Zasekaný NTB
Napsal: 06 pro 2010 23:22
Zdravím. Dostal jsem kámoščin notebook abych jí ho zprovoznil. Zapnutí pc a spuštění např. internetového prohlížeče trvá cca 20 minut... Někdy se prohlížeč ani nezapne... Bude určitě potřeba formát celého pc, ale ješte bych potřeboval ten NTB aspoň na pár dní rozjet... přikládám log. Díky za pomov.
Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2010-12-06 23:18:15
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 25 GB (33%) free of 76 GB
Total RAM: 447 MB (32% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:18:28, on 6.12.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\TEMP\BN2.tmp
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WinOverBoost\wob2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Administrator.EVCA\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
O4 - HKLM\..\Run: [reset] regedit /s reset.reg
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [NVIDIA driver monitor] C:\WINDOWS\nvsvc32.exe
O4 - HKLM\..\Run: [sebunni] C:\WINDOWS\system32\mynak.exe
O4 - HKLM\..\Run: [wuaucldt] c:\windows\system32\wuaucldt.exe
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Windows Firewall] C:\DOCUME~1\EVA~1\LOCALS~1\Temp\lsass.exe
O4 - HKLM\..\Run: [WinOverBoost] C:\Program Files\WinOverBoost\wob2.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Atheros Configuration Service (ACS) - Atheros - C:\WINDOWS\System32\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DistributedAgentServices - BrainWork - C:\WINDOWS\system32\spool\drivers\Distributed.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: AOL Antivirus Update Service (r1d4yrbuv130y4do) - Unknown owner - C:\Documents and Settings\Evča\Data aplikací\Microsoft\joreb.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
--
End of file - 5914 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{D4027C7F-154A-4066-A1AD-4243D8127440}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ACU"=C:\Program Files\Atheros\ACU.exe [2006-11-17 348249]
"reset"=regedit /s reset.reg []
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-10-30 16269312]
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"HControl"=C:\WINDOWS\ATK0100\HControl.exe [2006-10-14 110592]
"NVIDIA driver monitor"=C:\WINDOWS\nvsvc32.exe [2010-11-03 90112]
"sebunni"=C:\WINDOWS\system32\mynak.exe []
"wuaucldt"=c:\windows\system32\wuaucldt.exe [2010-11-22 33280]
"Regedit32"=C:\WINDOWS\system32\regedit.exe []
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-11-22 2216960]
"Windows Firewall"=C:\DOCUME~1\EVA~1\LOCALS~1\Temp\lsass.exe []
"WinOverBoost"=C:\Program Files\WinOverBoost\wob2.exe [2004-03-20 119808]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Seznam Postak]
C:\Program Files\Seznam.cz\postak.exe -s []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinOverBoost]
C:\Program Files\WinOverBoost\wob2.exe [2004-03-20 119808]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^0e6qq6c.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\0e6qq6c.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^0lhcc6o.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\0lhcc6o.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^1cyytka.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\1cyytka.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^3qqlccn.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\3qqlccn.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^6mm70tp.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\6mm70tp.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^a3ccxoojalg.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\a3ccxoojalg.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^aa6mm6yy6.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\aa6mm6yy6.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^bhxy0o3aa3.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\bhxy0o3aa3.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^cy726qvl.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\cy726qvl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^effwrriddu.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\effwrriddu.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^hcc6ojk6gg6.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\hcc6ojk6gg6.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^hndezzqvlh.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\hndezzqvlh.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^jek5l0hn.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\jek5l0hn.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^jpk1gccxoo.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\jpk1gccxoo.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^k6ww6ii6.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\k6ww6ii6.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^kk6ww6ii6.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\kk6ww6ii6.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^kv26snnezz.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\kv26snnezz.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^lccxooja.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\lccxooja.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^lccxoojk6gg.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\lccxoojk6gg.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^lhxxtjjpvb.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\lhxxtjjpvb.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^mm3yy6kk6.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\mm3yy6kk6.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^mm5n0o0a.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\mm5n0o0a.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^pq0mms5y.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\pq0mms5y.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^q60c3oo3aa.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\q60c3oo3aa.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^q6cc6ojk.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\q6cc6ojk.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^qmmhyytkkf.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\qmmhyytkkf.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^r1iytkffb.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\r1iytkffb.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^tpffwrridd.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\tpffwrridd.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^u9q1miiduu.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\u9q1miiduu.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^ufbww6ii.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\ufbww6ii.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^w60i3upv.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\w60i3upv.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^wrc3oo70ll.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\wrc3oo70ll.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^ze6qq6cc.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\ze6qq6cc.exe []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-07-04 118784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aoeyyxqn.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\gzrjgxsu]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\nlvfzcis]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Tci18.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\zuhcrkzd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aoeyyxqn.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\gzrjgxsu]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nlvfzcis]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tci18.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\zuhcrkzd]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010\WNt500x86\RpcSandraSrv.exe"="C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service"
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010\WNt500x86\sandra.mui"="C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010\WNt500x86\sandra.mui:*:Enabled:SiSoftware Sandra Agent Service"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype "
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Documents and Settings\Evča\Plocha\P17535732.JPG-www.facebook.exe"="C:\WINDOWS\nvsvc32.exe:*:Enabled:NVIDIA driver monitor"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
"C:\DOCUME~1\EVA~1\LOCALS~1\Temp\4721249.exe"="C:\DOCUME~1\EVA~1\LOCALS~1\Temp\4721249.exe:*:Enabled:Microsoft Office"
"C:\DOCUME~1\EVA~1\LOCALS~1\Temp\416.exe"="C:\DOCUME~1\EVA~1\LOCALS~1\Temp\416.exe:*:Enabled:Microsoft Office"
"C:\DOCUME~1\EVA~1\LOCALS~1\Temp\49146.exe"="C:\DOCUME~1\EVA~1\LOCALS~1\Temp\49146.exe:*:Enabled:Microsoft Office"
"C:\DOCUME~1\EVA~1\LOCALS~1\Temp\626.exe"="C:\DOCUME~1\EVA~1\LOCALS~1\Temp\626.exe:*:Enabled:Microsoft Office"
"C:\DOCUME~1\EVA~1\LOCALS~1\Temp\632530.exe"="C:\DOCUME~1\EVA~1\LOCALS~1\Temp\632530.exe:*:Enabled:Microsoft Office"
"C:\WINDOWS\System32\svchost.exe"="C:\WINDOWS\System32\svchost.exe:*:Enabled:Microsoft Office"
"C:\WINDOWS\system32\spool\drivers\Distributed.exe"="C:\WINDOWS\system32\spool\drivers\Distributed.exe:*:Enabled:BWProxyClient"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2010-12-06 23:18:16 ----D---- C:\Program Files\trend micro
2010-12-06 23:18:15 ----D---- C:\rsit
2010-12-06 23:17:07 ----D---- C:\Documents and Settings\Administrator.EVCA\Data aplikací\Macromedia
2010-12-06 23:16:26 ----D---- C:\Documents and Settings\Administrator.EVCA\Data aplikací\Mozilla
2010-12-06 23:16:15 ----D---- C:\Documents and Settings\Administrator.EVCA\Data aplikací\Adobe
2010-12-06 23:14:10 ----A---- C:\Documents and Settings\All Users\Data aplikací\xml5.tmp
2010-12-06 23:14:10 ----A---- C:\Documents and Settings\All Users\Data aplikací\xml4.tmp
2010-12-06 23:14:05 ----A---- C:\Documents and Settings\All Users\Data aplikací\xml3.tmp
2010-12-06 23:09:46 ----A---- C:\WINDOWS\ntbtlog.txt
2010-12-04 11:54:58 ----A---- C:\WINDOWS\system32\drivers\Tci18.sys
2010-12-01 09:42:21 ----A---- C:\_srvlog.txt
2010-11-30 13:34:10 ----A---- C:\WINDOWS\system32\drivers\nlvfzcis.sys
2010-11-26 19:31:13 ----A---- C:\WINDOWS\system32\drivers\wcscd.sys
2010-11-26 01:26:11 ----A---- C:\cy.exe
2010-11-24 23:35:04 ----A---- C:\WebHD.exe
2010-11-23 18:36:43 ----D---- C:\WINDOWS\Minidump
2010-11-23 16:13:53 ----HDC---- C:\WINDOWS\ie8
2010-11-23 16:10:02 ----D---- C:\Program Files\QIP
2010-11-22 19:35:15 ----A---- C:\WINDOWS\system32\wuaucldt.exe
2010-11-22 18:55:45 ----A---- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2010-11-22 18:55:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2010-11-22 18:55:03 ----D---- C:\Program Files\Spyware Terminator
2010-11-22 18:40:17 ----D---- C:\WINDOWS\pss
2010-11-22 18:24:17 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-11-22 18:19:16 ----D---- C:\Documents and Settings\Administrator.EVCA\Data aplikací\WinRAR
2010-11-22 18:03:22 ----ASH---- C:\Documents and Settings\Administrator.EVCA\Data aplikací\desktop.ini
2010-11-22 18:03:21 ----SD---- C:\Documents and Settings\Administrator.EVCA\Data aplikací\Microsoft
2010-11-22 18:03:15 ----SHD---- C:\WINDOWS\CSC
2010-11-22 17:31:03 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-11-22 17:30:56 ----D---- C:\Program Files\CleanMyPC
2010-11-19 00:57:59 ----A---- C:\win22.exe
2010-11-17 21:27:25 ----A---- C:\winn27.exe
2010-11-15 22:03:10 ----A---- C:\winnt7.exe
2010-11-11 11:22:08 ----A---- C:\WINDOWS\system32\drivers\aoeyyxqn.sys
2010-11-10 09:00:27 ----A---- C:\jshd.exe
======List of files/folders modified in the last 1 months======
2010-12-06 23:18:16 ----D---- C:\Program Files
2010-12-06 23:15:02 ----D---- C:\WINDOWS\system32
2010-12-06 23:11:39 ----AD---- C:\WINDOWS\Temp
2010-12-06 23:09:46 ----D---- C:\WINDOWS
2010-12-05 23:26:15 ----D---- C:\WINDOWS\Prefetch
2010-12-05 20:23:35 ----D---- C:\WINDOWS\system32\config
2010-12-05 10:21:28 ----D---- C:\WINDOWS\system32\CatRoot2
2010-12-04 11:54:58 ----D---- C:\WINDOWS\system32\drivers
2010-11-27 22:43:34 ----HD---- C:\WINDOWS\inf
2010-11-23 18:39:48 ----RSHD---- C:\RECYCLER
2010-11-23 18:07:22 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-11-23 18:07:22 ----D---- C:\WINDOWS\Media
2010-11-23 18:07:22 ----D---- C:\WINDOWS\Help
2010-11-23 18:07:22 ----D---- C:\Program Files\Internet Explorer
2010-11-23 17:20:12 ----D---- C:\Program Files\ICQ6Toolbar
2010-11-23 17:19:57 ----HD---- C:\Program Files\InstallShield Installation Information
2010-11-23 17:19:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\ICQ
2010-11-23 16:19:43 ----HD---- C:\WINDOWS\msdownld.tmp
2010-11-23 16:17:22 ----D---- C:\WINDOWS\system32\en-US
2010-11-23 16:12:56 ----D---- C:\WINDOWS\Debug
2010-11-22 19:44:33 ----SHD---- C:\WINDOWS\Installer
2010-11-22 19:44:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-11-22 18:03:21 ----D---- C:\Documents and Settings
2010-11-15 23:03:01 ----D---- C:\Program Files\Ask.com
2010-11-15 23:03:00 ----SD---- C:\WINDOWS\Tasks
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aoeyyxqn;aoeyyxqn; C:\WINDOWS\System32\Drivers\aoeyyxqn.sys [2010-11-11 40128]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 Tci18;Tci18; C:\WINDOWS\System32\Drivers\Tci18.sys [2010-12-06 34176]
R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\System32\DRIVERS\ar5211.sys [2006-12-05 529344]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2005-02-17 5632]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 WSIMD;wsimd Service; C:\WINDOWS\System32\DRIVERS\wsimd.sys [2006-07-20 54432]
S0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-08-08 691696]
S1 ATITool;ATITool Overclocking Utility; C:\WINDOWS\system32\DRIVERS\ATITool.sys [2006-11-10 24064]
S1 cdfss;cdfss; \??\C:\WINDOWS\TEMP\cdfss []
S1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
S1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
S1 wcscd;wcscd; C:\WINDOWS\system32\drivers\wcscd.sys [2010-11-26 30560]
S2 nlvfzcis;nlvfzcis; C:\WINDOWS\system32\drivers\nlvfzcis.sys [2010-11-30 82944]
S3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\WINDOWS\ATK0100\ASNDIS5.SYS []
S3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-07-04 2304000]
S3 BthEnum;Služba Bluetooth Enumerator; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-11-03 4394496]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 SANDRA;SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010\WNt500x86\Sandra.sys []
S3 sdbus;sdbus; C:\WINDOWS\System32\DRIVERS\sdbus.sys [2008-04-13 79232]
S3 w29n51;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows XP; C:\WINDOWS\System32\DRIVERS\w29n51.sys []
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 s24trans;WLAN Transport; C:\WINDOWS\System32\DRIVERS\s24trans.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
S2 ACS;Atheros Configuration Service; C:\WINDOWS\System32\acs.exe [2006-11-17 360533]
S2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-07-04 483328]
S2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 DistributedAgentServices;DistributedAgentServices; C:\WINDOWS\system32\spool\drivers\Distributed.exe [2010-12-05 117732]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-07-25 135664]
S2 r1d4yrbuv130y4do;AOL Antivirus Update Service; C:\Documents and Settings\Evča\Data aplikací\Microsoft\joreb.exe []
S2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-11-22 496128]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2010-12-06 23:18:15
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 25 GB (33%) free of 76 GB
Total RAM: 447 MB (32% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:18:28, on 6.12.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\TEMP\BN2.tmp
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WinOverBoost\wob2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Administrator.EVCA\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
O4 - HKLM\..\Run: [reset] regedit /s reset.reg
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [NVIDIA driver monitor] C:\WINDOWS\nvsvc32.exe
O4 - HKLM\..\Run: [sebunni] C:\WINDOWS\system32\mynak.exe
O4 - HKLM\..\Run: [wuaucldt] c:\windows\system32\wuaucldt.exe
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Windows Firewall] C:\DOCUME~1\EVA~1\LOCALS~1\Temp\lsass.exe
O4 - HKLM\..\Run: [WinOverBoost] C:\Program Files\WinOverBoost\wob2.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Atheros Configuration Service (ACS) - Atheros - C:\WINDOWS\System32\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DistributedAgentServices - BrainWork - C:\WINDOWS\system32\spool\drivers\Distributed.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: AOL Antivirus Update Service (r1d4yrbuv130y4do) - Unknown owner - C:\Documents and Settings\Evča\Data aplikací\Microsoft\joreb.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
--
End of file - 5914 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{D4027C7F-154A-4066-A1AD-4243D8127440}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ACU"=C:\Program Files\Atheros\ACU.exe [2006-11-17 348249]
"reset"=regedit /s reset.reg []
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-10-30 16269312]
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"HControl"=C:\WINDOWS\ATK0100\HControl.exe [2006-10-14 110592]
"NVIDIA driver monitor"=C:\WINDOWS\nvsvc32.exe [2010-11-03 90112]
"sebunni"=C:\WINDOWS\system32\mynak.exe []
"wuaucldt"=c:\windows\system32\wuaucldt.exe [2010-11-22 33280]
"Regedit32"=C:\WINDOWS\system32\regedit.exe []
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-11-22 2216960]
"Windows Firewall"=C:\DOCUME~1\EVA~1\LOCALS~1\Temp\lsass.exe []
"WinOverBoost"=C:\Program Files\WinOverBoost\wob2.exe [2004-03-20 119808]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Seznam Postak]
C:\Program Files\Seznam.cz\postak.exe -s []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinOverBoost]
C:\Program Files\WinOverBoost\wob2.exe [2004-03-20 119808]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^0e6qq6c.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\0e6qq6c.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^0lhcc6o.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\0lhcc6o.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^1cyytka.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\1cyytka.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^3qqlccn.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\3qqlccn.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^6mm70tp.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\6mm70tp.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^a3ccxoojalg.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\a3ccxoojalg.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^aa6mm6yy6.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\aa6mm6yy6.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^bhxy0o3aa3.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\bhxy0o3aa3.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^cy726qvl.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\cy726qvl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^effwrriddu.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\effwrriddu.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^hcc6ojk6gg6.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\hcc6ojk6gg6.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^hndezzqvlh.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\hndezzqvlh.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^jek5l0hn.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\jek5l0hn.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^jpk1gccxoo.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\jpk1gccxoo.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^k6ww6ii6.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\k6ww6ii6.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^kk6ww6ii6.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\kk6ww6ii6.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^kv26snnezz.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\kv26snnezz.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^lccxooja.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\lccxooja.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^lccxoojk6gg.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\lccxoojk6gg.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^lhxxtjjpvb.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\lhxxtjjpvb.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^mm3yy6kk6.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\mm3yy6kk6.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^mm5n0o0a.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\mm5n0o0a.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^pq0mms5y.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\pq0mms5y.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^q60c3oo3aa.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\q60c3oo3aa.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^q6cc6ojk.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\q6cc6ojk.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^qmmhyytkkf.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\qmmhyytkkf.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^r1iytkffb.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\r1iytkffb.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^tpffwrridd.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\tpffwrridd.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^u9q1miiduu.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\u9q1miiduu.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^ufbww6ii.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\ufbww6ii.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^w60i3upv.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\w60i3upv.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^wrc3oo70ll.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\wrc3oo70ll.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Evča^Nabídka Start^Programy^Po spuštění^ze6qq6cc.exe]
C:\Documents and Settings\Evča\Nabídka Start\Programy\Po spuštění\ze6qq6cc.exe []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-07-04 118784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aoeyyxqn.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\gzrjgxsu]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\nlvfzcis]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Tci18.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\zuhcrkzd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aoeyyxqn.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\gzrjgxsu]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nlvfzcis]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tci18.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\zuhcrkzd]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010\WNt500x86\RpcSandraSrv.exe"="C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service"
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010\WNt500x86\sandra.mui"="C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010\WNt500x86\sandra.mui:*:Enabled:SiSoftware Sandra Agent Service"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype "
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Documents and Settings\Evča\Plocha\P17535732.JPG-www.facebook.exe"="C:\WINDOWS\nvsvc32.exe:*:Enabled:NVIDIA driver monitor"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
"C:\DOCUME~1\EVA~1\LOCALS~1\Temp\4721249.exe"="C:\DOCUME~1\EVA~1\LOCALS~1\Temp\4721249.exe:*:Enabled:Microsoft Office"
"C:\DOCUME~1\EVA~1\LOCALS~1\Temp\416.exe"="C:\DOCUME~1\EVA~1\LOCALS~1\Temp\416.exe:*:Enabled:Microsoft Office"
"C:\DOCUME~1\EVA~1\LOCALS~1\Temp\49146.exe"="C:\DOCUME~1\EVA~1\LOCALS~1\Temp\49146.exe:*:Enabled:Microsoft Office"
"C:\DOCUME~1\EVA~1\LOCALS~1\Temp\626.exe"="C:\DOCUME~1\EVA~1\LOCALS~1\Temp\626.exe:*:Enabled:Microsoft Office"
"C:\DOCUME~1\EVA~1\LOCALS~1\Temp\632530.exe"="C:\DOCUME~1\EVA~1\LOCALS~1\Temp\632530.exe:*:Enabled:Microsoft Office"
"C:\WINDOWS\System32\svchost.exe"="C:\WINDOWS\System32\svchost.exe:*:Enabled:Microsoft Office"
"C:\WINDOWS\system32\spool\drivers\Distributed.exe"="C:\WINDOWS\system32\spool\drivers\Distributed.exe:*:Enabled:BWProxyClient"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2010-12-06 23:18:16 ----D---- C:\Program Files\trend micro
2010-12-06 23:18:15 ----D---- C:\rsit
2010-12-06 23:17:07 ----D---- C:\Documents and Settings\Administrator.EVCA\Data aplikací\Macromedia
2010-12-06 23:16:26 ----D---- C:\Documents and Settings\Administrator.EVCA\Data aplikací\Mozilla
2010-12-06 23:16:15 ----D---- C:\Documents and Settings\Administrator.EVCA\Data aplikací\Adobe
2010-12-06 23:14:10 ----A---- C:\Documents and Settings\All Users\Data aplikací\xml5.tmp
2010-12-06 23:14:10 ----A---- C:\Documents and Settings\All Users\Data aplikací\xml4.tmp
2010-12-06 23:14:05 ----A---- C:\Documents and Settings\All Users\Data aplikací\xml3.tmp
2010-12-06 23:09:46 ----A---- C:\WINDOWS\ntbtlog.txt
2010-12-04 11:54:58 ----A---- C:\WINDOWS\system32\drivers\Tci18.sys
2010-12-01 09:42:21 ----A---- C:\_srvlog.txt
2010-11-30 13:34:10 ----A---- C:\WINDOWS\system32\drivers\nlvfzcis.sys
2010-11-26 19:31:13 ----A---- C:\WINDOWS\system32\drivers\wcscd.sys
2010-11-26 01:26:11 ----A---- C:\cy.exe
2010-11-24 23:35:04 ----A---- C:\WebHD.exe
2010-11-23 18:36:43 ----D---- C:\WINDOWS\Minidump
2010-11-23 16:13:53 ----HDC---- C:\WINDOWS\ie8
2010-11-23 16:10:02 ----D---- C:\Program Files\QIP
2010-11-22 19:35:15 ----A---- C:\WINDOWS\system32\wuaucldt.exe
2010-11-22 18:55:45 ----A---- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2010-11-22 18:55:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2010-11-22 18:55:03 ----D---- C:\Program Files\Spyware Terminator
2010-11-22 18:40:17 ----D---- C:\WINDOWS\pss
2010-11-22 18:24:17 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-11-22 18:19:16 ----D---- C:\Documents and Settings\Administrator.EVCA\Data aplikací\WinRAR
2010-11-22 18:03:22 ----ASH---- C:\Documents and Settings\Administrator.EVCA\Data aplikací\desktop.ini
2010-11-22 18:03:21 ----SD---- C:\Documents and Settings\Administrator.EVCA\Data aplikací\Microsoft
2010-11-22 18:03:15 ----SHD---- C:\WINDOWS\CSC
2010-11-22 17:31:03 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-11-22 17:30:56 ----D---- C:\Program Files\CleanMyPC
2010-11-19 00:57:59 ----A---- C:\win22.exe
2010-11-17 21:27:25 ----A---- C:\winn27.exe
2010-11-15 22:03:10 ----A---- C:\winnt7.exe
2010-11-11 11:22:08 ----A---- C:\WINDOWS\system32\drivers\aoeyyxqn.sys
2010-11-10 09:00:27 ----A---- C:\jshd.exe
======List of files/folders modified in the last 1 months======
2010-12-06 23:18:16 ----D---- C:\Program Files
2010-12-06 23:15:02 ----D---- C:\WINDOWS\system32
2010-12-06 23:11:39 ----AD---- C:\WINDOWS\Temp
2010-12-06 23:09:46 ----D---- C:\WINDOWS
2010-12-05 23:26:15 ----D---- C:\WINDOWS\Prefetch
2010-12-05 20:23:35 ----D---- C:\WINDOWS\system32\config
2010-12-05 10:21:28 ----D---- C:\WINDOWS\system32\CatRoot2
2010-12-04 11:54:58 ----D---- C:\WINDOWS\system32\drivers
2010-11-27 22:43:34 ----HD---- C:\WINDOWS\inf
2010-11-23 18:39:48 ----RSHD---- C:\RECYCLER
2010-11-23 18:07:22 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-11-23 18:07:22 ----D---- C:\WINDOWS\Media
2010-11-23 18:07:22 ----D---- C:\WINDOWS\Help
2010-11-23 18:07:22 ----D---- C:\Program Files\Internet Explorer
2010-11-23 17:20:12 ----D---- C:\Program Files\ICQ6Toolbar
2010-11-23 17:19:57 ----HD---- C:\Program Files\InstallShield Installation Information
2010-11-23 17:19:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\ICQ
2010-11-23 16:19:43 ----HD---- C:\WINDOWS\msdownld.tmp
2010-11-23 16:17:22 ----D---- C:\WINDOWS\system32\en-US
2010-11-23 16:12:56 ----D---- C:\WINDOWS\Debug
2010-11-22 19:44:33 ----SHD---- C:\WINDOWS\Installer
2010-11-22 19:44:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-11-22 18:03:21 ----D---- C:\Documents and Settings
2010-11-15 23:03:01 ----D---- C:\Program Files\Ask.com
2010-11-15 23:03:00 ----SD---- C:\WINDOWS\Tasks
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aoeyyxqn;aoeyyxqn; C:\WINDOWS\System32\Drivers\aoeyyxqn.sys [2010-11-11 40128]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 Tci18;Tci18; C:\WINDOWS\System32\Drivers\Tci18.sys [2010-12-06 34176]
R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\System32\DRIVERS\ar5211.sys [2006-12-05 529344]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2005-02-17 5632]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 WSIMD;wsimd Service; C:\WINDOWS\System32\DRIVERS\wsimd.sys [2006-07-20 54432]
S0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-08-08 691696]
S1 ATITool;ATITool Overclocking Utility; C:\WINDOWS\system32\DRIVERS\ATITool.sys [2006-11-10 24064]
S1 cdfss;cdfss; \??\C:\WINDOWS\TEMP\cdfss []
S1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
S1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
S1 wcscd;wcscd; C:\WINDOWS\system32\drivers\wcscd.sys [2010-11-26 30560]
S2 nlvfzcis;nlvfzcis; C:\WINDOWS\system32\drivers\nlvfzcis.sys [2010-11-30 82944]
S3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\WINDOWS\ATK0100\ASNDIS5.SYS []
S3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-07-04 2304000]
S3 BthEnum;Služba Bluetooth Enumerator; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-11-03 4394496]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 SANDRA;SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010\WNt500x86\Sandra.sys []
S3 sdbus;sdbus; C:\WINDOWS\System32\DRIVERS\sdbus.sys [2008-04-13 79232]
S3 w29n51;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows XP; C:\WINDOWS\System32\DRIVERS\w29n51.sys []
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 s24trans;WLAN Transport; C:\WINDOWS\System32\DRIVERS\s24trans.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
S2 ACS;Atheros Configuration Service; C:\WINDOWS\System32\acs.exe [2006-11-17 360533]
S2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-07-04 483328]
S2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 DistributedAgentServices;DistributedAgentServices; C:\WINDOWS\system32\spool\drivers\Distributed.exe [2010-12-05 117732]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-07-25 135664]
S2 r1d4yrbuv130y4do;AOL Antivirus Update Service; C:\Documents and Settings\Evča\Data aplikací\Microsoft\joreb.exe []
S2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-11-22 496128]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------