16 18:27:55 ----A---- D:\WINDOWS\system32\wmpns.dll
2010-10-16 18:27:49 ----D---- D:\Program Files\Windows Media Connect 2
2010-10-16 18:27:39 ----HDC---- D:\WINDOWS\$NtUninstallwmp11$
2010-10-16 18:27:00 ----HDC---- D:\WINDOWS\$NtUninstallWMFDist11$
2010-10-16 18:26:36 ----D---- D:\WINDOWS\system32\LogFiles
2010-10-16 18:26:36 ----D---- D:\WINDOWS\system32\drivers\UMDF
2010-10-16 18:26:26 ----HDC---- D:\WINDOWS\$NtUninstallWudf01000$
2010-10-16 18:25:27 ----D---- D:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2010-10-16 16:38:24 ----D---- D:\Documents and Settings\maros\Application Data\vlc

======List of files/folders modified in the last 1 months======

2010-11-13 14:03:14 ----D---- D:\Program Files
2010-11-13 14:00:02 ----D---- D:\WINDOWS\temp
2010-11-13 13:57:55 ----A---- D:\WINDOWS\SchedLgU.Txt
2010-11-13 13:56:35 ----A---- D:\WINDOWS\wincmd.ini
2010-11-13 13:14:38 ----D---- D:\WINDOWS\Prefetch
2010-11-13 13:14:33 ----D---- D:\WINDOWS
2010-11-13 13:12:16 ----D---- D:\WINDOWS\system32
2010-11-13 13:01:23 ----HD---- D:\WINDOWS\inf
2010-11-13 13:01:20 ----RSHDC---- D:\WINDOWS\system32\dllcache
2010-11-13 13:01:08 ----HD---- D:\WINDOWS\$hf_mig$
2010-11-13 13:01:07 ----D---- D:\WINDOWS\system32\CatRoot2
2010-11-13 12:54:05 ----A---- D:\WINDOWS\win.ini
2010-11-13 12:54:05 ----A---- D:\WINDOWS\system.ini
2010-11-13 00:44:21 ----D---- D:\Program Files\Common Files
2010-11-13 00:25:39 ----D---- D:\WINDOWS\system32\Restore
2010-11-13 00:00:43 ----D---- D:\WINDOWS\Debug
2010-11-12 17:18:18 ----D---- D:\WINDOWS\system32\drivers
2010-11-12 16:20:39 ----D---- D:\WINDOWS\system32\CatRoot
2010-11-12 13:18:08 ----A---- D:\WINDOWS\NeroDigital.ini
2010-11-08 23:54:24 ----D---- D:\Documents and Settings\maros\Application Data\Skype
2010-11-08 23:31:30 ----D---- D:\Documents and Settings\maros\Application Data\skypePM
2010-11-08 14:29:36 ----D---- D:\Documents and Settings\maros\Application Data\Adobe
2010-11-08 14:04:08 ----D---- D:\WINDOWS\Minidump
2010-11-06 16:00:04 ----D---- D:\WINDOWS\AppPatch
2010-11-06 14:58:47 ----SHD---- D:\WINDOWS\Installer
2010-11-02 16:47:16 ----A---- D:\WINDOWS\system32\MRT.exe
2010-11-01 17:57:59 ----D---- D:\WINDOWS\system32\0ico0
2010-10-31 10:38:53 ----AC---- D:\WINDOWS\system32\PerfStringBackup.INI
2010-10-31 01:57:30 ----SD---- D:\Documents and Settings\maros\Application Data\Microsoft
2010-10-31 01:22:53 ----D---- D:\Documents and Settings\maros\Application Data\Winamp
2010-10-31 01:08:48 ----D---- D:\Program Files\Winamp
2010-10-29 00:01:49 ----D---- D:\Program Files\Mozilla Firefox
2010-10-26 09:52:22 ----D---- D:\Program Files\Mozilla Sunbird
2010-10-25 13:25:21 ----D---- D:\Program Files\Java
2010-10-16 18:27:49 ----D---- D:\Program Files\Windows Media Player
2010-10-16 18:27:45 ----D---- D:\WINDOWS\Help
2010-10-16 09:52:56 ----D---- D:\Documents and Settings\maros\Application Data\uTorrent

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; D:\WINDOWS\System32\Drivers\PxHelp20.sys [2008-07-31 43872]
R1 AmdK8;AMD Processor Driver; D:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 cdrbsdrv;cdrbsdrv; D:\WINDOWS\system32\drivers\cdrbsdrv.sys [2005-05-10 32256]
R1 EIO;EIO; \??\D:\WINDOWS\system32\drivers\EIO.sys []
R1 kbdhid;Keyboard HID Driver; D:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848]
R1 nod32drv;nod32drv; D:\WINDOWS\system32\drivers\nod32drv.sys [2008-12-16 15424]
R1 StarOpen;StarOpen; D:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; D:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 AMON;AMON; D:\WINDOWS\system32\drivers\amon.sys [2008-12-16 512096]
R2 Sentinel;Sentinel; D:\WINDOWS\System32\Drivers\SENTINEL.SYS [2004-05-14 76288]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; D:\WINDOWS\system32\drivers\ADIHdAud.sys [2005-10-05 141312]
R3 AEAudioService;AEAudio Service; D:\WINDOWS\system32\drivers\AEAudio.sys [2005-03-04 127872]
R3 Afc;PPdus ASPI Shell; D:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 asusgsb;ASUS Virtual Video Capture Device Driver; D:\WINDOWS\system32\drivers\asusgsb.sys [2007-07-12 12416]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Microsoft HID Class Driver; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-04 9600]
R3 mouhid;Mouse HID Driver; D:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; D:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 MxlW2k;MxlW2k; D:\WINDOWS\system32\drivers\MxlW2k.sys [2008-07-24 28352]
R3 nv;nv; D:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-10-22 3994624]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; D:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-07-11 35072]
R3 nvnetbus;NVIDIA Network Bus Enumerator; D:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-07-11 13184]
R3 pfc;Padus ASPI Shell; D:\WINDOWS\system32\drivers\pfc.sys [2008-04-13 9856]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; D:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 SenFiltService;SenFilt Service; D:\WINDOWS\system32\drivers\Senfilt.sys [2005-08-11 393088]
R3 usbccgp;Microsoft USB Generic Parent Driver; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 whfltr2k;WheelMouse USB Lower Filter Driver; D:\WINDOWS\system32\DRIVERS\whfltr2k.sys [2007-01-25 6784]
S3 CCDECODE;Closed Caption Decoder; D:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 DrvAgent32;DrvAgent32; \??\D:\WINDOWS\system32\Drivers\DrvAgent32.sys []
S3 HdAudAddService;ATI Function Driver for High Definition Audio Service; D:\WINDOWS\system32\drivers\AtiHdAud.sys [2006-12-28 84992]
S3 k750bus;Sony Ericsson 750 driver (WDM); D:\WINDOWS\system32\DRIVERS\k750bus.sys [2005-02-11 55216]
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter; D:\WINDOWS\system32\DRIVERS\k750mdfl.sys [2005-02-11 6576]
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers; D:\WINDOWS\system32\DRIVERS\k750mdm.sys [2005-02-11 89872]
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers; D:\WINDOWS\system32\DRIVERS\k750mgmt.sys [2005-02-11 81728]
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers; D:\WINDOWS\system32\DRIVERS\k750obex.sys [2005-02-11 79488]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; D:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; D:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 PAC207;Trust WB-1400T Webcam; D:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-14 508288]
S3 SBRE;SBRE; \??\D:\WINDOWS\system32\drivers\SBREdrv.sys []
S3 SLIP;BDA Slip De-Framer; D:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 ssm_bus;SAMSUNG Mobile USB Device II 1.0 driver (WDM); D:\WINDOWS\system32\DRIVERS\ssm_bus.sys [2007-05-02 83592]
S3 ssm_mdfl;SAMSUNG Mobile USB Modem II 1.0 Filter; D:\WINDOWS\system32\DRIVERS\ssm_mdfl.sys [2007-05-02 15112]
S3 ssm_mdm;SAMSUNG Mobile USB Port II 1.0 Drivers; D:\WINDOWS\system32\DRIVERS\ssm_mdm.sys [2007-05-02 109704]
S3 streamip;BDA IPSink; D:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbaudio;USB Audio Driver (WDM); D:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 usbprint;Microsoft USB PRINTER Class; D:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;USB Scanner Driver; D:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 Video3D;ASUS Video3D Service; D:\WINDOWS\System32\Drivers\Video3D32.sys []
S3 VNUSB;VN Series Device; D:\WINDOWS\system32\DRIVERS\VNUSB.sys []
S3 WinDriver6;WinDriver6; D:\WINDOWS\system32\drivers\windrvr6.sys []
S3 WpdUsb;WpdUsb; D:\WINDOWS\System32\Drivers\wpdusb.sys [2009-01-30 38528]
S3 WSTCODEC;World Standard Teletext Codec; D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; D:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; D:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 sptd;sptd; D:\WINDOWS\System32\Drivers\sptd.sys [2008-06-17 717296]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ArcGIS License Manager;ArcGIS License Manager; D:\PROGRA~1\ESRI\License\arcgis9x\lmgrd.exe [1999-12-01 467968]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; D:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre6\bin\jqs.exe [2010-09-15 153376]
R2 NOD32krn;NOD32 Kernel Service; D:\Program Files\Eset\nod32krn.exe [2008-12-16 552064]
R2 NVSvc;NVIDIA Display Driver Service; D:\WINDOWS\system32\nvsvc32.exe [2006-10-22 159810]
R3 FLEXnet Licensing Service;FLEXnet Licensing Service; D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-04-11 654848]
S2 ATKKeyboardService;ATK Keyboard Service; D:\WINDOWS\ATKKBService.exe [2006-09-22 241664]
S2 gupdate1c98246f88f9210;Google Update Service (gupdate1c98246f88f9210); D:\Program Files\Google\Update\GoogleUpdate.exe [2009-01-29 133104]
S2 PEVSystemStart;PEVSystemStart; D:\ComboFix\PEV.cfxxe EXEC /i D:\ComboFix\REGT.cfxxe /S D:\ComboFix\CregB.dat []
S3 aspnet_state;ASP.NET State Service; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 IDriverT;InstallDriver Table Manager; D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 McComponentHostService;McAfee Security Scan Component Host Service; D:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 NBService;NBService; D:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 NMIndexingService;NMIndexingService; D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 odserv;Microsoft Office Diagnostics Service; D:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; D:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2007-03-26 292864]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; D:\Program Files\Windows Media Player\WMPNetwk.exe [2009-02-04 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; D:\WINDOWS\system32\svchost.exe [2004-08-04 14336]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: vypinanie zvukovky, conficker (?)

#2 Příspěvek od motji »

Hezké odpoledne :)
Můžu se zeptat, kdy naposledy jste spouštěl combofix?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

mexexe
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 13 lis 2010 14:02

Re: vypinanie zvukovky, conficker (?)

#3 Příspěvek od mexexe »

motji píše:Hezké odpoledne :)
Můžu se zeptat, kdy naposledy jste spouštěl combofix?
tak tyzden dozadu, pred tym tak mesiac
tentoraz mi vsak vyhodilo modru obrazovku takze som sa k logu nedostal. potom este vybehla ked som spustil mwaw.exe ale dal som CHKDSK/F a je to ok.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: vypinanie zvukovky, conficker (?)

#4 Příspěvek od motji »

Vidím tam totiž zbytky po combofixu, můžou dělat neplechu.

:arrow: Stahněte OTL http://oldtimer.geekstogo.com/OTL.exe
-uložte ho na plochu a spustte soubor OTL.exe.
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

netsvcs
drivers32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
c:\windows\*.* /U
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
nvraid.sys
ndis.sys
winlogon.exe
explorer.exe
userinit.exe
lsass.exe
svchost.exe
smss.exe
hal.dll
ws2_32.dll
tcpip.sys
cryptsvc.dll
Changer.sys
JakNDis.sys
isapnp.sys
cdrom.sys
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
CREATERESTOREPOINT 
- zaškrtněte okénko Pro všechny uživatele.
-označte okénka Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
- Klikněte na tlačítko Prohledat
-po dokončení skenu se objeví logy OTL.Txt a Extras.txt, vložte je zde :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

mexexe
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 13 lis 2010 14:02

Re: vypinanie zvukovky, conficker (?)

#5 Příspěvek od mexexe »

Vyplulo mi to: Access violation at address 0040295B in module 'OTL.exe'. Read af address 0151E000.
OTC sa tvari ze citujem: "Creating restore point. DO NOT INTERRUPT ...", ale vyzera to ako keby sa to zaseklo.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: vypinanie zvukovky, conficker (?)

#6 Příspěvek od motji »

Spusťte OTL v nouzovém režimu bez skriptu.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

mexexe
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 13 lis 2010 14:02

Re: vypinanie zvukovky, conficker (?)

#7 Příspěvek od mexexe »

je to dlhe, neviem to tu nahodit nejako "normalne", pardon.
Přílohy
OTL.rar
(16.71 KiB) Staženo 21 x

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: vypinanie zvukovky, conficker (?)

#8 Příspěvek od motji »

Rozdělte log do více příspěvků, bude to pro mě přehlednější, než to stahnout :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

mexexe
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 13 lis 2010 14:02

Re: vypinanie zvukovky, conficker (?)

#9 Příspěvek od mexexe »

OTL.TXT part1:
OTL logfile created on: 13. 11. 2010 15:06:38 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = D:\Documents and Settings\maros\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d. M. yyyy

3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 82,00% Memory free
5,00 Gb Paging File | 5,00 Gb Available in Paging File | 93,00% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 52,73 Gb Total Space | 9,01 Gb Free Space | 17,09% Space Free | Partition Type: NTFS
Drive D: | 21,79 Gb Total Space | 2,88 Gb Free Space | 13,21% Space Free | Partition Type: NTFS
Drive M: | 298,09 Gb Total Space | 5,61 Gb Free Space | 1,88% Space Free | Partition Type: NTFS

Computer Name: MEXEXE | User Name: maros | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Processes (SafeList) ==========

PRC - [2010.11.13 14:56:09 | 000,575,488 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\maros\Desktop\OTL.exe
PRC - [2010.10.29 00:01:40 | 000,016,856 | ---- | M] (Mozilla Corporation) -- D:\Program Files\Mozilla Firefox\plugin-container.exe
PRC - [2010.10.29 00:01:39 | 000,912,344 | ---- | M] (Mozilla Corporation) -- D:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.10.17 10:40:21 | 000,134,808 | ---- | M] (Google Inc.) -- D:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
PRC - [2010.09.23 13:36:04 | 000,624,056 | ---- | M] (Adobe Systems Inc.) -- D:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
PRC - [2010.01.15 13:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- D:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2008.12.19 23:57:37 | 000,185,872 | ---- | M] (RealNetworks, Inc.) -- D:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2008.12.16 01:21:33 | 000,949,376 | ---- | M] (Eset ) -- D:\Program Files\ESET\nod32kui.exe
PRC - [2008.12.16 01:21:33 | 000,552,064 | ---- | M] (Eset ) -- D:\Program Files\ESET\nod32krn.exe
PRC - [2008.04.11 01:54:35 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) -- D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
PRC - [2007.11.26 16:40:38 | 000,413,696 | ---- | M] (Eberhard Werle) -- D:\Program Files\Calibrize\CalibrizeResume.exe
PRC - [2007.03.11 15:56:10 | 000,086,016 | ---- | M] () -- D:\Advanced Wheel Mouse\wh_exec.exe
PRC - [2007.02.19 02:51:35 | 000,552,960 | ---- | M] () -- D:\Program Files\ESRI\License\arcgis9x\ARCGIS.EXE
PRC - [2006.11.03 10:01:16 | 000,319,488 | ---- | M] (PixArt Imaging Incorporation) -- D:\WINDOWS\PixArt\PAC207\Monitor.exe
PRC - [2005.05.20 02:11:06 | 000,925,696 | R--- | M] (Analog Devices, Inc.) -- D:\Program Files\Analog Devices\Core\smax4pnp.exe
PRC - [2004.08.04 13:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\explorer.exe
PRC - [1999.12.01 11:38:28 | 000,467,968 | ---- | M] () -- D:\Program Files\ESRI\License\arcgis9x\lmgrd.exe


========== Modules (SafeList) ==========

MOD - [2010.11.13 14:56:09 | 000,575,488 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\maros\Desktop\OTL.exe
MOD - [2007.02.08 16:03:48 | 000,036,864 | ---- | M] () -- D:\Advanced Wheel Mouse\wh_hook.dll
MOD - [2006.05.03 22:53:54 | 000,174,592 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\framedyn.dll
MOD - [2004.08.04 13:00:00 | 001,852,416 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\AppPatch\AcGenral.dll
MOD - [2004.08.04 13:00:00 | 001,050,624 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
MOD - [2004.08.04 13:00:00 | 000,071,680 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\msacm32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\WINDOWS\system32\wuauserv.dll -- (wuauserv)
SRV - File not found [Auto | Stopped] -- D:\ComboFix\PEV.cfx -- (PEVSystemStart)
SRV - [2010.01.15 13:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- D:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2008.12.16 01:21:33 | 000,552,064 | ---- | M] (Eset ) [Auto | Running] -- D:\Program Files\Eset\nod32krn.exe -- (NOD32krn)
SRV - [2008.04.11 01:54:35 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Running] -- D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2007.03.26 12:06:24 | 000,292,864 | ---- | M] (Nokia.) [On_Demand | Stopped] -- D:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2006.09.22 09:58:12 | 000,241,664 | ---- | M] (ASUSTeK COMPUTER INC.) [Auto | Stopped] -- D:\WINDOWS\ATKKBService.exe -- (ATKKeyboardService)
SRV - [1999.12.01 11:38:28 | 000,467,968 | ---- | M] () [Auto | Running] -- D:\Program Files\ESRI\License\arcgis9x\lmgrd.exe -- (ArcGIS License Manager)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- D:\WINDOWS\System32\drivers\windrvr6.sys -- (WinDriver6)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\WINDOWS\System32\DRIVERS\VNUSB.sys -- (VNUSB)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\WINDOWS\System32\Drivers\Video3D32.sys -- (Video3D)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\WINDOWS\System32\drivers\SBREdrv.sys -- (SBRE)
DRV - [2010.10.06 13:46:36 | 000,023,456 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\DrvAgent32.sys -- (DrvAgent32)
DRV - [2008.12.16 01:21:34 | 000,512,096 | ---- | M] (Eset ) [Kernel | Auto | Running] -- D:\WINDOWS\system32\drivers\amon.sys -- (AMON)
DRV - [2008.12.16 01:21:33 | 000,015,424 | ---- | M] () [Kernel | System | Running] -- D:\WINDOWS\system32\drivers\nod32drv.sys -- (nod32drv)
DRV - [2008.07.24 16:05:12 | 000,028,352 | ---- | M] (MusicMatch, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\System32\drivers\MxlW2k.sys -- (MxlW2k)
DRV - [2008.06.17 14:54:12 | 000,717,296 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- D:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2008.04.13 01:00:14 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2007.07.12 09:03:42 | 000,012,416 | ---- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\asusgsb.sys -- (asusgsb)
DRV - [2007.07.12 09:03:38 | 000,012,288 | ---- | M] (ASUSTeK Computer Inc.) [Kernel | System | Running] -- D:\WINDOWS\system32\drivers\EIO.sys -- (EIO)
DRV - [2007.05.14 09:26:10 | 000,508,288 | ---- | M] (PixArt Imaging Inc.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\PFC027.SYS -- (PAC207)
DRV - [2007.05.02 11:12:36 | 000,109,704 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\ssm_mdm.sys -- (ssm_mdm)
DRV - [2007.05.02 11:12:36 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\ssm_mdfl.sys -- (ssm_mdfl)
DRV - [2007.05.02 11:12:34 | 000,083,592 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\ssm_bus.sys -- (ssm_bus) SAMSUNG Mobile USB Device II 1.0 driver (WDM)
DRV - [2007.01.25 16:45:02 | 000,006,784 | ---- | M] () [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\whfltr2k.sys -- (whfltr2k)
DRV - [2006.12.28 05:44:44 | 000,084,992 | R--- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\AtiHdAud.sys -- (HdAudAddService)
DRV - [2006.10.22 11:22:00 | 003,994,624 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2006.07.24 16:05:00 | 000,005,632 | ---- | M] () [File_System | System | Running] -- D:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2006.07.11 07:04:42 | 000,013,184 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2006.07.11 07:04:40 | 000,035,072 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2005.10.05 10:21:10 | 000,141,312 | R--- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV - [2005.08.11 06:49:28 | 000,393,088 | R--- | M] (Sensaura) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService)
DRV - [2005.05.10 23:33:12 | 000,032,256 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\cdrbsdrv.sys -- (cdrbsdrv)
DRV - [2005.03.09 14:53:00 | 000,036,352 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- D:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005.02.23 13:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\afc.sys -- (Afc)
DRV - [2005.02.11 09:24:24 | 000,079,488 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\k750obex.sys -- (k750obex)
DRV - [2005.02.11 09:22:48 | 000,081,728 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\k750mgmt.sys -- (k750mgmt)
DRV - [2005.02.11 09:21:10 | 000,089,872 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\k750mdm.sys -- (k750mdm)
DRV - [2005.02.11 09:21:02 | 000,006,576 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\k750mdfl.sys -- (k750mdfl)
DRV - [2005.02.11 09:19:20 | 000,055,216 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\k750bus.sys -- (k750bus) Sony Ericsson 750 driver (WDM)
DRV - [2005.01.07 16:07:18 | 000,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
DRV - [2004.08.13 03:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2004.08.03 22:07:56 | 000,059,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2004.08.03 21:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004.05.14 04:42:00 | 000,076,288 | ---- | M] (Rainbow Technologies, Inc.) [Kernel | Auto | Running] -- D:\WINDOWS\System32\Drivers\SENTINEL.SYS -- (Sentinel)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1708537768-573735546-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-1708537768-573735546-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-1708537768-573735546-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-1708537768-573735546-1801674531-1003\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1708537768-573735546-1801674531-1003\..\URLSearchHook: {95289393-33EA-4F8D-B952-483415B9C955} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1708537768-573735546-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1708537768-573735546-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "QIP Search"
FF - prefs.js..browser.search.order.1: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "megaup"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "megaup"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.sme.sk/"

FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: D:\Program Files\Google\Google Gears\Firefox\ [2010.03.06 18:48:55 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2010.11.06 14:57:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2010.11.06 14:57:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Sunbird 0.8\extensions\\Components: D:\Program Files\Mozilla Sunbird\components [2009.01.14 15:08:03 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Sunbird 0.8\extensions\\Plugins: D:\Program Files\Mozilla Sunbird\plugins

[2008.06.19 09:34:27 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Mozilla\Extensions
[2010.11.12 22:13:21 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Mozilla\Firefox\Profiles\bfhmp6kc.default\extensions
[2010.01.28 16:45:05 | 000,000,000 | ---D | M] (Gmail Manager) -- D:\Documents and Settings\maros\Application Data\Mozilla\Firefox\Profiles\bfhmp6kc.default\extensions\{582195F5-92E7-40a0-A127-DB71295901D7}
[2010.08.26 23:16:07 | 000,000,000 | ---D | M] (Yahoo! Mail Notifier) -- D:\Documents and Settings\maros\Application Data\Mozilla\Firefox\Profiles\bfhmp6kc.default\extensions\{89f8dde0-010a-11da-8cd6-0800200c9a66}
[2010.10.16 15:15:59 | 000,000,000 | ---D | M] (DownloadHelper) -- D:\Documents and Settings\maros\Application Data\Mozilla\Firefox\Profiles\bfhmp6kc.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009.10.13 12:12:20 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\maros\Application Data\Mozilla\Firefox\Profiles\bfhmp6kc.default\extensions\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}
[2008.05.02 16:59:45 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Mozilla\Sunbird\Profiles\11kbtxxi.default\extensions
[2010.08.26 23:09:26 | 000,005,551 | ---- | M] () -- D:\Documents and Settings\maros\Application Data\Mozilla\Firefox\Profiles\bfhmp6kc.default\searchplugins\google-maps.xml
[2010.08.26 23:09:51 | 000,004,140 | ---- | M] () -- D:\Documents and Settings\maros\Application Data\Mozilla\Firefox\Profiles\bfhmp6kc.default\searchplugins\youtube.xml
[2010.11.12 22:13:21 | 000,000,000 | ---D | M] -- D:\Program Files\Mozilla Firefox\extensions
[2010.07.01 11:00:19 | 000,000,000 | ---D | M] (Java Console) -- D:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.09.08 10:09:55 | 000,000,000 | ---D | M] (Java Console) -- D:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.10.25 13:25:24 | 000,000,000 | ---D | M] (Java Console) -- D:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2009.10.05 18:34:50 | 000,118,000 | ---- | M] () -- D:\Program Files\Mozilla Firefox\components\qippipe.dll
[2010.09.15 03:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- D:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.07.12 17:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- D:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2010.10.17 11:53:41 | 000,001,583 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\atlas-sk.xml
[2010.10.17 11:53:41 | 000,001,380 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\azet-sk.xml
[2010.10.17 11:53:41 | 000,001,479 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\dunaj-sk.xml
[2010.10.17 11:53:41 | 000,001,473 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\slovnik-sk.xml
[2010.10.17 11:53:41 | 000,001,104 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sk.xml
[2010.10.17 11:53:41 | 000,000,830 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\zoznam-sk.xml

O1 HOSTS File: ([2010.11.06 16:18:14 | 000,000,027 | ---- | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - D:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-1708537768-573735546-1801674531-1003\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-1708537768-573735546-1801674531-1003\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] D:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [FineReader7NewsReaderPro] D:\Program Files\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe (ABBYY (BIT Software))
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] D:\WINDOWS\System32\HdAShCut.exe (Windows (R) Server 2003 DDK provider)
O4 - HKLM..\Run: [Monitor] D:\WINDOWS\PixArt\PAC207\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [NeroFilterCheck] D:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [nod32kui] D:\Program Files\Eset\nod32kui.exe (Eset )
O4 - HKLM..\Run: [NvCplDaemon] D:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] D:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] D:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SoundMAXPnP] D:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] D:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKLM..\Run: [WheelMouse] D:\Advanced Wheel Mouse\wh_exec.exe ()
O4 - HKU\S-1-5-21-1708537768-573735546-1801674531-1003..\Run: [CalibrizeResume] D:\Program Files\Calibrize\CalibrizeResume.exe (Eberhard Werle)
O4 - HKU\S-1-5-21-1708537768-573735546-1801674531-1003..\Run: [CGFLoader] D:\Program Files\Calibrize\CalibrizeLoader.exe (Colorjinn)
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = D:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: D:\Documents and Settings\maros\Start Menu\Programs\Startup\Juice.lnk = D:\Program Files\Juice\Juice.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 475
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1708537768-573735546-1801674531-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1708537768-573735546-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 475
O7 - HKU\S-1-5-21-1708537768-573735546-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Append to existing PDF - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra 'Tools' menuitem : &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - D:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - D:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - D:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - D:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - D:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - D:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - D:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - D:\WINDOWS\System32\imon.dll (Eset )
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} http://acs.pandasoftware.com/activescan ... stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... vc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resourc ... oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDow ... rtScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 3.3)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.4.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: D:\Documents and Settings\maros\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: D:\Documents and Settings\maros\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.04.11 00:53:18 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: wuauserv - C:\WINDOWS\system32\wuauserv.dll File not found

Drivers32: msacm.divxa32 - D:\WINDOWS\System32\DivXa32.acm (Hacked With Joy !)
Drivers32: msacm.iac2 - D:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - D:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - D:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - D:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - D:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - D:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - D:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - D:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - D:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.MJPG - D:\WINDOWS\System32\Pvmjpg21.dll (Pegasus Imaging Corporation)
Drivers32: vidc.yv12 - D:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.

========== Files/Folders - Created Within 60 Days ==========

[2010.11.13 14:55:45 | 000,575,488 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\maros\Desktop\OTL.exe
[2010.11.13 14:03:14 | 000,000,000 | ---D | C] -- D:\Program Files\trend micro
[2010.11.13 14:03:14 | 000,000,000 | ---D | C] -- D:\rsit
[2010.11.13 13:11:23 | 000,000,000 | RH-D | C] -- D:\Documents and Settings\maros\Recent
[2010.11.13 12:40:21 | 000,000,000 | ---D | C] -- D:\WINDOWS\pss
[2010.11.13 09:02:20 | 000,000,000 | ---D | C] -- D:\WINDOWS\rundll16.exe
[2010.11.13 09:02:20 | 000,000,000 | ---D | C] -- D:\WINDOWS\logo1_.exe
[2010.11.13 00:46:25 | 000,000,000 | ---D | C] -- D:\WINDOWS\VDLL.DLL
[2010.11.13 00:46:25 | 000,000,000 | ---D | C] -- D:\WINDOWS\System32\runouce.exe
[2010.11.13 00:46:25 | 000,000,000 | ---D | C] -- D:\WINDOWS\RUNDL132.EXE
[2010.11.13 00:46:25 | 000,000,000 | ---D | C] -- D:\WINDOWS\logo_1.exe
[2010.11.13 00:44:27 | 000,632,064 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\msvcr80.dll
[2010.11.13 00:44:26 | 000,554,240 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\msvcp80.dll
[2010.11.13 00:44:25 | 000,034,048 | ---- | C] (MicroWorld Technologies Inc.) -- D:\WINDOWS\System32\eEmpty.exe
[2010.11.13 00:44:23 | 000,146,432 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\REGEDIT.COM
[2010.11.13 00:44:23 | 000,146,432 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\R.COM
[2010.11.13 00:44:23 | 000,135,680 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\TASKMGR.COM
[2010.11.13 00:44:23 | 000,135,680 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\T.COM
[2010.11.13 00:44:21 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\MicroWorld
[2010.11.13 00:44:17 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\MicroWorld
[2010.11.13 00:15:07 | 000,000,000 | ---D | C] -- D:\Documents and Settings\maros\Desktop\hhh
[2010.11.12 16:39:01 | 000,000,000 | ---D | C] -- D:\Program Files\Altap Salamander
[2010.11.12 16:29:11 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Panda Security
[2010.11.12 16:29:07 | 000,000,000 | ---D | C] -- D:\Program Files\Panda USB Vaccine
[2010.11.06 16:23:53 | 000,000,000 | -HSD | C] -- D:\RECYCLER
[2010.11.06 16:08:12 | 000,401,720 | ---- | C] (Trend Micro Inc.) -- D:\Documents and Settings\maros\Desktop\HijackThis.exe
[2010.11.06 15:48:34 | 000,031,232 | ---- | C] (NirSoft) -- D:\WINDOWS\NIRCMD.exe.mwt
[2010.11.06 15:02:04 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\McAfee Security Scan
[2010.11.06 15:01:55 | 000,000,000 | ---D | C] -- D:\Program Files\McAfee Security Scan
[2010.11.06 14:57:28 | 000,000,000 | -HSD | C] -- D:\Config.Msi
[2010.10.31 12:58:04 | 000,000,000 | ---D | C] -- D:\Documents and Settings\maros\Desktop\lavor
[2010.10.31 01:24:23 | 000,000,000 | ---D | C] -- D:\Documents and Settings\maros\My Documents\RSSRadio
[2010.10.31 01:20:08 | 000,000,000 | ---D | C] -- D:\Documents and Settings\maros\Application Data\RSSRadio.local
[2010.10.31 01:20:08 | 000,000,000 | ---D | C] -- D:\Documents and Settings\maros\Application Data\RSSRadio
[2010.10.31 01:19:47 | 000,000,000 | ---D | C] -- D:\Program Files\Dorada Software
[2010.10.31 01:08:28 | 000,000,000 | ---D | C] -- D:\Program Files\Winamp Detect
[2010.10.25 13:25:23 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\javaws.exe
[2010.10.25 13:25:23 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\javaw.exe
[2010.10.25 13:25:23 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\java.exe
[2010.10.17 12:25:21 | 000,000,000 | ---D | C] -- D:\Documents and Settings\LocalService\Application Data\McAfee
[2010.10.17 11:54:53 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\McAfee
[2010.10.16 18:28:15 | 000,014,640 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\spmsg.dll
[2010.10.16 18:27:49 | 000,000,000 | ---D | C] -- D:\Program Files\Windows Media Connect 2
[2010.10.16 18:26:36 | 000,000,000 | ---D | C] -- D:\WINDOWS\System32\drivers\UMDF
[2010.10.16 18:26:36 | 000,000,000 | ---D | C] -- D:\WINDOWS\System32\LogFiles
[2010.10.16 18:25:27 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2010.10.16 16:38:24 | 000,000,000 | ---D | C] -- D:\Documents and Settings\maros\Application Data\vlc
[2010.10.10 11:54:01 | 000,000,000 | ---D | C] -- D:\WINDOWS\ERDNT
[2010.10.08 18:26:45 | 000,000,000 | ---D | C] -- D:\Documents and Settings\maros\DoctorWeb
[2010.10.08 17:23:23 | 000,000,000 | ---D | C] -- D:\WINDOWS\temp
[2010.10.08 16:12:11 | 000,000,000 | -H-D | C] -- D:\WINDOWS\$hf_mig$
[2010.10.06 16:05:21 | 000,000,000 | ---D | C] -- D:\Documents and Settings\maros\Application Data\Malwarebytes
[2010.10.06 16:05:13 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.10.06 16:05:11 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys
[2010.10.06 16:05:11 | 000,000,000 | ---D | C] -- D:\Program Files\Malwarebytes' Anti-Malware
[2010.10.06 16:05:11 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010.10.06 14:09:07 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\NVIDIA
[2010.10.06 13:46:36 | 000,023,456 | ---- | C] (Phoenix Technologies) -- D:\WINDOWS\System32\drivers\DrvAgent32.sys
[2010.10.06 13:26:15 | 000,000,000 | ---D | C] -- D:\Documents and Settings\maros\Local Settings\Application Data\RadarSync
[2010.10.06 13:26:08 | 000,000,000 | ---D | C] -- D:\Program Files\RadarSync
[2010.10.06 13:13:18 | 000,599,424 | ---- | C] (ASMT) -- D:\WINDOWS\System32\drivers\Bravo_n_vivid.sys
[2010.10.06 13:13:18 | 000,599,424 | ---- | C] (ASMT) -- D:\WINDOWS\System32\drivers\Bravo_n_theater.sys
[2010.10.06 13:13:18 | 000,599,424 | ---- | C] (ASMT) -- D:\WINDOWS\System32\drivers\Bravo_n_enriched.sys
[2010.10.06 13:13:18 | 000,599,424 | ---- | C] (ASMT) -- D:\WINDOWS\System32\drivers\Bravo_n_crystal.sys
[2010.10.06 13:13:18 | 000,241,664 | ---- | C] (ASUSTeK COMPUTER INC.) -- D:\WINDOWS\ATKKBService.exe
[2010.10.06 13:13:18 | 000,011,008 | ---- | C] (ASUSTeK COMPUTER INC.) -- D:\WINDOWS\System32\drivers\atkkbnt.sys
[2010.10.06 13:13:17 | 000,599,424 | ---- | C] (ASMT) -- D:\WINDOWS\System32\drivers\Bravo_a_vivid.sys
[2010.10.06 13:13:16 | 000,599,424 | ---- | C] (ASMT) -- D:\WINDOWS\System32\drivers\Bravo_a_theater.sys
[2010.10.06 13:13:16 | 000,599,424 | ---- | C] (ASMT) -- D:\WINDOWS\System32\drivers\Bravo_a_enriched.sys
[2010.10.06 13:13:16 | 000,599,424 | ---- | C] (ASMT) -- D:\WINDOWS\System32\drivers\Bravo_a_crystal.sys
[2010.10.06 13:13:15 | 002,033,664 | ---- | C] (ASUSTeK COMPUTER INC.) -- D:\WINDOWS\System32\ATKOSDX32.dll
[2010.10.06 13:13:15 | 001,671,168 | ---- | C] (ASUSTeK COMPUTER INC.) -- D:\WINDOWS\System32\ATKDispCPL.dll
[2010.10.06 13:13:15 | 000,245,504 | ---- | C] (ASUSTeK Computer Inc.) -- D:\WINDOWS\System32\ATKDISP.dll
[2010.10.06 13:13:15 | 000,037,888 | ---- | C] (ASUSTeK COMPUTER INC.) -- D:\WINDOWS\System32\ATKOGL32.dll
[2010.10.06 12:50:04 | 000,000,000 | ---D | C] -- D:\Documents and Settings\LocalService\Local Settings\Application Data\Apple
[2010.10.04 13:07:24 | 000,000,000 | ---D | C] -- D:\Documents and Settings\maros\Application Data\U3
[2008.04.13 17:08:31 | 000,018,944 | ---- | C] ( ) -- D:\WINDOWS\System32\IMPLODE.DLL
[5 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 60 Days ==========

[2010.11.13 14:56:09 | 000,575,488 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\maros\Desktop\OTL.exe
[2010.11.13 14:45:00 | 000,001,000 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.11.13 14:04:30 | 000,339,991 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\RSIT(2).exe
[2010.11.13 13:58:57 | 000,093,734 | ---- | M] () -- D:\WINDOWS\System32\nvapps.xml
[2010.11.13 13:58:45 | 000,000,996 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.11.13 13:58:37 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2010.11.13 13:58:31 | 3454,324,736 | -HS- | M] () -- D:\hiberfil.sys
[2010.11.13 13:56:35 | 000,001,422 | ---- | M] () -- D:\WINDOWS\wincmd.ini
[2010.11.13 13:13:52 | 002,536,336 | ---- | M] () -- D:\WINDOWS\System32\FNTCACHE.DAT
[2010.11.13 13:01:27 | 000,073,000 | ---- | M] () -- D:\WINDOWS\System32\x
[2010.11.13 11:10:03 | 000,379,599 | ---- | M] () -- D:\Documents and Settings\maros\My Documents\pinfect.zip
[2010.11.13 11:00:36 | 000,002,427 | ---- | M] () -- D:\Documents and Settings\maros\Application Data\Microsoft\Internet Explorer\Quick Launch\RSSRadio.lnk
[2010.11.13 09:02:12 | 000,000,054 | ---- | M] () -- D:\WINDOWS\Lic.xxx
[2010.11.13 00:44:26 | 000,632,064 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\msvcr80.dll
[2010.11.13 00:44:25 | 000,554,240 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\msvcp80.dll
[2010.11.13 00:44:24 | 000,034,048 | ---- | M] (MicroWorld Technologies Inc.) -- D:\WINDOWS\System32\eEmpty.exe
[2010.11.13 00:43:54 | 109,339,400 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\mwav.exe
[2010.11.12 16:40:01 | 000,000,600 | ---- | M] () -- D:\Documents and Settings\maros\Application Data\winscp.rnd
[2010.11.12 13:18:08 | 000,000,069 | ---- | M] () -- D:\WINDOWS\NeroDigital.ini
[2010.11.10 13:50:00 | 000,000,284 | ---- | M] () -- D:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.11.10 13:33:32 | 004,471,713 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\ivanas_smile.jpg
[2010.11.09 11:21:39 | 000,035,840 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\ZÁKLADNÉ PARADIGMY.doc
[2010.11.09 11:21:34 | 000,036,352 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\teoretick%c3%a1 geografia.doc
[2010.11.09 11:21:29 | 000,076,288 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\TEORETICK%c3%81 GEOGRAFIA.doc
[2010.11.09 11:21:20 | 000,077,824 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\Súčastnosť a budúcnost geo výskumu na SK.doc
[2010.11.09 11:21:13 | 001,313,360 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\GEO.pdf
[2010.11.09 07:41:59 | 000,002,599 | ---- | M] () -- D:\Documents and Settings\maros\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2010.11.08 13:47:33 | 000,002,557 | ---- | M] () -- D:\Documents and Settings\maros\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2003.lnk
[2010.11.08 13:34:54 | 000,002,499 | ---- | M] () -- D:\Documents and Settings\maros\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office PowerPoint 2007.lnk
[2010.11.07 20:54:35 | 001,675,051 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\Sloveni%20najgermanskejsi%20Germani.pdf
[2010.11.06 16:18:14 | 000,000,027 | ---- | M] () -- D:\WINDOWS\System32\drivers\etc\hosts
[2010.11.06 16:08:13 | 000,401,720 | ---- | M] (Trend Micro Inc.) -- D:\Documents and Settings\maros\Desktop\HijackThis.exe
[2010.11.06 16:05:31 | 000,078,790 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\w.jpg
[2010.11.06 15:01:56 | 000,001,611 | ---- | M] () -- D:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2010.11.06 15:00:04 | 000,211,530 | -H-- | M] () -- D:\TREEINFO.WC
[2010.11.06 12:14:45 | 000,024,202 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\sused_doma_db5k41h3w.jpg
[2010.11.06 12:07:08 | 000,050,151 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\n1546892649_30097642_5273_abikf2hc5.jpg
[2010.11.06 11:52:44 | 000,047,746 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\1269800699_podborochka-popok_22022_s__52-w550.jpg
[2010.11.06 11:33:01 | 000,036,294 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\28646_397944748859_92155123859_4240123_7821765_n_abhl3i07u.jpg
[2010.11.06 10:57:35 | 000,077,340 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\podborka_89.jpg
[2010.11.06 09:53:21 | 000,202,240 | ---- | M] () -- D:\Documents and Settings\maros\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.11.05 18:58:26 | 023,428,440 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\Bee_in_Water_in_UltraSlo_motion.mp4
[2010.11.02 12:22:24 | 000,002,553 | ---- | M] () -- D:\Documents and Settings\maros\Application Data\Microsoft\Internet Explorer\Quick Launch\ABBYY FineReader 7.0 Professional Edition.lnk
[2010.11.01 22:03:31 | 000,054,272 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\Formular_vratne_flase-2010.doc
[2010.11.01 21:19:44 | 000,001,201 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\VIDEO.lnk
[2010.11.01 17:58:50 | 000,001,202 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\FOTY.lnk
[2010.11.01 17:58:42 | 000,001,259 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\MUSIC.lnk
[2010.10.31 10:38:53 | 000,392,296 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat
[2010.10.31 10:38:53 | 000,058,596 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat
[2010.10.31 01:10:14 | 000,001,535 | ---- | M] () -- D:\Documents and Settings\maros\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
[2010.10.31 01:04:17 | 000,000,665 | ---- | M] () -- D:\Documents and Settings\maros\Start Menu\Programs\Startup\Juice.lnk
[2010.10.30 19:12:28 | 000,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[2010.10.19 10:26:10 | 000,000,154 | ---- | M] () -- D:\WINDOWS\fm1.cfg
[2010.10.16 18:28:00 | 000,023,392 | ---- | M] () -- D:\WINDOWS\System32\nscompat.tlb
[2010.10.16 18:28:00 | 000,016,832 | ---- | M] () -- D:\WINDOWS\System32\amcompat.tlb
[2010.10.16 18:26:38 | 000,000,000 | -H-- | M] () -- D:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010.10.13 22:44:21 | 000,275,459 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\rozvrh.jpg
[2010.10.10 08:36:36 | 000,000,810 | ---- | M] () -- D:\Documents and Settings\maros\Application Data\Microsoft\Internet Explorer\Quick Launch\EVEREST Ultimate Edition.lnk
[2010.10.10 08:30:20 | 000,000,068 | -HS- | M] () -- D:\WINDOWS\setup_9.0.0.722_09.10.2010_16-35drv.spi
[2010.10.09 23:56:31 | 000,000,203 | ---- | M] () -- D:\WINDOWS\System32\imon1.dat
[2010.10.08 15:32:04 | 000,000,588 | RHS- | M] () -- D:\Documents and Settings\All Users\ntuser.pol
[2010.10.06 13:46:36 | 000,023,456 | ---- | M] (Phoenix Technologies) -- D:\WINDOWS\System32\drivers\DrvAgent32.sys
[2010.10.05 19:24:50 | 002,831,561 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\Untitled-2.jpg
[2010.10.05 19:24:30 | 002,511,172 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\Untitled-1.jpg
[2010.09.27 07:03:58 | 000,061,440 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\približne v.doc
[2010.09.27 07:03:58 | 000,040,448 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\Po dazdi.doc
[2010.09.27 07:03:58 | 000,036,352 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\Performance.doc
[2010.09.27 07:03:58 | 000,035,840 | ---- | M] () -- D:\Documents and Settings\maros\Desktop\BAR.doc
[2010.09.15 03:50:52 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\javaws.exe
[2010.09.15 03:50:51 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\javaw.exe
[2010.09.15 03:50:49 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\java.exe
[2010.09.15 03:50:37 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\deployJava1.dll
[2010.09.15 01:29:49 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- D:\WINDOWS\System32\javacpl.cpl
[5 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

mexexe
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 13 lis 2010 14:02

Re: vypinanie zvukovky, conficker (?)

#10 Příspěvek od mexexe »

OTL.TXT part2:

[2010.11.13 14:04:29 | 000,339,991 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\RSIT(2).exe
[2010.11.13 13:01:22 | 000,073,000 | ---- | C] () -- D:\WINDOWS\System32\x
[2010.11.13 12:52:05 | 3454,324,736 | -HS- | C] () -- D:\hiberfil.sys
[2010.11.13 11:10:03 | 000,379,599 | ---- | C] () -- D:\Documents and Settings\maros\My Documents\pinfect.zip
[2010.11.13 00:44:55 | 000,000,054 | ---- | C] () -- D:\WINDOWS\Lic.xxx
[2010.11.13 00:35:43 | 109,339,400 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\mwav.exe
[2010.11.12 16:40:01 | 000,000,600 | ---- | C] () -- D:\Documents and Settings\maros\Application Data\winscp.rnd
[2010.11.10 13:32:16 | 004,471,713 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\ivanas_smile.jpg
[2010.11.09 11:21:39 | 000,035,840 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\ZÁKLADNÉ PARADIGMY.doc
[2010.11.09 11:21:34 | 000,036,352 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\teoretick%c3%a1 geografia.doc
[2010.11.09 11:21:29 | 000,076,288 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\TEORETICK%c3%81 GEOGRAFIA.doc
[2010.11.09 11:21:20 | 000,077,824 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\Súčastnosť a budúcnost geo výskumu na SK.doc
[2010.11.09 11:21:12 | 001,313,360 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\GEO.pdf
[2010.11.07 20:54:35 | 001,675,051 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\Sloveni%20najgermanskejsi%20Germani.pdf
[2010.11.06 15:01:56 | 000,001,611 | ---- | C] () -- D:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2010.11.06 12:14:44 | 000,024,202 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\sused_doma_db5k41h3w.jpg
[2010.11.06 12:07:08 | 000,050,151 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\n1546892649_30097642_5273_abikf2hc5.jpg
[2010.11.06 11:52:44 | 000,047,746 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\1269800699_podborochka-popok_22022_s__52-w550.jpg
[2010.11.06 11:33:01 | 000,036,294 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\28646_397944748859_92155123859_4240123_7821765_n_abhl3i07u.jpg
[2010.11.06 10:57:35 | 000,077,340 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\podborka_89.jpg
[2010.11.05 18:56:10 | 023,428,440 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\Bee_in_Water_in_UltraSlo_motion.mp4
[2010.11.01 22:03:30 | 000,054,272 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\Formular_vratne_flase-2010.doc
[2010.10.31 17:35:33 | 000,002,427 | ---- | C] () -- D:\Documents and Settings\maros\Application Data\Microsoft\Internet Explorer\Quick Launch\RSSRadio.lnk
[2010.10.31 01:04:17 | 000,000,665 | ---- | C] () -- D:\Documents and Settings\maros\Start Menu\Programs\Startup\Juice.lnk
[2010.10.27 09:06:26 | 000,078,790 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\w.jpg
[2010.10.16 18:26:38 | 000,000,000 | -H-- | C] () -- D:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010.10.10 08:36:36 | 000,000,810 | ---- | C] () -- D:\Documents and Settings\maros\Application Data\Microsoft\Internet Explorer\Quick Launch\EVEREST Ultimate Edition.lnk
[2010.10.10 08:30:20 | 000,000,068 | -HS- | C] () -- D:\WINDOWS\setup_9.0.0.722_09.10.2010_16-35drv.spi
[2010.10.06 13:13:16 | 000,010,496 | ---- | C] () -- D:\WINDOWS\System32\ATKOSDMini.DLL
[2010.10.06 13:13:16 | 000,000,018 | ---- | C] () -- D:\WINDOWS\System32\atkid.ini
[2010.10.06 13:13:15 | 000,196,664 | ---- | C] () -- D:\WINDOWS\System32\atkosdRUS.rc0
[2010.10.06 13:13:15 | 000,196,664 | ---- | C] () -- D:\WINDOWS\System32\atkosdKOR.rc0
[2010.10.06 13:13:15 | 000,196,664 | ---- | C] () -- D:\WINDOWS\System32\atkosdJPN.rc0
[2010.10.06 13:13:15 | 000,196,664 | ---- | C] () -- D:\WINDOWS\System32\atkosdCHT.rc0
[2010.10.06 13:13:15 | 000,196,664 | ---- | C] () -- D:\WINDOWS\System32\atkosdCHS.rc0
[2010.10.06 13:13:15 | 000,196,664 | ---- | C] () -- D:\WINDOWS\System32\atkosdGER.rc0
[2010.10.06 13:13:15 | 000,196,664 | ---- | C] () -- D:\WINDOWS\System32\atkosdFRA.rc0
[2010.10.06 13:13:15 | 000,196,664 | ---- | C] () -- D:\WINDOWS\System32\atkosdENG.rc0
[2010.10.06 13:13:15 | 000,196,662 | ---- | C] () -- D:\WINDOWS\System32\ATKF16.rc0
[2010.10.06 13:13:15 | 000,196,662 | ---- | C] () -- D:\WINDOWS\System32\ATKF12.rc0
[2010.10.06 13:13:15 | 000,046,592 | ---- | C] () -- D:\WINDOWS\System32\asfrench.dll
[2010.10.06 13:13:15 | 000,046,080 | ---- | C] () -- D:\WINDOWS\System32\asrussian.dll
[2010.10.06 13:13:15 | 000,046,080 | ---- | C] () -- D:\WINDOWS\System32\asgerman.dll
[2010.10.06 13:13:15 | 000,046,080 | ---- | C] () -- D:\WINDOWS\System32\aseng.dll
[2010.10.06 13:13:15 | 000,045,568 | ---- | C] () -- D:\WINDOWS\System32\askorean.dll
[2010.10.06 13:13:15 | 000,045,568 | ---- | C] () -- D:\WINDOWS\System32\asjapan.dll
[2010.10.06 13:13:15 | 000,045,568 | ---- | C] () -- D:\WINDOWS\System32\ASCHT.dll
[2010.10.06 13:13:15 | 000,045,568 | ---- | C] () -- D:\WINDOWS\System32\aschs.dll
[2010.10.06 13:13:15 | 000,024,632 | ---- | C] () -- D:\WINDOWS\System32\atkrec.rc0
[2010.10.06 13:13:15 | 000,008,480 | ---- | C] () -- D:\WINDOWS\System32\atkgtvt.rc0
[2010.10.06 13:13:15 | 000,008,480 | ---- | C] () -- D:\WINDOWS\System32\atkgft.rc0
[2010.10.06 13:13:15 | 000,008,480 | ---- | C] () -- D:\WINDOWS\System32\atkdst.rc0
[2010.10.06 13:13:15 | 000,005,360 | ---- | C] () -- D:\WINDOWS\System32\atkgtvon.rc0
[2010.10.06 13:13:15 | 000,005,360 | ---- | C] () -- D:\WINDOWS\System32\atkgtvoff.rc0
[2010.10.06 13:13:15 | 000,005,360 | ---- | C] () -- D:\WINDOWS\System32\atkgfon.rc0
[2010.10.06 13:13:15 | 000,005,360 | ---- | C] () -- D:\WINDOWS\System32\atkgfoff.rc0
[2010.10.06 13:13:15 | 000,005,358 | ---- | C] () -- D:\WINDOWS\System32\atkdson.rc0
[2010.10.06 13:13:15 | 000,005,358 | ---- | C] () -- D:\WINDOWS\System32\atkdsoff.rc0
[2010.10.06 13:13:15 | 000,001,540 | ---- | C] () -- D:\WINDOWS\System32\ATKF16.rc1
[2010.10.06 13:13:15 | 000,001,540 | ---- | C] () -- D:\WINDOWS\System32\ATKF12.rc1
[2010.10.05 19:24:47 | 002,831,561 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\Untitled-2.jpg
[2010.10.05 19:24:26 | 002,511,172 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\Untitled-1.jpg
[2010.10.04 12:23:11 | 000,275,459 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\rozvrh.jpg
[2010.09.27 07:04:10 | 000,061,440 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\približne v.doc
[2010.09.27 07:04:10 | 000,040,448 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\Po dazdi.doc
[2010.09.27 07:04:10 | 000,036,352 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\Performance.doc
[2010.09.27 07:04:10 | 000,035,840 | ---- | C] () -- D:\Documents and Settings\maros\Desktop\BAR.doc
[2010.08.20 18:29:52 | 000,027,648 | ---- | C] () -- D:\WINDOWS\System32\AVSredirect.dll
[2010.02.15 23:45:03 | 000,000,000 | ---- | C] () -- D:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2010.02.15 23:43:27 | 000,005,632 | ---- | C] () -- D:\WINDOWS\System32\drivers\StarOpen.sys
[2010.01.25 18:15:11 | 000,000,313 | ---- | C] () -- D:\WINDOWS\AUSTRAL.ini
[2010.01.25 12:47:08 | 000,000,313 | ---- | C] () -- D:\WINDOWS\ASIE.ini
[2010.01.24 22:18:17 | 000,000,313 | ---- | C] () -- D:\WINDOWS\AMERIKA.ini
[2010.01.24 20:50:07 | 000,000,306 | ---- | C] () -- D:\WINDOWS\AFRIKA.ini
[2009.02.22 12:53:51 | 000,000,313 | ---- | C] () -- D:\WINDOWS\EVROPA.ini
[2009.02.09 01:31:09 | 000,002,181 | ---- | C] () -- D:\WINDOWS\Helicon Debug Window.ini
[2008.12.16 01:23:44 | 000,015,424 | ---- | C] () -- D:\WINDOWS\System32\drivers\nod32drv.sys
[2008.12.09 14:14:06 | 000,000,107 | ---- | C] () -- D:\Documents and Settings\maros\Application Data\netstat.bat
[2008.09.06 10:30:31 | 000,069,632 | R--- | C] () -- D:\WINDOWS\System32\xmltok.dll
[2008.09.06 10:30:31 | 000,036,864 | R--- | C] () -- D:\WINDOWS\System32\xmlparse.dll
[2008.07.02 19:01:09 | 000,000,333 | ---- | C] () -- D:\WINDOWS\lexstat.ini
[2008.06.10 12:47:22 | 000,000,048 | ---- | C] () -- D:\WINDOWS\WININIT.INI
[2008.04.17 20:23:02 | 000,000,314 | ---- | C] () -- D:\WINDOWS\System32\Remover.ini
[2008.04.16 19:10:30 | 000,000,240 | ---- | C] () -- D:\WINDOWS\cdplayer.ini
[2008.04.13 21:30:23 | 000,741,376 | ---- | C] () -- D:\WINDOWS\System32\audxlib.dll
[2008.04.13 21:30:23 | 000,568,320 | ---- | C] () -- D:\WINDOWS\System32\ff_x264.dll
[2008.04.13 21:30:23 | 000,204,800 | ---- | C] () -- D:\WINDOWS\System32\ff_kernelDeint.dll
[2008.04.13 21:30:23 | 000,143,360 | ---- | C] () -- D:\WINDOWS\System32\ff_theora.dll
[2008.04.13 21:30:23 | 000,023,552 | ---- | C] () -- D:\WINDOWS\System32\ff_wmv9.dll
[2008.04.13 21:30:22 | 000,245,760 | ---- | C] () -- D:\WINDOWS\System32\ff_libfaad2.dll
[2008.04.13 21:30:22 | 000,155,648 | ---- | C] () -- D:\WINDOWS\System32\ff_libdts.dll
[2008.04.13 21:30:22 | 000,122,880 | ---- | C] () -- D:\WINDOWS\System32\ff_samplerate.dll
[2008.04.13 21:30:22 | 000,118,784 | ---- | C] () -- D:\WINDOWS\System32\ff_libmad.dll
[2008.04.13 21:30:22 | 000,097,280 | ---- | C] () -- D:\WINDOWS\System32\ff_realaac.dll
[2008.04.13 21:30:22 | 000,081,408 | ---- | C] () -- D:\WINDOWS\System32\ff_tremor.dll
[2008.04.13 21:30:22 | 000,038,400 | ---- | C] () -- D:\WINDOWS\System32\ff_unrar.dll
[2008.04.13 21:30:22 | 000,037,376 | ---- | C] () -- D:\WINDOWS\System32\ff_liba52.dll
[2008.04.13 17:08:31 | 000,210,944 | ---- | C] () -- D:\WINDOWS\System32\Msvcrt10.dll
[2008.04.13 14:31:06 | 000,000,052 | ---- | C] () -- D:\WINDOWS\wcx_ftp.ini
[2008.04.13 01:48:13 | 000,202,240 | ---- | C] () -- D:\Documents and Settings\maros\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.04.13 01:48:13 | 000,000,069 | ---- | C] () -- D:\WINDOWS\NeroDigital.ini
[2008.04.13 00:56:14 | 000,001,422 | ---- | C] () -- D:\WINDOWS\wincmd.ini
[2008.04.12 20:09:13 | 000,000,050 | ---- | C] () -- D:\WINDOWS\Winamp.ini
[2008.04.12 20:08:50 | 000,000,041 | ---- | C] () -- D:\WINDOWS\winampa.ini
[2008.04.11 09:06:08 | 000,000,032 | ---- | C] () -- D:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008.04.11 08:02:00 | 000,005,810 | R--- | C] () -- D:\WINDOWS\System32\drivers\ASACPI.sys
[2008.04.11 08:01:55 | 000,015,466 | ---- | C] () -- D:\WINDOWS\Ascd_tmp.ini
[2008.04.11 08:01:45 | 000,005,824 | ---- | C] () -- D:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008.04.11 02:40:44 | 000,004,161 | ---- | C] () -- D:\WINDOWS\ODBCINST.INI
[2008.04.11 02:30:07 | 000,000,376 | ---- | C] () -- D:\WINDOWS\ODBC.INI
[2008.04.11 02:04:05 | 002,463,976 | ---- | C] () -- D:\WINDOWS\System32\NPSWF32.dll
[2008.01.09 14:01:48 | 000,000,453 | ---- | C] () -- D:\WINDOWS\bdoscandellang.ini
[2007.01.25 16:45:02 | 000,006,784 | ---- | C] () -- D:\WINDOWS\System32\drivers\whfltr2k.sys
[2006.11.02 08:27:46 | 000,000,518 | ---- | C] () -- D:\WINDOWS\System32\SP207.ini
[2006.07.21 09:50:00 | 001,662,976 | ---- | C] () -- D:\WINDOWS\System32\nvwdmcpl.dll
[2006.07.21 09:50:00 | 001,470,464 | ---- | C] () -- D:\WINDOWS\System32\nview.dll
[2006.07.21 09:50:00 | 001,019,904 | ---- | C] () -- D:\WINDOWS\System32\nvwimg.dll
[2006.07.21 09:50:00 | 000,581,632 | ---- | C] () -- D:\WINDOWS\System32\nvhwvid.dll
[2006.07.21 09:50:00 | 000,466,944 | ---- | C] () -- D:\WINDOWS\System32\nvshell.dll
[2006.07.21 09:50:00 | 000,286,720 | ---- | C] () -- D:\WINDOWS\System32\nvnt4cpl.dll
[2006.07.21 09:50:00 | 000,212,992 | ---- | C] () -- D:\WINDOWS\System32\nvapi.dll
[2005.12.21 11:36:46 | 000,009,728 | ---- | C] () -- D:\WINDOWS\System32\ff_vfw.dll
[2005.10.14 10:56:50 | 000,921,600 | ---- | C] () -- D:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 10:56:50 | 000,237,568 | ---- | C] () -- D:\WINDOWS\System32\OggDS.dll
[2005.10.14 10:56:50 | 000,188,416 | ---- | C] () -- D:\WINDOWS\System32\vorbis.dll
[2005.10.14 10:56:50 | 000,155,136 | ---- | C] () -- D:\WINDOWS\System32\unrar.dll
[2005.10.14 10:56:50 | 000,045,056 | ---- | C] () -- D:\WINDOWS\System32\ogg.dll
[2005.10.14 10:56:48 | 003,223,552 | ---- | C] () -- D:\WINDOWS\System32\libavcodec.dll
[2005.10.14 10:56:48 | 000,540,672 | ---- | C] () -- D:\WINDOWS\System32\libmplayer.dll
[2005.10.14 10:56:48 | 000,266,240 | ---- | C] () -- D:\WINDOWS\System32\TomsMoComp_ff.dll
[2005.10.14 10:56:48 | 000,094,208 | ---- | C] () -- D:\WINDOWS\System32\libmpeg2_ff.dll
[2004.08.04 13:00:00 | 000,081,920 | ---- | C] () -- D:\WINDOWS\System32\ieencode.dll
[2004.08.04 13:00:00 | 000,027,440 | ---- | C] () -- D:\WINDOWS\System32\drivers\secdrv.sys
[2002.03.21 14:39:02 | 000,073,728 | R--- | C] () -- D:\WINDOWS\System32\UNACEV2.DLL
[2002.03.20 21:01:06 | 000,006,688 | R--- | C] () -- D:\WINDOWS\System32\Digita.sys
[2002.03.20 21:00:20 | 000,049,152 | R--- | C] () -- D:\WINDOWS\System32\TransportUSB.dll
[2002.03.20 21:00:20 | 000,049,152 | R--- | C] () -- D:\WINDOWS\System32\TransportSerial.dll
[2002.03.20 21:00:20 | 000,049,152 | R--- | C] () -- D:\WINDOWS\System32\TransportIrDA.dll
[2002.03.20 21:00:20 | 000,049,152 | R--- | C] () -- D:\WINDOWS\System32\TransportIrCOMM.dll
[1997.06.25 14:24:16 | 000,040,448 | ---- | C] () -- D:\WINDOWS\System32\RegObj.dll

========== LOP Check ==========

[2008.04.13 01:00:17 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\ACD Systems
[2009.10.13 12:12:22 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Azureus
[2008.07.02 19:02:20 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\BVRP Software
[2009.04.26 18:28:40 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\ESRI
[2009.08.05 22:10:10 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Installations
[2009.01.30 14:21:45 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\JollyBear
[2008.12.06 02:20:59 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\MainType
[2010.11.13 00:44:21 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\MicroWorld
[2010.11.12 16:29:11 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Panda Security
[2009.08.05 22:13:00 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\PC Suite
[2009.01.30 14:33:37 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\TEMP
[2008.04.13 01:03:08 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\ACD Systems
[2009.06.21 17:10:43 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Audacity
[2009.10.13 12:24:18 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Azureus
[2008.10.27 17:55:41 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\CoSoSys
[2008.06.17 14:54:06 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\DAEMON Tools
[2009.03.29 22:16:49 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\ESRI
[2008.04.13 13:51:28 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\iPodder
[2008.12.04 15:20:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\MainType
[2008.11.06 11:49:41 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Mikrotik
[2010.08.27 15:13:14 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\MyPhoneExplorer
[2009.08.05 22:12:38 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Nokia
[2008.08.26 14:02:49 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\OLYMPUS
[2010.08.24 11:54:52 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Opera
[2009.08.05 22:11:11 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\PC Suite
[2009.03.27 20:19:58 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\QIP
[2010.11.13 12:00:59 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\RSSRadio
[2010.11.01 13:11:09 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\RSSRadio.local
[2010.09.07 21:06:45 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Samsung
[2008.04.13 14:34:26 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Sony
[2010.02.03 00:21:21 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Thinstall
[2010.10.16 09:52:56 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\uTorrent

========== Purity Check ==========



========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CGFLoader" = D:\Program Files\Calibrize\CalibrizeLoader.exe -- [2007.11.26 16:39:58 | 001,961,984 | ---- | M] (Colorjinn)
"CalibrizeResume" = D:\Program Files\Calibrize\CalibrizeResume.exe -- [2007.11.26 16:40:38 | 000,413,696 | ---- | M] (Eberhard Werle)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AdobeUpdater]
"" =

< c:\windows\*.* /U >

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >
[2008.12.06 23:02:41 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\ABBYY
[2008.04.13 01:00:17 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\ACD Systems
[2010.04.20 05:31:23 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Adobe
[2008.04.13 00:50:43 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Ahead
[2008.04.11 02:08:21 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\ALM
[2008.04.13 02:44:05 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Apple
[2009.10.13 12:12:22 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Azureus
[2008.07.02 19:02:20 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\BVRP Software
[2009.04.26 18:28:40 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\ESRI
[2010.07.05 14:43:28 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\FLEXnet
[2009.08.05 22:10:10 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Installations
[2009.01.30 14:21:45 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\JollyBear
[2010.10.08 14:53:48 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2008.12.06 02:20:59 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\MainType
[2010.10.06 16:05:11 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010.10.17 11:54:53 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\McAfee
[2010.11.06 15:02:04 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\McAfee Security Scan
[2008.04.17 20:31:30 | 000,000,000 | --SD | M] -- D:\Documents and Settings\All Users\Application Data\Microsoft
[2010.09.07 21:00:21 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Microsoft Help
[2010.11.13 00:44:21 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\MicroWorld
[2008.04.13 00:49:19 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Nero
[2010.10.06 14:09:07 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\NVIDIA
[2008.06.01 23:38:37 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\nView_Profiles
[2010.11.12 16:29:11 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Panda Security
[2009.08.05 22:13:00 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\PC Suite
[2010.03.12 11:40:41 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Real
[2008.04.11 09:03:30 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Skype
[2010.07.01 11:00:32 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Sun
[2009.01.30 14:33:37 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\TEMP
[2008.04.18 17:28:05 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Trymedia
[2010.10.16 18:25:27 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage

< %ALLUSERSPROFILE%\Application Data\*.exe /s >
[2010.03.24 19:17:47 | 000,326,056 | ---- | M] (Adobe Systems Incorporated) -- D:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\8.1\ARM\ARM Update\AcrobatUpdater.exe
[2010.03.24 19:17:47 | 000,952,768 | ---- | M] (Adobe Systems Incorporated) -- D:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\8.1\ARM\ARM Update\AdobeARM.exe
[2010.03.24 19:17:47 | 000,326,056 | ---- | M] (Adobe Systems Incorporated) -- D:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\8.1\ARM\ARM Update\ReaderUpdater.exe
[2007.04.02 05:45:08 | 044,338,384 | R--- | M] () -- D:\Documents and Settings\All Users\Application Data\Installations\{57A48477-92F0-4C1F-ADF9-4806C4EC3CF2}\Nokia_PC_Suite_683_rel_14_1_EA.exe
[2009.08.05 22:10:30 | 000,008,192 | ---- | M] () -- D:\Documents and Settings\All Users\Application Data\Installations\{57A48477-92F0-4C1F-ADF9-4806C4EC3CF2}\Installations\CommonCustomActions\UninstCCD.exe
[2009.08.05 22:10:30 | 000,009,728 | ---- | M] () -- D:\Documents and Settings\All Users\Application Data\Installations\{57A48477-92F0-4C1F-ADF9-4806C4EC3CF2}\Installations\CommonCustomActions\UninstPCS.exe
[2009.08.05 22:10:30 | 000,015,360 | ---- | M] () -- D:\Documents and Settings\All Users\Application Data\Installations\{57A48477-92F0-4C1F-ADF9-4806C4EC3CF2}\Installations\CommonCustomActions\UninstPCSFEMsi.exe
[2008.11.13 18:23:16 | 000,075,072 | ---- | M] (Kaspersky Lab) -- D:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\english\setup.exe
[2009.11.18 11:27:38 | 000,059,992 | ---- | M] (Kaspersky Lab) -- D:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Internet Security 2010 9.0.0.736\Czech\setup.exe

< %APPDATA%\*. >
[2008.12.06 23:03:25 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\ABBYY
[2008.04.13 01:03:08 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\ACD Systems
[2010.11.08 14:29:36 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Adobe
[2009.08.12 14:21:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Ahead
[2008.04.13 21:38:18 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Apple Computer
[2008.04.17 20:19:08 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\ArcSoft
[2008.04.11 01:11:47 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\ATI
[2009.06.21 17:10:43 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Audacity
[2009.10.13 12:24:18 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Azureus
[2008.10.27 17:55:41 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\CoSoSys
[2008.06.17 14:54:06 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\DAEMON Tools
[2010.08.24 07:42:39 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\dvdcss
[2009.03.29 22:16:49 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\ESRI
[2008.04.24 17:34:41 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Help
[2008.04.11 00:57:14 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Identities
[2008.04.13 13:51:28 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\iPodder
[2008.04.12 21:05:01 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Macromedia
[2008.12.04 15:20:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\MainType
[2010.10.06 16:05:21 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Malwarebytes
[2010.10.31 01:57:30 | 000,000,000 | --SD | M] -- D:\Documents and Settings\maros\Application Data\Microsoft
[2008.11.06 11:49:41 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Mikrotik
[2009.01.29 20:39:56 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Mozilla
[2010.08.27 15:13:14 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\MyPhoneExplorer
[2009.08.05 22:12:38 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Nokia
[2008.08.26 14:02:49 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\OLYMPUS
[2010.08.24 11:54:52 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Opera
[2009.08.05 22:11:11 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\PC Suite
[2009.03.27 20:19:58 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\QIP
[2008.12.19 23:59:33 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Real
[2010.11.13 12:00:59 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\RSSRadio
[2010.11.01 13:11:09 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\RSSRadio.local
[2010.09.07 21:06:45 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Samsung
[2010.11.08 23:54:24 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Skype
[2010.11.08 23:31:30 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\skypePM
[2008.04.13 14:34:26 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Sony
[2009.01.03 21:44:12 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Sun
[2008.05.02 16:59:46 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Talkback
[2010.02.03 00:21:21 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Thinstall
[2010.10.05 02:45:19 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\U3
[2010.10.16 09:52:56 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\uTorrent
[2010.10.19 17:04:18 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\vlc
[2010.10.31 01:22:53 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\Winamp
[2008.04.13 00:58:36 | 000,000,000 | ---D | M] -- D:\Documents and Settings\maros\Application Data\WinRAR

< %APPDATA%\*.exe /s >
[2007.10.09 17:26:14 | 003,892,808 | ---- | M] (High-Logic ) -- D:\Documents and Settings\maros\Application Data\MainType\MainTypeSetup.exe
[2008.04.11 01:07:07 | 000,009,158 | R--- | M] () -- D:\Documents and Settings\maros\Application Data\Microsoft\Installer\{5399ACAF-7B15-43D5-9233-4E797B184FD2}\ARPPRODUCTICON.exe
[2010.06.27 15:44:50 | 000,439,816 | ---- | M] (RealNetworks, Inc.) -- D:\Documents and Settings\maros\Application Data\Real\Update\setup3.10\setup.exe
[2010.09.11 15:29:57 | 000,452,104 | ---- | M] (RealNetworks, Inc.) -- D:\Documents and Settings\maros\Application Data\Real\Update\setup3.12\setup.exe
[2010.11.11 21:57:18 | 000,506,024 | ---- | M] (RealNetworks, Inc.) -- D:\Documents and Settings\maros\Application Data\Real\Update\setup3.13\setup.exe
[2010.05.13 12:09:52 | 000,220,272 | ---- | M] (Google Inc.) -- D:\Documents and Settings\maros\Application Data\Real\Update\setup3.13\gtb\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
[2010.10.22 18:10:16 | 000,190,632 | ---- | M] (RealNetworks, Inc.) -- D:\Documents and Settings\maros\Application Data\Real\Update\setup3.13\gtb_helper\LaunchHelper.exe
[2010.03.25 11:08:26 | 013,407,072 | ---- | M] () -- D:\Documents and Settings\maros\Application Data\Real\Update\setup3.13\chr\ChromeInstaller.exe
[2010.10.22 18:10:16 | 000,190,632 | ---- | M] (RealNetworks, Inc.) -- D:\Documents and Settings\maros\Application Data\Real\Update\setup3.13\chr_helper\LaunchHelper.exe
[2010.11.12 06:00:18 | 025,809,040 | ---- | M] (RealNetworks, Inc.) -- D:\Documents and Settings\maros\Application Data\Real\Update\setup3.13\rp\RealPlayer.exe
[2010.11.04 18:05:08 | 000,092,328 | ---- | M] (RealNetworks, Inc.) -- D:\Documents and Settings\maros\Application Data\Real\Update\setup3.13\ui_data\vista.exe
[2007.10.23 08:27:20 | 000,110,592 | ---- | M] () -- D:\Documents and Settings\maros\Application Data\U3\temp\cleanup.exe
[2008.05.02 09:41:48 | 003,493,888 | -H-- | M] (SanDisk Corporation) -- D:\Documents and Settings\maros\Application Data\U3\temp\Launchpad Removal.exe


< MD5 for: AGP440.SYS >
[2004.08.04 13:00:00 | 018,738,937 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys

< MD5 for: ATAPI.SYS >
[2004.08.04 13:00:00 | 018,738,937 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2004.08.04 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- D:\WINDOWS\ERDNT\cache\atapi.sys
[2004.08.04 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- D:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: CDROM.SYS >
[2004.08.04 13:00:00 | 018,738,937 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2004.08.04 13:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- D:\WINDOWS\system32\drivers\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2004.08.04 13:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=10654F9DDCEA9C46CFB77554231BE73B -- D:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2004.08.04 13:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=10654F9DDCEA9C46CFB77554231BE73B -- D:\WINDOWS\system32\cryptsvc.dll
[2004.08.04 13:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=10654F9DDCEA9C46CFB77554231BE73B -- D:\WINDOWS\system32\dllcache\cryptsvc.dll

< MD5 for: EVENTLOG.DLL >
[2004.08.04 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- D:\WINDOWS\ERDNT\cache\eventlog.dll
[2004.08.04 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- D:\WINDOWS\system32\dllcache\eventlog.dll
[2004.08.04 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- D:\WINDOWS\system32\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2004.08.04 13:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- D:\WINDOWS\ERDNT\cache\explorer.exe
[2004.08.04 13:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- D:\WINDOWS\explorer.exe
[2004.08.04 13:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- D:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: HAL.DLL >
[2004.08.04 13:00:00 | 018,738,937 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2004.08.04 13:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- D:\WINDOWS\system32\hal.dll

< MD5 for: CHANGER.SYS >
[2004.08.04 13:00:00 | 018,738,937 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys

< MD5 for: ISAPNP.SYS >
[2004.08.04 13:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=E504F706CCB699C2596E9A3DA1596E87 -- D:\WINDOWS\system32\drivers\isapnp.sys

< MD5 for: LSASS.EXE >
[2004.08.04 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=84885F9B82F4D55C6146EBF6065D75D2 -- D:\WINDOWS\ERDNT\cache\lsass.exe
[2004.08.04 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=84885F9B82F4D55C6146EBF6065D75D2 -- D:\WINDOWS\system32\dllcache\lsass.exe
[2004.08.04 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=84885F9B82F4D55C6146EBF6065D75D2 -- D:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2004.08.04 13:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- D:\WINDOWS\ERDNT\cache\ndis.sys
[2004.08.04 13:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- D:\WINDOWS\system32\dllcache\ndis.sys
[2004.08.04 13:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- D:\WINDOWS\system32\drivers\ndis.sys

< MD5 for: NETLOGON.DLL >
[2004.08.04 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- D:\WINDOWS\ERDNT\cache\netlogon.dll
[2004.08.04 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- D:\WINDOWS\system32\dllcache\netlogon.dll
[2004.08.04 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- D:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004.08.04 13:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- D:\WINDOWS\ERDNT\cache\scecli.dll
[2004.08.04 13:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- D:\WINDOWS\system32\dllcache\scecli.dll
[2004.08.04 13:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- D:\WINDOWS\system32\scecli.dll

< MD5 for: SMSS.EXE >
[2004.08.04 13:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=BD7FB0957C716F1A60333AEE04DE2178 -- D:\WINDOWS\system32\dllcache\smss.exe
[2004.08.04 13:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=BD7FB0957C716F1A60333AEE04DE2178 -- D:\WINDOWS\system32\smss.exe

< MD5 for: SVCHOST.EXE >
[2004.08.04 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- D:\WINDOWS\ERDNT\cache\svchost.exe
[2004.08.04 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- D:\WINDOWS\system32\dllcache\svchost.exe
[2004.08.04 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- D:\WINDOWS\system32\svchost.exe

< MD5 for: TCPIP.SYS >
[2004.08.04 13:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- D:\WINDOWS\system32\dllcache\tcpip.sys
[2009.05.16 13:22:56 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=C81D6A930A7805F6DAA0C7902B99037E -- D:\WINDOWS\system32\drivers\tcpip.sys

< MD5 for: USERINIT.EXE >
[2004.08.04 13:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- D:\WINDOWS\ERDNT\cache\userinit.exe
[2004.08.04 13:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- D:\WINDOWS\system32\dllcache\userinit.exe
[2004.08.04 13:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- D:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004.08.04 13:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- D:\WINDOWS\ERDNT\cache\winlogon.exe
[2004.08.04 13:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- D:\WINDOWS\system32\dllcache\winlogon.exe
[2004.08.04 13:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- D:\WINDOWS\system32\winlogon.exe

< MD5 for: WS2_32.DLL >
[2004.08.04 13:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 -- D:\WINDOWS\ERDNT\cache\ws2_32.dll
[2004.08.04 13:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 -- D:\WINDOWS\system32\dllcache\ws2_32.dll
[2004.08.04 13:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 -- D:\WINDOWS\system32\ws2_32.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 D:\WINDOWS\system32\*.tmp files -> D:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2008.04.11 02:38:54 | 000,094,208 | ---- | M] () -- D:\WINDOWS\system32\config\default.sav
[2008.04.11 02:38:54 | 000,659,456 | ---- | M] () -- D:\WINDOWS\system32\config\software.sav
[2008.04.11 02:38:54 | 000,913,408 | ---- | M] () -- D:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >
[1 D:\WINDOWS\system32\*.tmp files -> D:\WINDOWS\system32\*.tmp -> ]

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2010.11.13 00:44:24 | 000,034,048 | ---- | M] (MicroWorld Technologies Inc.) -- D:\WINDOWS\system32\eEmpty.exe
[2010.11.13 13:13:52 | 002,536,336 | ---- | M] () -- D:\WINDOWS\system32\FNTCACHE.DAT
[2010.11.13 13:59:20 | 000,000,083 | ---- | M] () -- D:\WINDOWS\system32\LMGRD.LOG
[2010.11.13 00:44:25 | 000,554,240 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\msvcp80.dll
[2010.11.13 00:44:26 | 000,632,064 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\msvcr80.dll
[2010.11.13 13:58:57 | 000,093,734 | ---- | M] () -- D:\WINDOWS\system32\nvapps.xml
[2010.11.13 13:01:27 | 000,073,000 | ---- | M] () -- D:\WINDOWS\system32\x
[1 D:\WINDOWS\system32\*.tmp files -> D:\WINDOWS\system32\*.tmp -> ]

========== Alternate Data Streams ==========

@Alternate Data Stream - 400 bytes -> D:\Documents and Settings\maros\Local Settings\Application Data\desktop.ini:5c43de08f544da0e2ebf87ecd84498e6
@Alternate Data Stream - 107 bytes -> D:\Documents and Settings\All Users\Application Data\TEMP:43301D1D
@Alternate Data Stream - 104 bytes -> D:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >

mexexe
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 13 lis 2010 14:02

Re: vypinanie zvukovky, conficker (?)

#11 Příspěvek od mexexe »

EXTRAS.TXT:
OTL Extras logfile created on: 13. 11. 2010 15:06:38 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = D:\Documents and Settings\maros\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d. M. yyyy

3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 82,00% Memory free
5,00 Gb Paging File | 5,00 Gb Available in Paging File | 93,00% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 52,73 Gb Total Space | 9,01 Gb Free Space | 17,09% Space Free | Partition Type: NTFS
Drive D: | 21,79 Gb Total Space | 2,88 Gb Free Space | 13,21% Space Free | Partition Type: NTFS
Drive M: | 298,09 Gb Total Space | 5,61 Gb Free Space | 1,88% Space Free | Partition Type: NTFS

Computer Name: MEXEXE | User Name: maros | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- D:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_USERS\S-1-5-21-1708537768-573735546-1801674531-1003\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
https [open] -- "D:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] -- "D:\Program Files\ACD Systems\ACDSee\6.0\ACDSee6.exe" "%1" (ACD Systems Ltd.)
Directory [AddToPlaylistVLC] -- "D:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "D:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\Program Files\uTorrent\uTorrent.exe" = D:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"D:\WINDOWS\system32\dplaysvr.exe" = D:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper -- (Microsoft Corporation)
"M:\games\age\age2_x1.exe" = M:\games\age\age2_x1.exe:*:Enabled:Age of Empires II Expansion -- (Microsoft Corporation)
"D:\Program Files\totalcmd\TOTALCMD.EXE" = D:\Program Files\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows -- (C. Ghisler & Co.)
"D:\Program Files\Opera\opera.exe" = D:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser -- (Opera Software)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{0224CACC-994D-45F8-B973-D65056EA9C2F}" = Adobe XMP DVA Panels CS3
"{066D65EA-ED53-44E4-A96A-F81B6E409D2E}" = PC Connectivity Solution
"{06A1BE8A-4CA4-4A39-B9E4-E815AA8FE05C}" = Sony Noise Reduction Plug-In 2.0h
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0A95786A-AB81-4ABF-9707-7B5BB7E515B5}" = ASUS VGA Driver
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}" = Adobe After Effects CS3 Presets
"{1B46F6A0-CA8B-4391-BE72-ADA7A3592E7D}" = ESRI Course Data for Data Production and Editing Techniques
"{1F34839E-4826-4B64-B1B3-42E5AE8DEC5A}" = ArcGIS Desktop
"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 22
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2FA41EBB-3F5A-35C3-85D6-51EC72A11FBD}" = Google Gears
"{30837A37-8F9F-4817-8B52-C501B67DC3BE}" = Trust WB-1400T Webcam
"{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}" = ASUS Enhanced Display Driver
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{38A0BB97-772D-422E-BCCA-4BA2A5D81F42}" = ACDSee 6.0 PowerPack
"{4458C442-7376-4CF9-AF58-E8CEA6722363}" = Adobe Setup
"{45EBDA59-D33B-433A-956E-B2F236468B56}" = MUSICMATCH® Jukebox
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4FC31A14-3D58-4F8F-85DA-EB3EBC771252}" = Catalyst Control Center - Branding
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{5399ACAF-7B15-43D5-9233-4E797B184FD2}" = AVIVO
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{55A41219-9B22-4098-BAE7-AE289B3C569A}_is1" = Panda USB Vaccine 1.0.1.4
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.6
"{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
"{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}" = AHV content for Acrobat and Flash
"{6D482078-8D15-4FD3-B838-C7B49174650F}" = Opera 10.61
"{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7ACFB90E-8FD0-4397-AD3A-5195412623A3}" = Adobe Help Viewer CS3
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}" = Adobe Video Profiles
"{847CAE64-4CD2-4B2D-AF00-978FF5431051}" = Nero 7 Ultra Edition
"{8718DC03-D066-4957-94E5-50C3C5042E8E}" = Adobe Creative Suite 3 Master Collection
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{9011041B-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0010-0405-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Czech) 12
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAF70000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 7.0 Professional Edition
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-1033-0000-7760-000000000003}" = Adobe Acrobat 8 Professional
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.5
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
"{B671CBFD-4109-4D35-9252-3062D3CCB7B2}" = Adobe SING CS3
"{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}" = Adobe BridgeTalk Plugin CS3
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}" = Adobe Flash Player 9 ActiveX
"{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
"{C151CE54-E7EA-4804-854B-F515368B0798}" = Athlon 64 Processor Driver
"{C5BD220A-EFE8-48A5-B70E-9503D535FACE}" = Adobe WAS CS3
"{CB3F8375-B600-4B9F-83C9-238ED1E583FD}" = Adobe InDesign CS3
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D5A31AB1-345D-47C7-A87B-036A669F6DF1}" = Adobe XMP Panels CS3
"{DBC3FDEC-D5F4-439C-9A18-EF454A74E3DE}_is1" = NOD32 FiX v2.1
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}" = Adobe InDesign CS3 Icon Handler
"{F02598C2-2A5F-4593-8F09-439F3317B2C8}" = Sentinel System Driver 5.42.1 (32-bit)
"{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools
"{F85C632C-29AB-4FD5-9870-AC39E4BDECF9}" = RSSRadio
"Adobe Acrobat 8 Professional" = Adobe Acrobat 8.2.5 Professional
"Adobe Acrobat 8 Professional_825" = Adobe Acrobat 8.2.5 - CPSID_83708
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
"Adobe_4dcfd9b7e901b57f81f667144603236" = Add or Remove Adobe Creative Suite 3 Master Collection
"Adobe_6c8e2cb4fd241c55406016127a6ab2e" = Adobe Color Common Settings
"Altap Salamander 2.54" = Altap Salamander 2.54
"ArcGIS License Manager" = ArcGIS License Manager
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.5 (Unicode)
"Autopano Giga" = Autopano Giga
"Calibrize_is1" = Calibrize 2.0
"CCleaner" = CCleaner (remove only)
"ClassicPro" = ClassicPro© v1.1
"DIVXAudio" = DivX ;-) Audio
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.02
"ffdshow" = ffdshow
"HijackThis" = HijackThis 2.0.2
"ImageWarp" = ImageWarp
"InstallShield_{30837A37-8F9F-4817-8B52-C501B67DC3BE}" = Trust WB-1400T Webcam
"Kasparov Chessmate_is1" = Kasparov Chessmate
"Lexicon 4.0" = Lingea Lexicon 2002
"MainType2_is1" = MainType 2.1.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Mozilla Firefox (3.6.12)" = Mozilla Firefox (3.6.12)
"Mozilla Sunbird (0.8)" = Mozilla Sunbird (0.8)
"MPE" = MyPhoneExplorer
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NOD32" = Antivírusový systém NOD32
"NVIDIA Drivers" = NVIDIA Drivers
"Python 2.4.1" = Python 2.4.1
"Quantum GIS Enceladus" = Quantum GIS Enceladus 1.4.0-1
"RealPlayer 6.0" = RealPlayer
"Recuva" = Recuva
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"SUPER ©" = SUPER © Version 2010.bld.38 (May 2, 2010)
"The KMPlayer" = The KMPlayer (remove only)
"Totalcmd" = Total Commander (Remove or Repair)
"VLC media player" = VLC media player 1.1.4
"WheelMouse" = Advanced Wheel Mouse 6.0.0.000
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1708537768-573735546-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"3DDeinstKey" = ArcView 3D Analyst
"ArcView GIS 3.3" = ArcView GIS 3.3
"Spatial11DeinstKey" = ArcView Spatial Analyst
"uTorrent" = µTorrent
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12. 11. 2010 2:54:02 | Computer Name = MEXEXE | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 12. 11. 2010 4:13:56 | Computer Name = MEXEXE | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x00000000.

Error - 12. 11. 2010 4:14:09 | Computer Name = MEXEXE | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x00000000.

Error - 12. 11. 2010 5:59:07 | Computer Name = MEXEXE | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 12. 11. 2010 10:37:41 | Computer Name = MEXEXE | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x00000000.

Error - 12. 11. 2010 16:55:07 | Computer Name = MEXEXE | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 13. 11. 2010 3:56:05 | Computer Name = MEXEXE | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x00000000.

Error - 13. 11. 2010 5:01:53 | Computer Name = MEXEXE | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 13. 11. 2010 7:52:42 | Computer Name = MEXEXE | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x00000000.

Error - 13. 11. 2010 8:52:48 | Computer Name = MEXEXE | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

[ System Events ]
Error - 13. 11. 2010 8:14:28 | Computer Name = MEXEXE | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 13. 11. 2010 8:14:45 | Computer Name = MEXEXE | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2

Error - 13. 11. 2010 8:14:45 | Computer Name = MEXEXE | Source = Service Control Manager | ID = 7023
Description = The Automatic Updates service terminated with the following error:
%%126

Error - 13. 11. 2010 8:59:23 | Computer Name = MEXEXE | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 13. 11. 2010 8:59:30 | Computer Name = MEXEXE | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2

Error - 13. 11. 2010 8:59:30 | Computer Name = MEXEXE | Source = Service Control Manager | ID = 7023
Description = The Automatic Updates service terminated with the following error:
%%126

Error - 13. 11. 2010 9:58:05 | Computer Name = MEXEXE | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 13. 11. 2010 9:58:05 | Computer Name = MEXEXE | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2

Error - 13. 11. 2010 10:06:55 | Computer Name = MEXEXE | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 13. 11. 2010 10:06:55 | Computer Name = MEXEXE | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2


< End of report >

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: vypinanie zvukovky, conficker (?)

#12 Příspěvek od motji »

:arrow: Odinstalujte
D:\Program Files\McAfee Security Scan


:arrow: Spustte OTL
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
SRV - File not found [Auto | Stopped] -- D:\ComboFix\PEV.cfx -- (PEVSystemStart)
IE - HKU\S-1-5-21-1708537768-573735546-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-1708537768-573735546-1801674531-1003\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1708537768-573735546-1801674531-1003\..\URLSearchHook: {95289393-33EA-4F8D-B952-483415B9C955} - Reg Error: Key error. File not found
FF - prefs.js..browser.search.defaultenginename: "QIP Search"
FF - prefs.js..browser.search.order.1: "Yahoo"
O4 - HKLM..\Run: [UserFaultCheck] File not found
@Alternate Data Stream - 400 bytes -> D:\Documents and Settings\maros\Local Settings\Application Data\desktop.ini:5c43de08f544da0e2ebf87ecd84498e6
@Alternate Data Stream - 107 bytes -> D:\Documents and Settings\All Users\Application Data\TEMP:43301D1D
@Alternate Data Stream - 104 bytes -> D:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
D:\Documents and Settings\maros\DoctorWeb

:commands
[emptytemp]
[EMPTYFLASH]
[Reboot]

-klikněte na tlačítko opravit.
-Následně se pc restartuje.
- Log vložte zde :)



:arrow: Dejte soubor otestovat na http://www.virustotal.com

D:\Program Files\Calibrize\CalibrizeLoader.exe
D:\Documents and Settings\maros\Application Data\U3\temp\cleanup.exe


-Na virustotalu dáte procházet, a do spodního okénka nakopírujete přímo cestu k souboru a dáte odeslat
-z prohlížeče zkopírujete adresu ke stránce s výsledky
-pokud se Vás zeptá, dejte soubor otestovat znovu, tak aby to byl soubor z Vašeho počítače


:arrow: nainstalujte firewall, třeba Zone alarm a hlídejte, co povolujete.

:arrow: Avptool jste zkoušel?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

mexexe
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 13 lis 2010 14:02

Re: vypinanie zvukovky, conficker (?)

#13 Příspěvek od mexexe »

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
Service PEVSystemStart stopped successfully!
Service PEVSystemStart deleted successfully!
File D:\ComboFix\PEV.cfx not found.
HKU\S-1-5-21-1708537768-573735546-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-1708537768-573735546-1801674531-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1708537768-573735546-1801674531-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\\{95289393-33EA-4F8D-B952-483415B9C955} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95289393-33EA-4F8D-B952-483415B9C955}\ not found.
Prefs.js: "QIP Search" removed from browser.search.defaultenginename
Prefs.js: "Yahoo" removed from browser.search.order.1
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\UserFaultCheck deleted successfully.
ADS D:\Documents and Settings\maros\Local Settings\Application Data\desktop.ini:5c43de08f544da0e2ebf87ecd84498e6 deleted successfully.
ADS D:\Documents and Settings\All Users\Application Data\TEMP:43301D1D deleted successfully.
ADS D:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
D:\Documents and Settings\maros\DoctorWeb folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: maros
->Temp folder emptied: 707512729 bytes
->Temporary Internet Files folder emptied: 34725 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 133157938 bytes
->Opera cache emptied: 13949946 bytes
->Flash cache emptied: 1659 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 4536194 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 49335 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 161296723 bytes

Total Files Cleaned = 973,00 mb


[EMPTYFLASH]

User: All Users

User: Default User

User: LocalService

User: maros
->Flash cache emptied: 0 bytes

User: NetworkService

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.17.3 log created on 11132010_160615

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...


linky na Calibrize.exe:
http://www.virustotal.com/file-scan/rep ... 1289661234
a cleanup.exe:
//www.virustotal.com/file-scan/report.htm ... 1289661570

Zone alarm nainstalovany a AVPtool som skusal, nieco vycistil ale asi len nieco z karanteny(?) NODu.
Pri starte nic nevyskocilo a teraz sa komp spraval trochu inak, mam z toho dobry pocit :)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: vypinanie zvukovky, conficker (?)

#14 Příspěvek od motji »

Dobře, uklidíme po použitých programech, a jakmile se vyskytne nějaký problém, hned sem napíšete a vložíte log ze Rsitu na kontrolu. Nedělejte sám žádné skeny, já potom nevidím v logu už žádný problém a nemám se od čeho odrazit :) .



:arrow: Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech


:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

mexexe
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 13 lis 2010 14:02

Re: vypinanie zvukovky, conficker (?)

#15 Příspěvek od mexexe »

Zvukovka sa opat vypla. :(

Logfile of random's system information tool 1.08 (written by random/random)
Run by maros at 2010-11-13 17:11:31
Microsoft Windows XP Professional Service Pack 2
System drive D: has 4 GB (18%) free of 22 GB
Total RAM: 3294 MB (83% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:11:43, on 13. 11. 2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\ZoneLabs\vsmon.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\ESRI\License\arcgis9x\lmgrd.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
D:\Program Files\Eset\nod32krn.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\ESRI\License\arcgis9x\ARCGIS.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
D:\Program Files\Analog Devices\Core\smax4pnp.exe
D:\WINDOWS\PixArt\PAC207\Monitor.exe
D:\Program Files\Eset\nod32kui.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\ADVANC~1\wh_exec.exe
D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
D:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\WINDOWS\system32\RUNDLL32.EXE
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\Program Files\Calibrize\CalibrizeResume.exe
D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Mozilla Firefox\plugin-container.exe
D:\Documents and Settings\maros\Desktop\RSIT(2).exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\trend micro\maros.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://google.sk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - D:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "D:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] D:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] D:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Monitor] D:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [FineReader7NewsReaderPro] "D:\Program Files\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe"
O4 - HKLM\..\Run: [nod32kui] "D:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WheelMouse] D:\ADVANC~1\wh_exec.exe
O4 - HKLM\..\Run: [Adobe ARM] "D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CGFLoader] D:\Program Files\Calibrize\CalibrizeLoader.exe
O4 - HKCU\..\Run: [CalibrizeResume] D:\Program Files\Calibrize\CalibrizeResume.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Juice.lnk = D:\Program Files\Juice\Juice.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Juice.lnk = D:\Program Files\Juice\Juice.exe (User 'Default user')
O4 - Startup: Juice.lnk = D:\Program Files\Juice\Juice.exe
O8 - Extra context menu item: Append to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - D:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - D:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan ... stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc ... oscan8.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDow ... rtScan.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: ArcGIS License Manager - Unknown owner - D:\PROGRA~1\ESRI\License\arcgis9x\lmgrd.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - D:\WINDOWS\ATKKBService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c98246f88f9210) (gupdate1c98246f88f9210) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - D:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - D:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - D:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 9765 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\AppleSoftwareUpdate.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2010-09-23 61888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2010-09-23 320928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-09-15 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53}]
Google Gears Helper - D:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll [2010-02-23 2121728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-09-15 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2010-09-23 320928]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"=D:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
"Acrobat Assistant 8.0"=D:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [2010-09-23 624056]
"SoundMAXPnP"=D:\Program Files\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
"NeroFilterCheck"=D:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"Monitor"=D:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"NvCplDaemon"=D:\WINDOWS\system32\NvCpl.dll [2006-10-22 7700480]
"nwiz"=nwiz.exe /install []
"FineReader7NewsReaderPro"=D:\Program Files\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe [2003-12-10 278528]
"nod32kui"=D:\Program Files\Eset\nod32kui.exe [2008-12-16 949376]
"TkBellExe"=D:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-12-19 185872]
"WheelMouse"=D:\ADVANC~1\wh_exec.exe [2007-03-11 86016]
"Adobe ARM"=D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-21 932288]
"Adobe Reader Speed Launcher"=D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2010-09-24 40368]
"SunJavaUpdateSched"=D:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"NvMediaCenter"=D:\WINDOWS\system32\NvMcTray.dll [2006-10-22 86016]
"ZoneAlarm Client"=D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2010-09-02 1043968]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CGFLoader"=D:\Program Files\Calibrize\CalibrizeLoader.exe [2007-11-26 1961984]
"CalibrizeResume"=D:\Program Files\Calibrize\CalibrizeResume.exe [2007-11-26 413696]

D:\Documents and Settings\maros\Start Menu\Programs\Startup
Juice.lnk - D:\Program Files\Juice\Juice.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll [2009-01-30 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=475
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=475
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\Bonjour\mDNSResponder.exe"="D:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"D:\Program Files\uTorrent\uTorrent.exe"="D:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"D:\WINDOWS\system32\dplaysvr.exe"="D:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"M:\games\age\age2_x1.exe"="M:\games\age\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"D:\Program Files\totalcmd\TOTALCMD.EXE"="D:\Program Files\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"D:\Program Files\Opera\opera.exe"="D:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"D:\Program Files\Skype\Phone\Skype.exe"="D:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
"D:\WINDOWS\system32\ZoneLabs\vsmon.exe"="D:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2010-11-13 17:11:31 ----D---- D:\rsit
2010-11-13 16:38:03 ----D---- D:\Documents and Settings\maros\Application Data\CheckPoint
2010-11-13 16:37:22 ----D---- D:\Program Files\Conduit
2010-11-13 16:37:01 ----D---- D:\Program Files\CheckPoint
2010-11-13 16:36:55 ----A---- D:\WINDOWS\system32\vsregexp.dll
2010-11-13 16:36:52 ----A---- D:\WINDOWS\system32\zlcommdb.dll
2010-11-13 16:36:52 ----A---- D:\WINDOWS\system32\zlcomm.dll
2010-11-13 16:36:48 ----A---- D:\WINDOWS\system32\zpeng25.dll
2010-11-13 16:36:48 ----A---- D:\WINDOWS\system32\vswmi.dll
2010-11-13 16:36:47 ----A---- D:\WINDOWS\system32\vsxml.dll
2010-11-13 16:36:46 ----D---- D:\WINDOWS\system32\ZoneLabs
2010-11-13 16:36:46 ----A---- D:\WINDOWS\system32\vspubapi.dll
2010-11-13 16:36:46 ----A---- D:\WINDOWS\system32\vsmonapi.dll
2010-11-13 16:36:45 ----A---- D:\WINDOWS\system32\vsdatant.sys
2010-11-13 16:35:57 ----A---- D:\WINDOWS\system32\vsutil.dll
2010-11-13 16:35:57 ----A---- D:\WINDOWS\system32\vsinit.dll
2010-11-13 16:35:57 ----A---- D:\WINDOWS\system32\vsdata.dll
2010-11-13 16:33:46 ----HDC---- D:\WINDOWS\$NtUninstallKB943232$
2010-11-13 16:33:38 ----D---- D:\Program Files\Zone Labs
2010-11-13 16:33:20 ----D---- D:\WINDOWS\Internet Logs
2010-11-13 14:03:14 ----D---- D:\Program Files\trend micro
2010-11-13 13:01:18 ----HDC---- D:\WINDOWS\$NtUninstallKB894391$
2010-11-13 12:52:05 ----ASH---- D:\hiberfil.sys
2010-11-13 12:40:21 ----D---- D:\WINDOWS\pss
2010-11-13 08:55:16 ----ASH---- D:\pagefile.sys
2010-11-12 17:18:10 ----HDC---- D:\WINDOWS\$NtUninstallKB923414$
2010-11-12 17:17:12 ----HDC---- D:\WINDOWS\$NtUninstallKB885250$
2010-11-12 16:29:11 ----D---- D:\Documents and Settings\All Users\Application Data\Panda Security
2010-11-12 16:29:07 ----D---- D:\Program Files\Panda USB Vaccine
2010-11-06 16:32:19 ----A---- D:\del.txt
2010-11-06 16:23:53 ----SHD---- D:\RECYCLER
2010-11-06 16:18:18 ----A---- D:\WINDOWS\system32\tmp.txt
2010-11-06 15:48:34 ----A---- D:\WINDOWS\NIRCMD.exe.mwt
2010-11-06 14:57:28 ----SHD---- D:\Config.Msi
2010-10-31 01:20:08 ----D---- D:\Documents and Settings\maros\Application Data\RSSRadio.local
2010-10-31 01:20:08 ----D---- D:\Documents and Settings\maros\Application Data\RSSRadio
2010-10-31 01:19:47 ----D---- D:\Program Files\Dorada Software
2010-10-31 01:08:28 ----D---- D:\Program Files\Winamp Detect
2010-10-25 13:25:23 ----A---- D:\WINDOWS\system32\javaws.exe
2010-10-25 13:25:23 ----A---- D:\WINDOWS\system32\javaw.exe
2010-10-25 13:25:23 ----A---- D:\WINDOWS\system32\java.exe
2010-10-17 11:54:53 ----D---- D:\Documents and Settings\All Users\Application Data\McAfee
2010-10-16 18:28:20 ----HDC---- D:\WINDOWS\$NtUninstallKB926239$
2010-10-16 18:28:15 ----N---- D:\WINDOWS\system32\spmsg.dll
2010-10-16 18:28:05 ----HDC---- D:\WINDOWS\$NtUninstallMSCompPackV1$
2010-10-16 18:27:55 ----A---- D:\WINDOWS\system32\wmpns.dll
2010-10-16 18:27:49 ----D---- D:\Program Files\Windows Media Connect 2
2010-10-16 18:27:39 ----HDC---- D:\WINDOWS\$NtUninstallwmp11$
2010-10-16 18:27:00 ----HDC---- D:\WINDOWS\$NtUninstallWMFDist11$
2010-10-16 18:26:36 ----D---- D:\WINDOWS\system32\LogFiles
2010-10-16 18:26:36 ----D---- D:\WINDOWS\system32\drivers\UMDF
2010-10-16 18:26:26 ----HDC---- D:\WINDOWS\$NtUninstallWudf01000$
2010-10-16 18:25:27 ----D---- D:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2010-10-16 16:38:24 ----D---- D:\Documents and Settings\maros\Application Data\vlc

======List of files/folders modified in the last 1 months======

2010-11-13 17:11:43 ----D---- D:\WINDOWS\Prefetch
2010-11-13 17:11:38 ----D---- D:\WINDOWS\temp
2010-11-13 17:11:29 ----A---- D:\WINDOWS\SchedLgU.Txt
2010-11-13 17:09:31 ----D---- D:\WINDOWS
2010-11-13 17:08:36 ----D---- D:\WINDOWS\system32\CatRoot2
2010-11-13 17:08:04 ----D---- D:\Program Files
2010-11-13 17:03:04 ----SHD---- D:\System Volume Information
2010-11-13 17:03:04 ----D---- D:\WINDOWS\system32\Restore
2010-11-13 17:02:52 ----D---- D:\WINDOWS\system32
2010-11-13 17:02:52 ----D---- D:\Program Files\Common Files
2010-11-13 16:33:50 ----HD---- D:\WINDOWS\inf
2010-11-13 16:33:47 ----RSHDC---- D:\WINDOWS\system32\dllcache
2010-11-13 13:56:35 ----A---- D:\WINDOWS\wincmd.ini
2010-11-13 13:01:08 ----HD---- D:\WINDOWS\$hf_mig$
2010-11-13 12:54:05 ----A---- D:\WINDOWS\win.ini
2010-11-13 12:54:05 ----A---- D:\WINDOWS\system.ini
2010-11-13 00:00:43 ----D---- D:\WINDOWS\Debug
2010-11-12 17:18:18 ----D---- D:\WINDOWS\system32\drivers
2010-11-12 16:20:39 ----D---- D:\WINDOWS\system32\CatRoot
2010-11-12 13:18:08 ----A---- D:\WINDOWS\NeroDigital.ini
2010-11-08 23:54:24 ----D---- D:\Documents and Settings\maros\Application Data\Skype
2010-11-08 23:31:30 ----D---- D:\Documents and Settings\maros\Application Data\skypePM
2010-11-08 14:29:36 ----D---- D:\Documents and Settings\maros\Application Data\Adobe
2010-11-08 14:04:08 ----D---- D:\WINDOWS\Minidump
2010-11-06 16:00:04 ----D---- D:\WINDOWS\AppPatch
2010-11-06 14:58:47 ----SHD---- D:\WINDOWS\Installer
2010-11-02 16:47:16 ----A---- D:\WINDOWS\system32\MRT.exe
2010-11-01 17:57:59 ----D---- D:\WINDOWS\system32\0ico0
2010-10-31 10:38:53 ----AC---- D:\WINDOWS\system32\PerfStringBackup.INI
2010-10-31 01:57:30 ----SD---- D:\Documents and Settings\maros\Application Data\Microsoft
2010-10-31 01:22:53 ----D---- D:\Documents and Settings\maros\Application Data\Winamp
2010-10-31 01:08:48 ----D---- D:\Program Files\Winamp
2010-10-29 00:01:49 ----D---- D:\Program Files\Mozilla Firefox
2010-10-26 09:52:22 ----D---- D:\Program Files\Mozilla Sunbird
2010-10-25 13:25:21 ----D---- D:\Program Files\Java
2010-10-16 18:27:49 ----D---- D:\Program Files\Windows Media Player
2010-10-16 18:27:45 ----D---- D:\WINDOWS\Help
2010-10-16 09:52:56 ----D---- D:\Documents and Settings\maros\Application Data\uTorrent

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; D:\WINDOWS\System32\Drivers\PxHelp20.sys [2008-07-31 43872]
R1 AmdK8;AMD Processor Driver; D:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 cdrbsdrv;cdrbsdrv; D:\WINDOWS\system32\drivers\cdrbsdrv.sys [2005-05-10 32256]
R1 EIO;EIO; \??\D:\WINDOWS\system32\drivers\EIO.sys []
R1 kbdhid;Keyboard HID Driver; D:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848]
R1 nod32drv;nod32drv; D:\WINDOWS\system32\drivers\nod32drv.sys [2008-12-16 15424]
R1 StarOpen;StarOpen; D:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R1 vsdatant;vsdatant; D:\WINDOWS\System32\vsdatant.sys [2010-05-13 532224]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; D:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 AMON;AMON; D:\WINDOWS\system32\drivers\amon.sys [2008-12-16 512096]
R2 Sentinel;Sentinel; D:\WINDOWS\System32\Drivers\SENTINEL.SYS [2004-05-14 76288]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; D:\WINDOWS\system32\drivers\ADIHdAud.sys [2005-10-05 141312]
R3 AEAudioService;AEAudio Service; D:\WINDOWS\system32\drivers\AEAudio.sys [2005-03-04 127872]
R3 Afc;PPdus ASPI Shell; D:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 asusgsb;ASUS Virtual Video Capture Device Driver; D:\WINDOWS\system32\drivers\asusgsb.sys [2007-07-12 12416]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Microsoft HID Class Driver; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-04 9600]
R3 mouhid;Mouse HID Driver; D:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; D:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 MxlW2k;MxlW2k; D:\WINDOWS\system32\drivers\MxlW2k.sys [2008-07-24 28352]
R3 nv;nv; D:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-10-22 3994624]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; D:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-07-11 35072]
R3 nvnetbus;NVIDIA Network Bus Enumerator; D:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-07-11 13184]
R3 pfc;Padus ASPI Shell; D:\WINDOWS\system32\drivers\pfc.sys [2008-04-13 9856]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; D:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 SenFiltService;SenFilt Service; D:\WINDOWS\system32\drivers\Senfilt.sys [2005-08-11 393088]
R3 usbccgp;Microsoft USB Generic Parent Driver; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 whfltr2k;WheelMouse USB Lower Filter Driver; D:\WINDOWS\system32\DRIVERS\whfltr2k.sys [2007-01-25 6784]
S3 CCDECODE;Closed Caption Decoder; D:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 DrvAgent32;DrvAgent32; \??\D:\WINDOWS\system32\Drivers\DrvAgent32.sys []
S3 HdAudAddService;ATI Function Driver for High Definition Audio Service; D:\WINDOWS\system32\drivers\AtiHdAud.sys [2006-12-28 84992]
S3 k750bus;Sony Ericsson 750 driver (WDM); D:\WINDOWS\system32\DRIVERS\k750bus.sys [2005-02-11 55216]
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter; D:\WINDOWS\system32\DRIVERS\k750mdfl.sys [2005-02-11 6576]
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers; D:\WINDOWS\system32\DRIVERS\k750mdm.sys [2005-02-11 89872]
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers; D:\WINDOWS\system32\DRIVERS\k750mgmt.sys [2005-02-11 81728]
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers; D:\WINDOWS\system32\DRIVERS\k750obex.sys [2005-02-11 79488]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; D:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; D:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 PAC207;Trust WB-1400T Webcam; D:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-14 508288]
S3 SBRE;SBRE; \??\D:\WINDOWS\system32\drivers\SBREdrv.sys []
S3 SLIP;BDA Slip De-Framer; D:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 ssm_bus;SAMSUNG Mobile USB Device II 1.0 driver (WDM); D:\WINDOWS\system32\DRIVERS\ssm_bus.sys [2007-05-02 83592]
S3 ssm_mdfl;SAMSUNG Mobile USB Modem II 1.0 Filter; D:\WINDOWS\system32\DRIVERS\ssm_mdfl.sys [2007-05-02 15112]
S3 ssm_mdm;SAMSUNG Mobile USB Port II 1.0 Drivers; D:\WINDOWS\system32\DRIVERS\ssm_mdm.sys [2007-05-02 109704]
S3 streamip;BDA IPSink; D:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbaudio;USB Audio Driver (WDM); D:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 usbprint;Microsoft USB PRINTER Class; D:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;USB Scanner Driver; D:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 Video3D;ASUS Video3D Service; D:\WINDOWS\System32\Drivers\Video3D32.sys []
S3 VNUSB;VN Series Device; D:\WINDOWS\system32\DRIVERS\VNUSB.sys []
S3 WinDriver6;WinDriver6; D:\WINDOWS\system32\drivers\windrvr6.sys []
S3 WpdUsb;WpdUsb; D:\WINDOWS\System32\Drivers\wpdusb.sys [2009-01-30 38528]
S3 WSTCODEC;World Standard Teletext Codec; D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; D:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; D:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 sptd;sptd; D:\WINDOWS\System32\Drivers\sptd.sys [2008-06-17 717296]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ArcGIS License Manager;ArcGIS License Manager; D:\PROGRA~1\ESRI\License\arcgis9x\lmgrd.exe [1999-12-01 467968]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; D:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre6\bin\jqs.exe [2010-09-15 153376]
R2 NOD32krn;NOD32 Kernel Service; D:\Program Files\Eset\nod32krn.exe [2008-12-16 552064]
R2 NVSvc;NVIDIA Display Driver Service; D:\WINDOWS\system32\nvsvc32.exe [2006-10-22 159810]
R2 vsmon;TrueVector Internet Monitor; D:\WINDOWS\system32\ZoneLabs\vsmon.exe [2010-09-02 2435592]
R3 FLEXnet Licensing Service;FLEXnet Licensing Service; D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-04-11 654848]
S2 ATKKeyboardService;ATK Keyboard Service; D:\WINDOWS\ATKKBService.exe [2006-09-22 241664]
S2 gupdate1c98246f88f9210;Google Update Service (gupdate1c98246f88f9210); D:\Program Files\Google\Update\GoogleUpdate.exe [2009-01-29 133104]
S3 aspnet_state;ASP.NET State Service; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 IDriverT;InstallDriver Table Manager; D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 NBService;NBService; D:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 NMIndexingService;NMIndexingService; D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 odserv;Microsoft Office Diagnostics Service; D:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; D:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2007-03-26 292864]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; D:\Program Files\Windows Media Player\WMPNetwk.exe [2009-02-04 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; D:\WINDOWS\system32\svchost.exe [2004-08-04 14336]

-----------------EOF-----------------

Odpovědět