Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Problem notebook

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
erik182
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 26 pro 2010 11:14

Problem notebook

#1 Příspěvek od erik182 »

Ahoj dostal sa mi do ruk notebook mojho tatu , bol zavireny a strasne pomaly nemal tam nainstalovany ziadny antivirus ani firewall .
Nainstaloval som tam antivirus vsetko co naslo odstranil ale pocitac je stale pomaly nejde taskman , nejde spustit Safemode windowsu (pri spustani sa objavi blue dead screen ).
poradte pls
Logfile of random's system information tool 1.08 (written by random/random)
Run by Hojo at 2010-12-26 11:41:44
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 7 GB (34%) free of 20 GB
Total RAM: 247 MB (10% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:46:16, on 26.12.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\dllhost.exe
C:\Documents and Settings\Hojo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Hojo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Hojo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Documents and Settings\Hojo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Hojo\My Documents\Downloads\RSIT.exe
C:\Program Files\trend micro\Hojo.exe
C:\Program Files\STOPzilla!\wscControlSZ.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.intervideo.com/jsp/Product_P ... ale=0x041b
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Anti Trojan Elite] C:\Program Files\Anti Trojan Elite\TJEnder.exe :NO
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/ ... 3112278546
O20 - Winlogon Notify: TPSvc - TPSvc.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe

--
End of file - 4522 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-854245398-1801674531-1004Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-854245398-1801674531-1004UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E3215F20-3212-11D6-9F8B-00D0B743919D}]
STOPzilla Browser Helper Object - C:\Program Files\STOPzilla!\SZIEBHO.dll [2010-12-23 247248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
""= []
"Anti Trojan Elite"=C:\Program Files\Anti Trojan Elite\TJEnder.exe :NO []
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-12-13 281768]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2006-06-06 139264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\TPSvc]
TPSvc.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=1
"DisableTaskMgr"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"F:\VoaxUH.EXE"="F:\VoaxUH.EXE:*:Enabled:ipsec"
"C:\WINDOWS\Explorer.EXE"="C:\WINDOWS\Explorer.EXE:*:Enabled:ipsec"
"C:\Program Files\InterVideo\DVD Check\DVDCheck.exe"="C:\Program Files\InterVideo\DVD Check\DVDCheck.exe:*:Enabled:ipsec"
"C:\Garmin\nRoute\nRoute.exe"="C:\Garmin\nRoute\nRoute.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\hkcmd.exe"="C:\WINDOWS\system32\hkcmd.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\igfxpers.exe"="C:\WINDOWS\system32\igfxpers.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\igfxtray.exe"="C:\WINDOWS\system32\igfxtray.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\wuauclt.exe"="C:\WINDOWS\system32\wuauclt.exe:*:Enabled:ipsec"
"C:\Program Files\AVG\AVG10\avgmfapx.exe"="C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:Inštalátor produktu AVG"
"C:\Program Files\Analog Devices\Core\smax4pnp.exe"="C:\Program Files\Analog Devices\Core\smax4pnp.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\netsh.exe"="C:\WINDOWS\system32\netsh.exe:*:Enabled:ipsec"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-12-26 11:42:10 ----D---- C:\Program Files\trend micro
2010-12-26 11:37:19 ----D---- C:\rsit
2010-12-26 11:23:57 ----D---- C:\Program Files\STOPzilla!
2010-12-26 11:23:53 ----D---- C:\Program Files\Common Files\iS3
2010-12-26 11:22:48 ----D---- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2010-12-26 10:45:16 ----D---- C:\WINDOWS\LastGood
2010-12-26 10:41:14 ----D---- C:\Program Files\Comodo
2010-12-26 10:30:02 ----D---- C:\Documents and Settings\All Users\Application Data\Comodo Downloader
2010-12-26 00:52:09 ----D---- C:\WINDOWS\system32\NtmsData
2010-12-26 00:31:11 ----D---- C:\Documents and Settings\Hojo\Application Data\Avira
2010-12-26 00:23:30 ----A---- C:\WINDOWS\system32\drivers\ssmdrv.sys
2010-12-26 00:23:09 ----A---- C:\WINDOWS\system32\drivers\avipbb.sys
2010-12-26 00:23:09 ----A---- C:\WINDOWS\system32\drivers\avgntmgr.sys
2010-12-26 00:23:09 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2010-12-26 00:23:08 ----A---- C:\WINDOWS\system32\drivers\avgntdd.sys
2010-12-26 00:22:18 ----D---- C:\Program Files\Avira
2010-12-26 00:22:18 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2010-12-25 22:43:29 ----D---- C:\Install
2010-12-25 21:51:17 ----A---- C:\WINDOWS\OEWABLog.txt
2010-12-25 21:45:14 ----D---- C:\WINDOWS\Prefetch
2010-12-25 19:53:49 ----HDC---- C:\WINDOWS\$NtUninstallKB982381$
2010-12-25 19:49:05 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-12-25 19:44:48 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-12-25 19:39:59 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-12-25 19:37:56 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-12-25 19:35:21 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-12-25 19:31:03 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-12-25 19:25:10 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-12-25 19:18:43 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-12-25 19:13:05 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-12-25 19:10:10 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-12-25 19:07:16 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-12-25 19:01:59 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-12-25 18:57:45 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-12-25 18:56:36 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-12-25 18:52:50 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-12-25 18:47:40 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-12-25 18:42:35 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-12-25 18:40:12 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-12-25 18:36:43 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-12-25 18:33:01 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-12-25 18:28:41 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-12-25 18:23:23 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-12-25 18:18:38 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-12-25 18:13:07 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-12-25 18:08:12 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-12-25 18:03:05 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-12-25 17:57:45 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-12-25 17:54:35 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-12-25 17:50:32 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-12-25 17:45:27 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-12-25 17:41:31 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-12-25 17:37:07 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-12-25 17:33:20 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-12-25 17:27:15 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-12-25 17:21:21 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-12-25 17:19:23 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-12-25 17:15:32 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-12-25 17:10:06 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-12-25 17:05:03 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-12-25 17:00:03 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-12-25 16:56:03 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-12-25 16:50:00 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-12-25 16:47:12 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-12-25 16:45:52 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-12-25 16:39:29 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-12-25 16:35:34 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-12-25 16:32:22 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2010-12-25 16:28:31 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-12-25 16:18:31 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-12-25 16:13:25 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-12-25 16:08:28 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-12-25 16:02:35 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-12-25 15:53:16 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-12-25 15:49:14 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-12-25 15:46:53 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-12-25 15:42:12 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-12-25 15:35:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2010-12-25 15:21:50 ----A---- C:\WINDOWS\setuplog.txt
2010-12-25 15:08:39 ----D---- C:\WINDOWS\system32\en-us
2010-12-25 15:08:12 ----D---- C:\WINDOWS\system32\scripting
2010-12-25 15:07:29 ----D---- C:\WINDOWS\l2schemas
2010-12-25 15:07:13 ----D---- C:\WINDOWS\system32\en
2010-12-25 15:07:11 ----D---- C:\WINDOWS\system32\bits
2010-12-25 14:05:26 ----D---- C:\WINDOWS\network diagnostic
2010-12-25 13:32:16 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-12-25 13:31:42 ----D---- C:\WINDOWS\EHome
2010-12-25 00:44:50 ----HDC---- C:\WINDOWS\$NtUninstallKB970430_0$
2010-12-25 00:32:02 ----HDC---- C:\WINDOWS\$NtUninstallKB971737_0$
2010-12-25 00:14:32 ----D---- C:\Program Files\Alwil Software
2010-12-25 00:14:32 ----D---- C:\Documents and Settings\All Users\Application Data\Alwil Software
2010-12-24 21:20:04 ----D---- C:\Documents and Settings\Hojo\Application Data\AVG10
2010-12-24 20:40:41 ----HD---- C:\Documents and Settings\All Users\Application Data\Common Files
2010-12-24 20:19:22 ----D---- C:\Documents and Settings\All Users\Application Data\AVG10
2010-12-24 20:15:26 ----D---- C:\Documents and Settings\Hojo\Application Data\Macromedia
2010-12-24 19:47:40 ----D---- C:\Documents and Settings\All Users\Application Data\MFAData
2010-12-23 22:18:58 ----A---- C:\WINDOWS\zip.exe
2010-12-23 22:18:58 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-12-23 22:18:58 ----A---- C:\WINDOWS\SWSC.exe
2010-12-23 22:18:58 ----A---- C:\WINDOWS\SWREG.exe
2010-12-23 22:18:58 ----A---- C:\WINDOWS\sed.exe
2010-12-23 22:18:58 ----A---- C:\WINDOWS\PEV.exe
2010-12-23 22:18:58 ----A---- C:\WINDOWS\NIRCMD.exe
2010-12-23 22:18:58 ----A---- C:\WINDOWS\MBR.exe
2010-12-23 22:18:58 ----A---- C:\WINDOWS\grep.exe
2010-12-23 22:18:48 ----D---- C:\WINDOWS\ERDNT
2010-12-23 21:33:39 ----D---- C:\Documents and Settings\Hojo\Application Data\Immunet
2010-12-23 21:28:54 ----RA---- C:\WINDOWS\system32\SZIO5.dll
2010-12-23 21:28:54 ----RA---- C:\WINDOWS\system32\SZComp5.dll
2010-12-23 21:28:54 ----RA---- C:\WINDOWS\system32\SZBase5.dll
2010-12-23 21:28:54 ----RA---- C:\WINDOWS\system32\IS3XDat5.dll
2010-12-23 21:28:54 ----RA---- C:\WINDOWS\system32\IS3HTUI5.dll
2010-12-23 21:28:54 ----RA---- C:\WINDOWS\system32\IS3Hks5.dll
2010-12-23 21:28:54 ----RA---- C:\WINDOWS\system32\IS3DBA5.dll
2010-12-23 21:28:52 ----RA---- C:\WINDOWS\system32\IS3Win325.dll
2010-12-23 21:28:52 ----RA---- C:\WINDOWS\system32\IS3UI5.dll
2010-12-23 21:28:52 ----RA---- C:\WINDOWS\system32\IS3Svc5.dll
2010-12-23 21:28:52 ----RA---- C:\WINDOWS\system32\IS3Inet5.dll
2010-12-23 21:28:52 ----RA---- C:\WINDOWS\system32\IS3Base5.dll
2010-12-23 20:42:21 ----HDC---- C:\WINDOWS\$NtUninstallKB978542_0$
2010-12-23 20:42:03 ----HDC---- C:\WINDOWS\$NtUninstallKB970238_0$
2010-12-23 20:41:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979482_0$
2010-12-23 20:41:36 ----HDC---- C:\WINDOWS\$NtUninstallKB978706_0$
2010-12-23 20:41:20 ----HDC---- C:\WINDOWS\$NtUninstallKB960803_0$
2010-12-23 20:41:04 ----HDC---- C:\WINDOWS\$NtUninstallKB973815_0$
2010-12-23 20:40:45 ----HDC---- C:\WINDOWS\$NtUninstallKB975562_0$
2010-12-23 20:40:30 ----HDC---- C:\WINDOWS\$NtUninstallKB956802_0$
2010-12-23 20:38:10 ----HDC---- C:\WINDOWS\$NtUninstallKB982381_0$
2010-12-23 20:36:50 ----HDC---- C:\WINDOWS\$NtUninstallKB975467_0$
2010-12-23 20:36:15 ----HDC---- C:\WINDOWS\$NtUninstallKB968389_0$
2010-12-23 20:17:38 ----A---- C:\WINDOWS\system32\browserchoice.exe
2010-12-23 19:52:08 ----HDC---- C:\WINDOWS\$NtUninstallKB980218_0$
2010-12-23 19:51:57 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2_0$
2010-12-23 19:51:46 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-12-23 19:51:29 ----HDC---- C:\WINDOWS\$NtUninstallKB959426_0$
2010-12-23 19:51:15 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2010-12-23 19:51:03 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2010-12-23 19:50:46 ----HDC---- C:\WINDOWS\$NtUninstallKB960859_0$
2010-12-23 19:50:33 ----HDC---- C:\WINDOWS\$NtUninstallKB971468_0$
2010-12-23 19:49:30 ----HDC---- C:\WINDOWS\$NtUninstallKB979683_0$
2010-12-23 19:48:56 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-12-23 19:48:46 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-12-23 19:48:37 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-12-23 19:48:20 ----HDC---- C:\WINDOWS\$NtUninstallKB980232_0$
2010-12-23 19:47:56 ----HDC---- C:\WINDOWS\$NtUninstallKB981350$
2010-12-23 19:44:30 ----HDC---- C:\WINDOWS\$NtUninstallKB955759_0$
2010-12-23 19:44:16 ----HDC---- C:\WINDOWS\$NtUninstallKB974318_0$
2010-12-23 19:43:59 ----HDC---- C:\WINDOWS\$NtUninstallKB969059_0$
2010-12-23 19:43:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593_0$
2010-12-23 19:43:27 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2010-12-23 19:43:15 ----HDC---- C:\WINDOWS\$NtUninstallKB978037_0$
2010-12-23 19:43:02 ----HDC---- C:\WINDOWS\$NtUninstallKB975713_0$
2010-12-23 19:42:49 ----HDC---- C:\WINDOWS\$NtUninstallKB971657_0$
2010-12-23 19:42:35 ----HDC---- C:\WINDOWS\$NtUninstallKB978338_0$
2010-12-23 19:42:23 ----HDC---- C:\WINDOWS\$NtUninstallKB960225_0$
2010-12-23 19:42:12 ----HDC---- C:\WINDOWS\$NtUninstallKB972270_0$
2010-12-23 19:42:00 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_0$
2010-12-23 19:40:03 ----HDC---- C:\WINDOWS\$NtUninstallKB956572_0$
2010-12-23 19:39:34 ----HDC---- C:\WINDOWS\$NtUninstallKB956844_0$
2010-12-23 19:39:21 ----HDC---- C:\WINDOWS\$NtUninstallKB961501_0$
2010-12-23 19:38:53 ----HDC---- C:\WINDOWS\$NtUninstallKB975561_0$
2010-12-23 19:38:37 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-12-23 19:38:26 ----HDC---- C:\WINDOWS\$NtUninstallKB973869_0$
2010-12-23 19:38:14 ----HDC---- C:\WINDOWS\$NtUninstallKB975025_0$
2010-12-23 19:37:46 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9L$
2010-12-23 19:37:19 ----HDC---- C:\WINDOWS\$NtUninstallKB952004_0$
2010-12-23 19:37:04 ----HDC---- C:\WINDOWS\$NtUninstallKB974571_0$
2010-12-23 19:36:47 ----HDC---- C:\WINDOWS\$NtUninstallKB975560_0$
2010-12-23 19:36:31 ----HDC---- C:\WINDOWS\$NtUninstallKB973507_0$
2010-12-23 19:36:17 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-12-23 19:35:25 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-12-23 19:35:05 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_0$
2010-12-23 19:34:53 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
2010-12-23 19:34:43 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-12-23 19:34:34 ----HDC---- C:\WINDOWS\$NtUninstallKB978601_0$
2010-12-23 19:34:15 ----HDC---- C:\WINDOWS\$NtUninstallKB979559_0$
2010-12-23 19:34:00 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2010-12-23 19:33:46 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-12-23 19:32:19 ----HDC---- C:\WINDOWS\$NtUninstallKB967715_0$
2010-12-23 19:31:56 ----HDC---- C:\WINDOWS\$NtUninstallKB974392_0$
2010-12-23 19:31:45 ----HDC---- C:\WINDOWS\$NtUninstallKB977914_0$
2010-12-23 19:31:19 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
2010-12-23 19:31:05 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-12-23 19:30:55 ----HDC---- C:\WINDOWS\$NtUninstallKB979309_0$
2010-12-23 19:30:44 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-12-23 19:30:12 ----D---- C:\WINDOWS\ServicePackFiles
2010-12-23 19:30:08 ----HDC---- C:\WINDOWS\$NtUninstallKB958470$
2010-12-23 19:29:55 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2010-12-23 19:29:32 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
2010-12-23 19:27:29 ----D---- C:\Program Files\MSXML 4.0
2010-12-23 19:26:21 ----HDC---- C:\WINDOWS\$NtUninstallKB923561_0$
2010-12-23 19:13:17 ----N---- C:\WINDOWS\system32\drivers\watv10nt.sys
2010-12-23 19:13:16 ----N---- C:\WINDOWS\system32\drivers\watv06nt.sys
2010-12-23 19:13:16 ----N---- C:\WINDOWS\system32\drivers\wadv11nt.sys
2010-12-23 19:13:16 ----N---- C:\WINDOWS\system32\drivers\wadv09nt.sys
2010-12-23 19:13:16 ----N---- C:\WINDOWS\system32\drivers\wadv08nt.sys
2010-12-23 19:13:16 ----N---- C:\WINDOWS\system32\drivers\wadv07nt.sys
2010-12-23 19:12:57 ----N---- C:\WINDOWS\system32\drivers\slwdmsup.sys
2010-12-23 19:12:57 ----N---- C:\WINDOWS\system32\drivers\slnthal.sys
2010-12-23 19:12:56 ----N---- C:\WINDOWS\system32\drivers\slntamr.sys
2010-12-23 19:12:56 ----N---- C:\WINDOWS\system32\drivers\slnt7554.sys
2010-12-23 19:12:53 ----N---- C:\WINDOWS\system32\drivers\s3gnbm.sys
2010-12-23 19:12:53 ----N---- C:\WINDOWS\system32\drivers\recagent.sys
2010-12-23 19:12:48 ----N---- C:\WINDOWS\system32\drivers\nv4_mini.sys
2010-12-23 19:12:47 ----N---- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2010-12-23 19:12:44 ----N---- C:\WINDOWS\system32\drivers\mtxparhm.sys
2010-12-23 19:12:43 ----N---- C:\WINDOWS\system32\drivers\mtlstrm.sys
2010-12-23 19:12:43 ----N---- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2010-12-23 19:12:32 ----N---- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2010-12-23 19:12:20 ----N---- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2010-12-23 19:12:20 ----N---- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2010-12-23 19:12:19 ----N---- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2010-12-23 19:04:17 ----N---- C:\WINDOWS\system32\drivers\atinxsxx.sys
2010-12-23 19:04:17 ----N---- C:\WINDOWS\system32\drivers\atinxbxx.sys
2010-12-23 19:04:17 ----N---- C:\WINDOWS\system32\drivers\atintuxx.sys
2010-12-23 19:04:17 ----N---- C:\WINDOWS\system32\drivers\atinttxx.sys
2010-12-23 19:04:17 ----N---- C:\WINDOWS\system32\drivers\atinsnxx.sys
2010-12-23 19:04:16 ----N---- C:\WINDOWS\system32\drivers\atinrvxx.sys
2010-12-23 19:04:16 ----N---- C:\WINDOWS\system32\drivers\atinraxx.sys
2010-12-23 19:04:16 ----N---- C:\WINDOWS\system32\drivers\atinpdxx.sys
2010-12-23 19:04:16 ----N---- C:\WINDOWS\system32\drivers\atinmdxx.sys
2010-12-23 19:04:16 ----N---- C:\WINDOWS\system32\drivers\atinbtxx.sys
2010-12-23 19:04:15 ----N---- C:\WINDOWS\system32\drivers\ati2mtag.sys
2010-12-23 19:04:15 ----N---- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2010-12-23 19:04:15 ----N---- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2010-12-23 19:04:15 ----N---- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1snxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1raxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1btxx.sys
2010-12-23 16:32:17 ----N---- C:\WINDOWS\system32\drivers\bthport.sys
2010-12-23 16:13:32 ----N---- C:\WINDOWS\system32\tzchange.exe
2010-12-23 15:45:19 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2010-12-23 15:39:15 ----D---- C:\WINDOWS\system32\MpEngineStore
2010-12-23 15:05:28 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2010-12-23 15:05:26 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2010-12-23 15:05:24 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2010-12-23 14:31:54 ----D---- C:\WINDOWS\system32\LogFiles
2010-12-23 14:27:43 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-12-23 14:27:43 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

======List of files/folders modified in the last 1 months======

2010-12-26 11:44:39 ----D---- C:\WINDOWS\Temp
2010-12-26 11:42:10 ----RD---- C:\Program Files
2010-12-26 11:26:27 ----SHD---- C:\WINDOWS\Installer
2010-12-26 11:24:57 ----D---- C:\WINDOWS\WinSxS
2010-12-26 11:23:53 ----D---- C:\WINDOWS\system32\drivers
2010-12-26 11:23:53 ----D---- C:\Program Files\Common Files
2010-12-26 11:23:28 ----D---- C:\WINDOWS\system32
2010-12-26 11:07:52 ----HD---- C:\WINDOWS\inf
2010-12-26 10:45:16 ----D---- C:\WINDOWS
2010-12-26 00:52:07 ----D---- C:\WINDOWS\repair
2010-12-26 00:51:37 ----D---- C:\WINDOWS\Registration
2010-12-26 00:27:22 ----D---- C:\WINDOWS\system32\CatRoot2
2010-12-26 00:20:49 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-12-26 00:12:47 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-12-25 23:55:58 ----HD---- C:\WINDOWS\$hf_mig$
2010-12-25 23:18:36 ----D---- C:\WINDOWS\system32\CatRoot
2010-12-25 22:27:57 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-12-25 21:55:25 ----D---- C:\WINDOWS\Debug
2010-12-25 21:41:13 ----D---- C:\WINDOWS\system32\Setup
2010-12-25 21:41:13 ----D---- C:\WINDOWS\AppPatch
2010-12-25 21:41:12 ----D---- C:\WINDOWS\system32\wbem
2010-12-25 21:41:09 ----RSD---- C:\WINDOWS\Fonts
2010-12-25 19:13:57 ----D---- C:\Program Files\Outlook Express
2010-12-25 18:53:31 ----D---- C:\Program Files\Movie Maker
2010-12-25 15:47:23 ----D---- C:\Program Files\Messenger
2010-12-25 15:37:52 ----D---- C:\WINDOWS\security
2010-12-25 15:21:22 ----D---- C:\WINDOWS\system32\inetsrv
2010-12-25 15:13:13 ----D---- C:\WINDOWS\ime
2010-12-25 15:11:57 ----D---- C:\WINDOWS\Help
2010-12-25 15:10:20 ----D---- C:\WINDOWS\system32\usmt
2010-12-25 15:09:29 ----D---- C:\WINDOWS\PeerNet
2010-12-25 15:07:33 ----D---- C:\Program Files\Internet Explorer
2010-12-25 14:36:42 ----D---- C:\WINDOWS\msagent
2010-12-25 14:36:28 ----D---- C:\WINDOWS\system32\oobe
2010-12-25 14:36:24 ----D---- C:\WINDOWS\system32\npp
2010-12-25 14:36:16 ----D---- C:\WINDOWS\mui
2010-12-25 14:35:50 ----D---- C:\WINDOWS\system32\Com
2010-12-25 14:34:50 ----D---- C:\WINDOWS\srchasst
2010-12-25 14:34:27 ----D---- C:\WINDOWS\system32\Restore
2010-12-25 14:27:15 ----D---- C:\WINDOWS\system
2010-12-25 14:22:32 ----D---- C:\Program Files\NetMeeting
2010-12-25 14:21:58 ----D---- C:\Program Files\Windows Media Player
2010-12-25 14:21:50 ----D---- C:\Program Files\Windows NT
2010-12-25 14:21:22 ----D---- C:\Program Files\Common Files\System
2010-12-25 13:56:16 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-12-25 00:24:27 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-12-24 23:29:58 ----A---- C:\WINDOWS\system32\MRT.exe
2010-12-24 20:15:17 ----D---- C:\Documents and Settings\Hojo\Application Data\Adobe
2010-12-24 20:00:35 ----D---- C:\Program Files\Common Files\Teleca Shared
2010-12-24 19:53:10 ----D---- C:\Program Files\Codec Pack - All In 1
2010-12-24 19:51:52 ----D---- C:\Program Files\CCleaner
2010-12-24 19:43:12 ----SD---- C:\WINDOWS\Tasks
2010-12-24 19:36:07 ----D---- C:\Garmin
2010-12-24 10:59:43 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-12-23 16:20:40 ----D---- C:\WINDOWS\SoftwareDistribution
2010-12-23 14:51:30 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-12-19 18:00:52 ----A---- C:\WINDOWS\system.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Texas Instruments OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 szkg5;szkg5; C:\WINDOWS\system32\DRIVERS\szkg.sys [2009-12-07 61328]
R0 szkgfs;szkgfs; C:\WINDOWS\system32\drivers\szkgfs.sys [2010-05-12 59280]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2010-12-13 135096]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-12-13 61960]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2006-02-28 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2006-02-28 55936]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2006-01-31 176128]
R3 AEAudioService;AEAudio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2005-06-07 152960]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 BCM43XX;Broadcom 802.11 ovládač sieťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2006-04-28 429184]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2005-08-05 45312]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2006-06-06 1168860]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2006-03-31 193056]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S0 is3srv;is3srv; C:\WINDOWS\system32\drivers\is3srv.sys [2009-12-07 61328]
S1 bofikpia;bofikpia; \??\C:\WINDOWS\system32\drivers\bofikpia.sys []
S1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2010-06-17 28520]
S2 ATE_PROCMON;ATE_PROCMON; \??\C:\Program Files\Anti Trojan Elite\ATEPMon.sys []
S3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys []
S3 dac970nt;dac970nt; \??\C:\WINDOWS\system32\drivers\pksmjm.sys []
S3 grmnusb;grmnusb; C:\WINDOWS\system32\drivers\grmnusb.sys [2003-09-23 7296]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM); C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys [2006-11-10 61600]
S3 SE2Emdfl;Sony Ericsson Device 046 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\SE2Emdfl.sys [2006-11-10 9360]
S3 SE2Emdm;Sony Ericsson Device 046 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\SE2Emdm.sys [2006-11-10 97184]
S3 SE2Emgmt;Sony Ericsson Device 046 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\SE2Emgmt.sys [2006-11-10 88688]
S3 se2End5;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (NDIS); C:\WINDOWS\system32\DRIVERS\se2End5.sys [2006-11-10 18704]
S3 SE2Eobex;Sony Ericsson Device 046 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\SE2Eobex.sys [2006-11-10 86560]
S3 se2Eunic;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (WDM); C:\WINDOWS\system32\DRIVERS\se2Eunic.sys [2006-11-10 90800]
S3 Ser2pl;Prolific Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2004-06-28 42752]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-12-13 267944]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-12-13 135336]
R2 szserver;STOPzilla Service; C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe [2010-12-23 62928]
S2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]

-----------------EOF-----------------
info
info.txt logfile of random's system information tool 1.08 2010-12-26 11:47:27

======Uninstall list======

-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
Broadcom 440x 10/100 Integrated Controller-->MsiExec.exe /X{9C9D0F85-5658-4A5E-95A9-65F7DB2916EE}
Broadcom 802.11 Wireless LAN Adapter-->"C:\Program Files\Broadcom\Broadcom 802.11\Driver\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="C:\Program Files\Broadcom\Broadcom 802.11\Driver"
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Codec Pack - All In 1 6.0.3.0-->C:\WINDOWS\iun6002.exe "C:\Program Files\Codec Pack - All In 1\irunin.ini"
Comodo TrustConnect™ v.1.7.1-->"C:\Program Files\Comodo\TrustConnect\unins000.exe"
Garmin City Navigator Europe v9-->MsiExec.exe /X{2697C026-58DE-4A42-83E5-5837C999630A}
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB981793)-->"C:\WINDOWS\$NtUninstallKB981793$\spuninst\spuninst.exe"
Intel(R) Graphics Media Accelerator Driver-->RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_27A6 PCI\VEN_8086&DEV_27A2
InterVideo DVD Check-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5D97A4A7-C274-4B63-86D9-07A33435F505}\setup.exe" REMOVEALL
InterVideo WinDVD-->"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
Map Explorer 8 8.0.36-4-->"C:\Program Files\Navigator8\MapExplorer\unins001.exe"
MapSource - European City Select v6-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{88AD4F45-AF1E-4A47-A9CE-8A542C6B3728} /l1033
Microsoft .NET Framework 1.1 Security Update (KB979906)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M979906\M979906Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft AutoRoute 2007-->MsiExec.exe /I{C82185E8-C27B-4EF4-2007-3333BC2C2B6D}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
nRoute 2.61 - Slovenčina -->C:\WINDOWS\iun6002ev.exe "C:\Garmin\nRoute\irunin.ini"
nRoute-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2D4ECAAA-28A3-4D3D-A030-E6025EB3E52C}\Setup.exe" -l0x9 AddRemove
nRoute-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AE97D691-DB7D-4735-8D6D-0E0164F75B94}\setup.exe" -l0x9 AddRemove
OpenOffice.org 2.0-->MsiExec.exe /I{137A1D92-07AA-4AFB-99DA-EB771A85AFFE}
PC Navigator 8 8.0.36-1-->"C:\Program Files\Navigator8\PC_Navigator\unins000.exe"
PL-2303 USB-to-Serial-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\Setup.exe" -l0x9 Installed
RealSpeak Solo for UK English Emily-->MsiExec.exe /I{A182077A-8D6B-4194-B48A-B4DC37C69907}
runtime-->MsiExec.exe /I{D88C3E7C-1DA6-4AD7-97FC-75BC8705B266}
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9L$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB978695)-->"C:\WINDOWS\$NtUninstallKB978695_WM9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB2229593)-->"C:\WINDOWS\$NtUninstallKB2229593$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971468)-->"C:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Security Update for Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975560)-->"C:\WINDOWS\$NtUninstallKB975560$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975561)-->"C:\WINDOWS\$NtUninstallKB975561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975562)-->"C:\WINDOWS\$NtUninstallKB975562$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975713)-->"C:\WINDOWS\$NtUninstallKB975713$\spuninst\spuninst.exe"
Security Update for Windows XP (KB977816)-->"C:\WINDOWS\$NtUninstallKB977816$\spuninst\spuninst.exe"
Security Update for Windows XP (KB977914)-->"C:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978037)-->"C:\WINDOWS\$NtUninstallKB978037$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978338)-->"C:\WINDOWS\$NtUninstallKB978338$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978542)-->"C:\WINDOWS\$NtUninstallKB978542$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978601)-->"C:\WINDOWS\$NtUninstallKB978601$\spuninst\spuninst.exe"
Security Update for Windows XP (KB978706)-->"C:\WINDOWS\$NtUninstallKB978706$\spuninst\spuninst.exe"
Security Update for Windows XP (KB979309)-->"C:\WINDOWS\$NtUninstallKB979309$\spuninst\spuninst.exe"
Security Update for Windows XP (KB979482)-->"C:\WINDOWS\$NtUninstallKB979482$\spuninst\spuninst.exe"
Security Update for Windows XP (KB979559)-->"C:\WINDOWS\$NtUninstallKB979559$\spuninst\spuninst.exe"
Security Update for Windows XP (KB979683)-->"C:\WINDOWS\$NtUninstallKB979683$\spuninst\spuninst.exe"
Security Update for Windows XP (KB980195)-->"C:\WINDOWS\$NtUninstallKB980195$\spuninst\spuninst.exe"
Security Update for Windows XP (KB980218)-->"C:\WINDOWS\$NtUninstallKB980218$\spuninst\spuninst.exe"
Security Update for Windows XP (KB980232)-->"C:\WINDOWS\$NtUninstallKB980232$\spuninst\spuninst.exe"
Security Update for Windows XP (KB982381)-->"C:\WINDOWS\$NtUninstallKB982381$\spuninst\spuninst.exe"
Setup Utility-->"C:\Program Files\Navigator8\Setup Utility\unins000.exe"
Sony Ericsson PC Suite-->MsiExec.exe /I{B56B1487-9A26-4AFD-A1FD-949C40F5F2BC}
SoundMAX-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\Setup.exe" -l0x9 -removeonly
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
STOPzilla-->MsiExec.exe /X{94A61BF7-F8EE-46D1-944B-C765A7FF117A}
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Total Commander (Remove or Repair)-->C:\Program Files\totalcmd\tcuninst.exe
Update for Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Update for Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
Update for Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
Update for Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
Update for Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

======Security center information======

AV: AntiVir Desktop
FW: AVG Firewall (disabled)

======System event log======

Computer Name: HOJO
Event Code: 26
Message: Application popup: NOTEPAD.EXE - DLL Initialization Failed : The application failed to initialize because the window station is shutting down.

Record Number: 8499
Source Name: Application Popup
Time Written: 20101223155911.000000+060
Event Type: informácie
User:

Computer Name: HOJO
Event Code: 26
Message: Application popup: netsh.exe - Application Error : The application failed to initialize properly (0xc0000142). Click on OK to terminate the application.

Record Number: 8498
Source Name: Application Popup
Time Written: 20101223155859.000000+060
Event Type: informácie
User:

Computer Name: HOJO
Event Code: 1074
Message: The process winlogon.exe has initiated the restart of HOJO for the following reason: No title for this reason could be found

Minor Reason: 0x12

Shutdown Type: reboot

Comment:

Record Number: 8497
Source Name: USER32
Time Written: 20101223155843.000000+060
Event Type: informácie
User: NT AUTHORITY\SYSTEM

Computer Name: HOJO
Event Code: 18
Message: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on 27. decembra 2010 at 18:00:
- Security Update for Windows XP (KB923561)
- Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB954430)
- Security Update for Windows XP (KB955069)
- Security Update for Windows XP (KB958644)
- Security Update for Windows XP (KB958470)
- Security Update for Windows Media Format Runtime 9, 9.5 & 11 for Windows XP SP2 (KB978695)
- Security Update for Windows XP (KB979309)
- Security Update for Windows XP (KB978601)
- Microsoft .NET Framework 1.1 SP1 Security Update for Windows 2000 and Windows XP (KB979906)

Record Number: 8496
Source Name: Windows Update Agent
Time Written: 20101223155833.000000+060
Event Type: informácie
User:

Computer Name: HOJO
Event Code: 18
Message: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on 27. decembra 2010 at 18:00:
- Security Update for Windows XP (KB923561)
- Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB954430)
- Security Update for Windows XP (KB955069)
- Security Update for Windows XP (KB958644)
- Security Update for Windows XP (KB958470)
- Security Update for Windows Media Format Runtime 9, 9.5 & 11 for Windows XP SP2 (KB978695)
- Security Update for Windows XP (KB979309)
- Security Update for Windows XP (KB978601)

Record Number: 8495
Source Name: Windows Update Agent
Time Written: 20101223155718.000000+060
Event Type: informácie
User:

=====Application event log=====

Computer Name: HOJO
Event Code: 1
Message: The VB Application identified by the event source logged this Application : Thread ID: 1624 ,Logged:

Record Number: 25865505
Source Name: VBRuntime
Time Written: 20101223153820.000000+060
Event Type: informácie
User:

Computer Name: HOJO
Event Code: 1
Message: The VB Application identified by the event source logged this Application : Thread ID: 1624 ,Logged:

Record Number: 25865504
Source Name: VBRuntime
Time Written: 20101223153820.000000+060
Event Type: informácie
User:

Computer Name: HOJO
Event Code: 1
Message: The VB Application identified by the event source logged this Application : Thread ID: 1624 ,Logged:

Record Number: 25865503
Source Name: VBRuntime
Time Written: 20101223153820.000000+060
Event Type: informácie
User:

Computer Name: HOJO
Event Code: 1
Message: The VB Application identified by the event source logged this Application : Thread ID: 1624 ,Logged:

Record Number: 25865502
Source Name: VBRuntime
Time Written: 20101223153820.000000+060
Event Type: informácie
User:

Computer Name: HOJO
Event Code: 1
Message: The VB Application identified by the event source logged this Application : Thread ID: 1624 ,Logged:

Record Number: 25865501
Source Name: VBRuntime
Time Written: 20101223153820.000000+060
Event Type: informácie
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files\Common Files\Teleca Shared
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 14 Stepping 8, GenuineIntel
"PROCESSOR_REVISION"=0e08
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"DEFAULT_CA_NR"=CA6

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problem notebook

#2 Příspěvek od vyosek »

Zdravim a pekny den preji :)

:arrow: Doporucuji odinstalovat Spybot - Search & Destroy - program ma uz nejlepsi leta davno za sebou a posledni cca 3 roky neni schopen celit aktualnim hrozbam - po ukonceni leceni, tam dame lepsi nahradu :wink:

:arrow: Odinstalujte C:\Program Files\STOPzilla! - neni to moc vhodny programek :roll:

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

erik182
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 26 pro 2010 11:14

Re: Problem notebook

#3 Příspěvek od erik182 »

log z combofix
ComboFix 10-12-25.02 - Hojo 26.12.2010 12:42:43.1.1 - x86
Running from: c:\documents and settings\Hojo\My Documents\Downloads\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Hojo\AUTORUN.INF
c:\documents and settings\Hojo\Documents .lnk
c:\documents and settings\Hojo\Music .lnk
c:\documents and settings\Hojo\New Folder .lnk
c:\documents and settings\Hojo\Passwords .lnk
c:\documents and settings\Hojo\Pictures .lnk
c:\documents and settings\Hojo\Video .lnk

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_DAC970NT
-------\Service_dac970nt


((((((((((((((((((((((((( Files Created from 2010-11-26 to 2010-12-26 )))))))))))))))))))))))))))))))
.

2010-12-26 10:42 . 2010-12-26 10:46 -------- d-----w- c:\program files\trend micro
2010-12-26 10:37 . 2010-12-26 10:47 -------- d-----w- C:\rsit
2010-12-26 10:22 . 2010-12-26 11:49 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2010-12-26 09:45 . 2010-12-26 09:45 -------- d-----w- c:\windows\LastGood.Tmp
2010-12-26 09:41 . 2010-12-26 09:41 -------- d-----w- c:\program files\Comodo
2010-12-26 09:30 . 2010-12-26 09:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Comodo Downloader
2010-12-25 23:52 . 2010-12-26 01:32 -------- d-----w- c:\windows\system32\NtmsData
2010-12-25 23:31 . 2010-12-25 23:31 -------- d-----w- c:\documents and settings\Hojo\Application Data\Avira
2010-12-25 23:23 . 2010-12-13 07:40 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-12-25 23:23 . 2010-12-13 07:40 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-12-25 23:23 . 2010-06-17 13:27 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-12-25 23:23 . 2010-06-17 13:27 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-12-25 23:22 . 2010-12-25 23:22 -------- d-----w- c:\program files\Avira
2010-12-25 23:22 . 2010-12-25 23:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-12-25 21:43 . 2010-12-25 21:43 -------- d-----w- C:\Install
2010-12-25 14:08 . 2010-12-25 14:10 -------- d-----w- c:\windows\system32\scripting
2010-12-25 14:07 . 2010-12-25 14:07 -------- d-----w- c:\windows\l2schemas
2010-12-25 14:07 . 2010-12-25 14:08 -------- d-----w- c:\windows\system32\en
2010-12-25 14:07 . 2010-12-25 14:07 -------- d-----w- c:\windows\system32\bits
2010-12-25 12:31 . 2010-12-25 12:31 -------- d-----w- c:\windows\EHome
2010-12-24 23:14 . 2010-12-24 23:14 -------- d-----w- c:\program files\Alwil Software
2010-12-24 23:14 . 2010-12-24 23:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-12-24 20:20 . 2010-12-24 20:20 -------- d-----w- c:\documents and settings\Hojo\Application Data\AVG10
2010-12-24 19:40 . 2010-12-24 19:40 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
2010-12-24 19:19 . 2010-12-25 21:37 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG10
2010-12-24 18:47 . 2010-12-24 19:14 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2010-12-24 18:43 . 2010-12-24 18:45 -------- d-----w- c:\documents and settings\Hojo\Local Settings\Application Data\Temp
2010-12-24 18:42 . 2010-12-24 18:53 -------- d-----w- c:\documents and settings\Hojo\Local Settings\Application Data\Google
2010-12-23 20:33 . 2010-12-24 09:59 -------- d-----w- c:\documents and settings\All Users\Immunet
2010-12-23 20:33 . 2010-12-23 20:33 -------- d-----w- c:\documents and settings\Hojo\Application Data\Immunet
2010-12-23 19:17 . 2010-12-24 21:40 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-12-23 18:30 . 2010-12-25 13:24 -------- d-----w- c:\windows\ServicePackFiles
2010-12-23 18:27 . 2010-12-23 18:27 -------- d-----w- c:\program files\MSXML 4.0
2010-12-23 18:13 . 2004-08-03 21:29 25471 ------w- c:\windows\system32\drivers\watv10nt.sys
2010-12-23 18:13 . 2004-08-03 21:29 22271 ------w- c:\windows\system32\drivers\watv06nt.sys
2010-12-23 18:13 . 2004-08-03 21:29 11935 ------w- c:\windows\system32\drivers\wadv11nt.sys
2010-12-23 18:13 . 2004-08-03 21:29 11871 ------w- c:\windows\system32\drivers\wadv09nt.sys
2010-12-23 18:13 . 2004-08-03 21:29 11807 ------w- c:\windows\system32\drivers\wadv07nt.sys
2010-12-23 18:13 . 2004-08-03 21:29 11295 ------w- c:\windows\system32\drivers\wadv08nt.sys
2010-12-23 18:04 . 2004-08-03 21:29 73216 ------w- c:\windows\system32\drivers\atintuxx.sys
2010-12-23 15:32 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-12-23 15:32 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-12-23 15:26 . 2009-12-31 16:50 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2010-12-23 15:25 . 2010-02-24 13:11 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-12-23 15:24 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-12-23 15:23 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-12-23 15:21 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-12-23 15:21 . 2009-10-15 16:28 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-12-23 15:20 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2010-12-23 15:20 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2010-12-23 15:20 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2010-12-23 15:20 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2010-12-23 15:20 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2010-12-23 15:20 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-12-23 15:20 . 2009-06-25 08:25 730112 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2010-12-23 15:20 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2010-12-23 15:19 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2010-12-23 15:19 . 2010-02-16 14:08 2146304 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-12-23 15:19 . 2010-02-17 08:10 2189952 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-12-23 15:19 . 2010-02-16 13:25 2024448 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-12-23 15:13 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-12-23 14:51 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-12-23 14:45 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2010-12-23 14:45 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-12-23 14:39 . 2010-12-23 14:58 -------- d-----w- c:\windows\system32\MpEngineStore
2010-12-23 14:05 . 2009-08-06 18:24 21728 ----a-w- c:\windows\system32\wucltui.dll.mui
2010-12-23 14:05 . 2009-08-06 18:24 17632 ----a-w- c:\windows\system32\wuaueng.dll.mui
2010-12-23 14:05 . 2009-08-06 18:24 15072 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2010-12-23 14:05 . 2009-08-06 18:24 15064 ----a-w- c:\windows\system32\wuapi.dll.mui
2010-12-23 13:31 . 2010-12-23 13:31 -------- d-----w- c:\windows\system32\LogFiles
2010-12-23 13:27 . 2010-12-26 11:52 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-12-23 13:27 . 2010-12-26 11:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-12-13 281768]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Garmin\\nRoute\\nRoute.exe"=
"c:\\WINDOWS\\system32\\wuauclt.exe"=
"c:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/26/2010 12:23 AM 135336]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys --> c:\windows\system32\drivers\is3srv.sys [?]
S0 szkg5;szkg5;c:\windows\system32\DRIVERS\szkg.sys --> c:\windows\system32\DRIVERS\szkg.sys [?]
S0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys --> c:\windows\system32\drivers\szkgfs.sys [?]
S1 bofikpia;bofikpia;\??\c:\windows\system32\drivers\bofikpia.sys --> c:\windows\system32\drivers\bofikpia.sys [?]
S2 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys --> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - SSMDRV
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://www.intervideo.com/jsp/Product_Promote. ... ale=0x041b
.
.
------- File Associations -------
.
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-Anti Trojan Elite - c:\program files\Anti Trojan Elite\TJEnder.exe
Notify-TPSvc - TPSvc.dll
AddRemove-Broadcom 802.11b Network Adapter - c:\program files\Broadcom\Broadcom 802.11\Driver\bcmwlu00.exe
AddRemove-CCleaner - c:\program files\CCleaner\uninst.exe
AddRemove-MSNINST - c:\program files\MSN\MsnInstaller\msninst.exe
AddRemove-Windows Media Format Runtime - c:\program files\Windows Media Player\wmsetsdk.exe
AddRemove-{91810AFC-A4F8-4EBA-A5AA-B198BBC81144} - c:\program files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-26 13:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
.
**************************************************************************
.
Completion time: 2010-12-26 14:00:32 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-26 13:00

Pre-Run: 7 074 770 944 bytes free
Post-Run: 7 279 321 088 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 4AFFC2B978F8D202D47858B312B724D0

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problem notebook

#4 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    File::
    C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-854245398-1801674531-1004Core.job
    C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-854245398-1801674531-1004UA.job
    
    Driver::
    is3srv
    szkg5
    szkgfs
    bofikpia
    ATE_PROCMON
    
    Collect::
    c:\windows\system32\drivers\is3srv.sys
    c:\windows\system32\DRIVERS\szkg.sys
    c:\windows\system32\drivers\szkgfs.sys
    c:\windows\system32\drivers\bofikpia.sys
    
    Folder::
    c:\program files\Anti Trojan Elite
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000000
    "FirewallOverride"=dword:00000000
    
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
    "AntiVirusOverride"=dword:00000000
    "AntiVirusDisableNotify"=dword:00000000
    "FirewallDisableNotify"=dword:00000000
    "FirewallOverride"=dword:00000000
    "UpdatesDisableNotify"=dword:00000000
    "UacDisableNotify"=dword:00000000
    
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

erik182
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 26 pro 2010 11:14

Re: Problem notebook

#5 Příspěvek od erik182 »

ComboFix 10-12-25.02 - Hojo 26.12.2010 14:19:42.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.247.124 [GMT 1:00]
Running from: c:\documents and settings\Hojo\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Hojo\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}

FILE ::
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-854245398-1801674531-1004Core.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-854245398-1801674531-1004UA.job"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ATE_PROCMON
-------\Legacy_SZKG5
-------\Legacy_SZKGFS
-------\Service_ATE_PROCMON
-------\Service_bofikpia
-------\Service_is3srv
-------\Service_szkg5
-------\Service_szkgfs


((((((((((((((((((((((((( Files Created from 2010-11-26 to 2010-12-26 )))))))))))))))))))))))))))))))
.

2010-12-26 10:42 . 2010-12-26 10:46 -------- d-----w- c:\program files\trend micro
2010-12-26 10:37 . 2010-12-26 10:47 -------- d-----w- C:\rsit
2010-12-26 10:22 . 2010-12-26 11:49 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2010-12-26 09:41 . 2010-12-26 09:41 -------- d-----w- c:\program files\Comodo
2010-12-26 09:30 . 2010-12-26 09:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Comodo Downloader
2010-12-25 23:52 . 2010-12-26 01:32 -------- d-----w- c:\windows\system32\NtmsData
2010-12-25 23:31 . 2010-12-25 23:31 -------- d-----w- c:\documents and settings\Hojo\Application Data\Avira
2010-12-25 23:23 . 2010-12-13 07:40 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-12-25 23:23 . 2010-12-13 07:40 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-12-25 23:23 . 2010-06-17 13:27 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-12-25 23:23 . 2010-06-17 13:27 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-12-25 23:22 . 2010-12-25 23:22 -------- d-----w- c:\program files\Avira
2010-12-25 23:22 . 2010-12-25 23:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-12-25 21:43 . 2010-12-25 21:43 -------- d-----w- C:\Install
2010-12-25 14:08 . 2010-12-25 14:10 -------- d-----w- c:\windows\system32\scripting
2010-12-25 14:07 . 2010-12-25 14:07 -------- d-----w- c:\windows\l2schemas
2010-12-25 14:07 . 2010-12-25 14:08 -------- d-----w- c:\windows\system32\en
2010-12-25 14:07 . 2010-12-25 14:07 -------- d-----w- c:\windows\system32\bits
2010-12-25 12:31 . 2010-12-25 12:31 -------- d-----w- c:\windows\EHome
2010-12-24 23:14 . 2010-12-24 23:14 -------- d-----w- c:\program files\Alwil Software
2010-12-24 23:14 . 2010-12-24 23:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-12-24 20:20 . 2010-12-24 20:20 -------- d-----w- c:\documents and settings\Hojo\Application Data\AVG10
2010-12-24 19:40 . 2010-12-24 19:40 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
2010-12-24 19:19 . 2010-12-25 21:37 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG10
2010-12-24 18:47 . 2010-12-24 19:14 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2010-12-24 18:43 . 2010-12-24 18:45 -------- d-----w- c:\documents and settings\Hojo\Local Settings\Application Data\Temp
2010-12-24 18:42 . 2010-12-24 18:53 -------- d-----w- c:\documents and settings\Hojo\Local Settings\Application Data\Google
2010-12-23 20:33 . 2010-12-24 09:59 -------- d-----w- c:\documents and settings\All Users\Immunet
2010-12-23 20:33 . 2010-12-23 20:33 -------- d-----w- c:\documents and settings\Hojo\Application Data\Immunet
2010-12-23 19:17 . 2010-12-24 21:40 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-12-23 18:30 . 2010-12-25 13:24 -------- d-----w- c:\windows\ServicePackFiles
2010-12-23 18:27 . 2010-12-23 18:27 -------- d-----w- c:\program files\MSXML 4.0
2010-12-23 18:13 . 2004-08-03 21:29 25471 ------w- c:\windows\system32\drivers\watv10nt.sys
2010-12-23 18:13 . 2004-08-03 21:29 22271 ------w- c:\windows\system32\drivers\watv06nt.sys
2010-12-23 18:13 . 2004-08-03 21:29 11935 ------w- c:\windows\system32\drivers\wadv11nt.sys
2010-12-23 18:13 . 2004-08-03 21:29 11871 ------w- c:\windows\system32\drivers\wadv09nt.sys
2010-12-23 18:13 . 2004-08-03 21:29 11807 ------w- c:\windows\system32\drivers\wadv07nt.sys
2010-12-23 18:13 . 2004-08-03 21:29 11295 ------w- c:\windows\system32\drivers\wadv08nt.sys
2010-12-23 18:04 . 2004-08-03 21:29 73216 ------w- c:\windows\system32\drivers\atintuxx.sys
2010-12-23 15:32 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-12-23 15:32 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-12-23 15:26 . 2009-12-31 16:50 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2010-12-23 15:25 . 2010-02-24 13:11 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-12-23 15:24 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-12-23 15:23 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-12-23 15:21 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-12-23 15:21 . 2009-10-15 16:28 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-12-23 15:20 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2010-12-23 15:20 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2010-12-23 15:20 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2010-12-23 15:20 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2010-12-23 15:20 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2010-12-23 15:20 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-12-23 15:20 . 2009-06-25 08:25 730112 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2010-12-23 15:20 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2010-12-23 15:19 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2010-12-23 15:19 . 2010-02-16 14:08 2146304 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-12-23 15:19 . 2010-02-17 08:10 2189952 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-12-23 15:19 . 2010-02-16 13:25 2024448 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-12-23 15:13 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-12-23 14:51 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-12-23 14:45 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2010-12-23 14:45 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-12-23 14:39 . 2010-12-23 14:58 -------- d-----w- c:\windows\system32\MpEngineStore
2010-12-23 14:05 . 2009-08-06 18:24 21728 ----a-w- c:\windows\system32\wucltui.dll.mui
2010-12-23 14:05 . 2009-08-06 18:24 17632 ----a-w- c:\windows\system32\wuaueng.dll.mui
2010-12-23 14:05 . 2009-08-06 18:24 15072 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2010-12-23 14:05 . 2009-08-06 18:24 15064 ----a-w- c:\windows\system32\wuapi.dll.mui
2010-12-23 13:31 . 2010-12-23 13:31 -------- d-----w- c:\windows\system32\LogFiles
2010-12-23 13:27 . 2010-12-26 11:52 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-12-23 13:27 . 2010-12-26 11:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-12-13 281768]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Garmin\\nRoute\\nRoute.exe"=
"c:\\WINDOWS\\system32\\wuauclt.exe"=
"c:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/26/2010 12:23 AM 135336]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://www.intervideo.com/jsp/Product_Promote. ... ale=0x041b
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-26 14:36
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-12-26 14:42:09 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-26 13:42
ComboFix2.txt 2010-12-26 13:00

Pre-Run: 7 278 862 336 bytes free
Post-Run: 7 270 862 848 bytes free

- - End Of File - - CA3F0495EB57C80DBA1F35214A5D1B6C

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problem notebook

#6 Příspěvek od vyosek »

Jak se chova PC :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

erik182
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 26 pro 2010 11:14

Re: Problem notebook

#7 Příspěvek od erik182 »

je to rozhodne lepsi uz de i taskman . i kdyz je to stale nejaky pomaly . kdyz tak jeste bych vas pozadal doporucit nahradu za ten Spyware Search& Destroy ja ho pouzivam uz hodne dlouho kdyz tak bych ho zmenil dekuji

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problem notebook

#8 Příspěvek od vyosek »

:arrow: Odinstalujte Combofix
  • Start - Spustit (nebo pouzijte klavesobou zkratku Win+R)
  • Napiste ComboFix /Uninstall
  • Stisknete Enter
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://sweb.cz/Marinus/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za 14 dni

:arrow: Doporucuji provest defragmentaci disku
  • Nejjednodussi (ale nejmene ucinny) zpusob je pomoci utility ve windowsech
    • Kliknete na Tento pocitac, dale na disk kliknete pravym tlacitkem, vyberte Vlastnosti
    • prepnete se do zalozky Nastroje
    • Nyni vidite pomucky Defragmentace - spustte ji kliknutim na Defragmentovat
    • Toto provedte se vsemi disky
  • Dalsi moznosti (a mnou doporucenou) je pres programek Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
    • Program stahnete, nainstalujte (dejte fajfku pryc u yahoo toolbaru) a spustte
    • Kliknete na Analyzovat
    • Pokud je ve sloupci Fragmentováno vice jak 5%, doporucuji provest defragmentaci (klik na Defragmentovat)
    • Postup provedte se vsemi disky
  • Posledni moznost je pres jednoduchy programek JKDefrag http://www.stahuj.centrum.cz/utility_a_ ... /jkdefrag/
    • Vyhodou programku je, ze se neinstaluje
    • Staci tedy jen stahnout dle verze vaseho OS a rozbalit
    • Nasledne spustit pomoci souboru JKDefrag pripadne JKDefrag64
    • Probehne analyza disku a nasledne i defragmentace
:arrow: Spybot - Search & Destroy - program ma uz nejlepsi leta davno za sebou a posledni cca 3 roky neni schopen celit aktualnim hrozbam :arrow: Dejte novy log z RSIT
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

erik182
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 26 pro 2010 11:14

Re: Problem notebook

#9 Příspěvek od erik182 »

Logfile of random's system information tool 1.08 (written by random/random)
Run by Hojo at 2010-12-27 10:07:31
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 8 GB (41%) free of 20 GB
Total RAM: 247 MB (43% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:08:43, on 27.12.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Hojo\Desktop\RSIT.exe
C:\Program Files\trend micro\Hojo.exe
C:\WINDOWS\system32\wscntfy.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.intervideo.com/jsp/Product_P ... ale=0x041b
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/ ... 3112278546
O20 - AppInit_DLLs:
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

--
End of file - 4399 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-12-26 279664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-12-26 812528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-12-26 279664]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2010-09-07 2838912]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-12-26 39408]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2010-10-25 2424560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2006-06-06 139264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Garmin\nRoute\nRoute.exe"="C:\Garmin\nRoute\nRoute.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\wuauclt.exe"="C:\WINDOWS\system32\wuauclt.exe:*:Enabled:ipsec"
"C:\Program Files\Analog Devices\Core\smax4pnp.exe"="C:\Program Files\Analog Devices\Core\smax4pnp.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\netsh.exe"="C:\WINDOWS\system32\netsh.exe:*:Enabled:ipsec"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-12-27 10:07:31 ----D---- C:\rsit
2010-12-27 09:54:51 ----D---- C:\WINDOWS\LastGood
2010-12-27 09:09:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2010-12-27 09:08:43 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2010-12-27 09:08:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2259922$
2010-12-27 09:08:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2010-12-27 09:07:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2010-12-27 09:07:37 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2010-12-27 09:07:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2296199$
2010-12-27 09:06:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2010-12-27 09:06:07 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-12-27 09:05:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2010-12-27 09:05:32 ----HDC---- C:\WINDOWS\$NtUninstallKB981349$
2010-12-27 09:05:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2010-12-27 09:04:56 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2010-12-27 09:04:36 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-12-27 09:04:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2010-12-27 09:03:00 ----HDC---- C:\WINDOWS\$NtUninstallKB981852$
2010-12-27 09:02:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2443685$
2010-12-27 09:01:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2010-12-27 09:01:32 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2010-12-27 09:01:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2010-12-27 09:00:57 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2010-12-27 09:00:40 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2010-12-27 09:00:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2436673$
2010-12-27 08:59:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2467659$
2010-12-27 08:58:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2416400$
2010-12-27 08:57:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2286198$
2010-12-27 08:56:02 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2010-12-27 08:51:27 ----SHD---- C:\Config.Msi
2010-12-27 00:31:04 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2010-12-27 00:31:02 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2010-12-27 00:30:58 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2010-12-27 00:30:55 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2010-12-27 00:30:52 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2010-12-27 00:30:52 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2010-12-27 00:30:51 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2010-12-27 00:28:23 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-12-27 00:26:36 ----D---- C:\Documents and Settings\All Users\Application Data\Alwil Software
2010-12-27 00:02:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2141007$
2010-12-27 00:01:59 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2010-12-27 00:00:51 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-12-26 23:58:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2010-12-26 23:57:50 ----A---- C:\WINDOWS\imsins.BAK
2010-12-26 23:57:37 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2010-12-26 23:56:32 ----D---- C:\Program Files\Defraggler
2010-12-26 20:16:04 ----D---- C:\Documents and Settings\Hojo\Application Data\SUPERAntiSpyware.com
2010-12-26 20:16:04 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2010-12-26 20:13:19 ----D---- C:\Program Files\SUPERAntiSpyware
2010-12-26 20:03:24 ----D---- C:\Documents and Settings\Hojo\Application Data\Adobe
2010-12-26 17:03:14 ----D---- C:\Documents and Settings\All Users\Application Data\COMODO
2010-12-26 16:27:34 ----SHD---- C:\RECYCLER
2010-12-26 16:21:08 ----D---- C:\Documents and Settings\Hojo\Application Data\Google
2010-12-26 16:11:10 ----D---- C:\Program Files\Google
2010-12-26 16:11:10 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2010-12-26 14:42:15 ----D---- C:\WINDOWS\temp
2010-12-26 12:24:34 ----A---- C:\Boot.bak
2010-12-26 12:23:37 ----RASHD---- C:\cmdcons
2010-12-26 12:00:48 ----D---- C:\Qoobox
2010-12-26 11:42:10 ----D---- C:\Program Files\trend micro
2010-12-26 10:30:02 ----D---- C:\Documents and Settings\All Users\Application Data\Comodo Downloader
2010-12-26 00:52:09 ----D---- C:\WINDOWS\system32\NtmsData
2010-12-25 21:45:14 ----D---- C:\WINDOWS\Prefetch
2010-12-25 15:08:39 ----D---- C:\WINDOWS\system32\en-us
2010-12-25 15:08:12 ----D---- C:\WINDOWS\system32\scripting
2010-12-25 15:07:29 ----D---- C:\WINDOWS\l2schemas
2010-12-25 15:07:13 ----D---- C:\WINDOWS\system32\en
2010-12-25 15:07:11 ----D---- C:\WINDOWS\system32\bits
2010-12-25 14:05:26 ----D---- C:\WINDOWS\network diagnostic
2010-12-25 13:32:16 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-12-25 13:31:42 ----D---- C:\WINDOWS\EHome
2010-12-25 00:14:32 ----D---- C:\Program Files\Alwil Software
2010-12-24 20:40:41 ----HD---- C:\Documents and Settings\All Users\Application Data\Common Files
2010-12-24 20:15:26 ----D---- C:\Documents and Settings\Hojo\Application Data\Macromedia
2010-12-24 19:47:40 ----D---- C:\Documents and Settings\All Users\Application Data\MFAData
2010-12-23 21:33:39 ----D---- C:\Documents and Settings\Hojo\Application Data\Immunet
2010-12-23 20:17:38 ----A---- C:\WINDOWS\system32\browserchoice.exe
2010-12-23 19:30:12 ----D---- C:\WINDOWS\ServicePackFiles
2010-12-23 19:27:29 ----D---- C:\Program Files\MSXML 4.0
2010-12-23 19:13:17 ----N---- C:\WINDOWS\system32\drivers\watv10nt.sys
2010-12-23 19:13:16 ----N---- C:\WINDOWS\system32\drivers\watv06nt.sys
2010-12-23 19:13:16 ----N---- C:\WINDOWS\system32\drivers\wadv11nt.sys
2010-12-23 19:13:16 ----N---- C:\WINDOWS\system32\drivers\wadv09nt.sys
2010-12-23 19:13:16 ----N---- C:\WINDOWS\system32\drivers\wadv08nt.sys
2010-12-23 19:13:16 ----N---- C:\WINDOWS\system32\drivers\wadv07nt.sys
2010-12-23 19:12:57 ----N---- C:\WINDOWS\system32\drivers\slwdmsup.sys
2010-12-23 19:12:57 ----N---- C:\WINDOWS\system32\drivers\slnthal.sys
2010-12-23 19:12:56 ----N---- C:\WINDOWS\system32\drivers\slntamr.sys
2010-12-23 19:12:56 ----N---- C:\WINDOWS\system32\drivers\slnt7554.sys
2010-12-23 19:12:53 ----N---- C:\WINDOWS\system32\drivers\s3gnbm.sys
2010-12-23 19:12:53 ----N---- C:\WINDOWS\system32\drivers\recagent.sys
2010-12-23 19:12:48 ----N---- C:\WINDOWS\system32\drivers\nv4_mini.sys
2010-12-23 19:12:47 ----N---- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2010-12-23 19:12:44 ----N---- C:\WINDOWS\system32\drivers\mtxparhm.sys
2010-12-23 19:12:43 ----N---- C:\WINDOWS\system32\drivers\mtlstrm.sys
2010-12-23 19:12:43 ----N---- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2010-12-23 19:12:32 ----N---- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2010-12-23 19:12:20 ----N---- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2010-12-23 19:12:20 ----N---- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2010-12-23 19:12:19 ----N---- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2010-12-23 19:04:17 ----N---- C:\WINDOWS\system32\drivers\atinxsxx.sys
2010-12-23 19:04:17 ----N---- C:\WINDOWS\system32\drivers\atinxbxx.sys
2010-12-23 19:04:17 ----N---- C:\WINDOWS\system32\drivers\atintuxx.sys
2010-12-23 19:04:17 ----N---- C:\WINDOWS\system32\drivers\atinttxx.sys
2010-12-23 19:04:17 ----N---- C:\WINDOWS\system32\drivers\atinsnxx.sys
2010-12-23 19:04:16 ----N---- C:\WINDOWS\system32\drivers\atinrvxx.sys
2010-12-23 19:04:16 ----N---- C:\WINDOWS\system32\drivers\atinraxx.sys
2010-12-23 19:04:16 ----N---- C:\WINDOWS\system32\drivers\atinpdxx.sys
2010-12-23 19:04:16 ----N---- C:\WINDOWS\system32\drivers\atinmdxx.sys
2010-12-23 19:04:16 ----N---- C:\WINDOWS\system32\drivers\atinbtxx.sys
2010-12-23 19:04:15 ----N---- C:\WINDOWS\system32\drivers\ati2mtag.sys
2010-12-23 19:04:15 ----N---- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2010-12-23 19:04:15 ----N---- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2010-12-23 19:04:15 ----N---- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1snxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1raxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1btxx.sys
2010-12-23 16:32:17 ----N---- C:\WINDOWS\system32\drivers\bthport.sys
2010-12-23 16:13:32 ----N---- C:\WINDOWS\system32\tzchange.exe
2010-12-23 15:45:19 ----A---- C:\WINDOWS\system32\xpsp4res.dll
2010-12-23 15:39:15 ----D---- C:\WINDOWS\system32\MpEngineStore
2010-12-23 15:05:28 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2010-12-23 15:05:26 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2010-12-23 15:05:24 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2010-12-23 14:31:54 ----D---- C:\WINDOWS\system32\LogFiles
2010-12-23 14:27:43 ----D---- C:\Program Files\Spybot - Search & Destroy

======List of files/folders modified in the last 1 months======

2010-12-27 09:55:04 ----HD---- C:\WINDOWS\inf
2010-12-27 09:54:51 ----D---- C:\WINDOWS
2010-12-27 09:54:43 ----D---- C:\WINDOWS\system32\CatRoot2
2010-12-27 09:48:03 ----D---- C:\WINDOWS\system32
2010-12-27 09:48:02 ----RD---- C:\Program Files
2010-12-27 09:47:07 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-12-27 09:09:43 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-12-27 09:09:38 ----D---- C:\WINDOWS\system32\CatRoot
2010-12-27 09:08:56 ----HD---- C:\WINDOWS\$hf_mig$
2010-12-27 09:08:48 ----D---- C:\WINDOWS\system32\drivers
2010-12-27 09:08:12 ----D---- C:\WINDOWS\WinSxS
2010-12-27 08:56:10 ----D---- C:\Program Files\Movie Maker
2010-12-27 08:53:53 ----SHD---- C:\WINDOWS\Installer
2010-12-27 00:29:14 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-12-26 23:58:51 ----D---- C:\Program Files\Outlook Express
2010-12-26 20:07:58 ----D---- C:\WINDOWS\Minidump
2010-12-26 17:08:05 ----D---- C:\Documents and Settings
2010-12-26 17:04:05 ----D---- C:\WINDOWS\system32\Restore
2010-12-26 17:04:04 ----SHD---- C:\System Volume Information
2010-12-26 16:17:57 ----D---- C:\WINDOWS\Debug
2010-12-26 16:12:48 ----D---- C:\Program Files\CCleaner
2010-12-26 16:12:22 ----SD---- C:\WINDOWS\Tasks
2010-12-26 14:32:28 ----A---- C:\WINDOWS\system.ini
2010-12-26 14:32:01 ----D---- C:\WINDOWS\system32\drivers\etc
2010-12-26 14:29:24 ----D---- C:\WINDOWS\system32\config
2010-12-26 14:24:14 ----D---- C:\WINDOWS\AppPatch
2010-12-26 14:24:11 ----D---- C:\Program Files\Common Files
2010-12-26 13:58:27 ----D---- C:\WINDOWS\repair
2010-12-26 12:24:59 ----RASH---- C:\boot.ini
2010-12-26 00:51:37 ----D---- C:\WINDOWS\Registration
2010-12-26 00:20:49 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-12-25 21:41:13 ----D---- C:\WINDOWS\system32\Setup
2010-12-25 21:41:12 ----D---- C:\WINDOWS\system32\wbem
2010-12-25 21:41:09 ----RSD---- C:\WINDOWS\Fonts
2010-12-25 15:47:23 ----D---- C:\Program Files\Messenger
2010-12-25 15:37:52 ----D---- C:\WINDOWS\security
2010-12-25 15:21:22 ----D---- C:\WINDOWS\system32\inetsrv
2010-12-25 15:13:13 ----D---- C:\WINDOWS\ime
2010-12-25 15:11:57 ----D---- C:\WINDOWS\Help
2010-12-25 15:10:20 ----D---- C:\WINDOWS\system32\usmt
2010-12-25 15:09:29 ----D---- C:\WINDOWS\PeerNet
2010-12-25 15:07:33 ----D---- C:\Program Files\Internet Explorer
2010-12-25 14:36:42 ----D---- C:\WINDOWS\msagent
2010-12-25 14:36:28 ----D---- C:\WINDOWS\system32\oobe
2010-12-25 14:36:24 ----D---- C:\WINDOWS\system32\npp
2010-12-25 14:36:16 ----D---- C:\WINDOWS\mui
2010-12-25 14:35:50 ----D---- C:\WINDOWS\system32\Com
2010-12-25 14:34:50 ----D---- C:\WINDOWS\srchasst
2010-12-25 14:27:15 ----D---- C:\WINDOWS\system
2010-12-25 14:22:32 ----D---- C:\Program Files\NetMeeting
2010-12-25 14:21:58 ----D---- C:\Program Files\Windows Media Player
2010-12-25 14:21:50 ----D---- C:\Program Files\Windows NT
2010-12-25 14:21:22 ----D---- C:\Program Files\Common Files\System
2010-12-25 13:56:16 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-12-24 23:29:58 ----A---- C:\WINDOWS\system32\MRT.exe
2010-12-24 20:00:35 ----D---- C:\Program Files\Common Files\Teleca Shared
2010-12-24 19:53:10 ----D---- C:\Program Files\Codec Pack - All In 1
2010-12-24 19:36:07 ----D---- C:\Garmin
2010-12-24 10:59:43 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-12-23 16:20:40 ----D---- C:\WINDOWS\SoftwareDistribution
2010-12-23 14:51:30 ----SD---- C:\WINDOWS\Downloaded Program Files

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Texas Instruments OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-09-07 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-09-07 165584]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-09-07 46672]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-09-07 17744]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-09-07 100176]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2006-02-28 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2006-02-28 55936]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2006-01-31 176128]
R3 AEAudioService;AEAudio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2005-06-07 152960]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2008-03-21 1203776]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-09-07 23376]
R3 BCM43XX;Broadcom 802.11 ovládač sieťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2006-04-28 429184]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2005-08-05 45312]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2006-06-06 1168860]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2006-03-31 193056]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 grmnusb;grmnusb; C:\WINDOWS\system32\drivers\grmnusb.sys [2003-09-23 7296]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM); C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys [2006-11-10 61600]
S3 SE2Emdfl;Sony Ericsson Device 046 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\SE2Emdfl.sys [2006-11-10 9360]
S3 SE2Emdm;Sony Ericsson Device 046 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\SE2Emdm.sys [2006-11-10 97184]
S3 SE2Emgmt;Sony Ericsson Device 046 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\SE2Emgmt.sys [2006-11-10 88688]
S3 se2End5;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (NDIS); C:\WINDOWS\system32\DRIVERS\se2End5.sys [2006-11-10 18704]
S3 SE2Eobex;Sony Ericsson Device 046 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\SE2Eobex.sys [2006-11-10 86560]
S3 se2Eunic;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (WDM); C:\WINDOWS\system32\DRIVERS\se2Eunic.sys [2006-11-10 90800]
S3 Ser2pl;Prolific Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2004-06-28 42752]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\WINDOWS\system32\agrsmsvc.exe [2008-03-18 13312]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-12-26 135664]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-12-26 182768]

-----------------EOF-----------------

erik182
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 26 pro 2010 11:14

Re: Problem notebook

#10 Příspěvek od erik182 »

Logfile of random's system information tool 1.08 (written by random/random)
Run by Hojo at 2010-12-27 10:07:31
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 8 GB (41%) free of 20 GB
Total RAM: 247 MB (43% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:08:43, on 27.12.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Hojo\Desktop\RSIT.exe
C:\Program Files\trend micro\Hojo.exe
C:\WINDOWS\system32\wscntfy.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.intervideo.com/jsp/Product_P ... ale=0x041b
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/ ... 3112278546
O20 - AppInit_DLLs:
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

--
End of file - 4399 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-12-26 279664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-12-26 812528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-12-26 279664]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2010-09-07 2838912]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-12-26 39408]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2010-10-25 2424560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2006-06-06 139264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Garmin\nRoute\nRoute.exe"="C:\Garmin\nRoute\nRoute.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\wuauclt.exe"="C:\WINDOWS\system32\wuauclt.exe:*:Enabled:ipsec"
"C:\Program Files\Analog Devices\Core\smax4pnp.exe"="C:\Program Files\Analog Devices\Core\smax4pnp.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\netsh.exe"="C:\WINDOWS\system32\netsh.exe:*:Enabled:ipsec"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-12-27 10:07:31 ----D---- C:\rsit
2010-12-27 09:54:51 ----D---- C:\WINDOWS\LastGood
2010-12-27 09:09:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2010-12-27 09:08:43 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2010-12-27 09:08:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2259922$
2010-12-27 09:08:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2010-12-27 09:07:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2010-12-27 09:07:37 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2010-12-27 09:07:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2296199$
2010-12-27 09:06:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2010-12-27 09:06:07 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-12-27 09:05:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2010-12-27 09:05:32 ----HDC---- C:\WINDOWS\$NtUninstallKB981349$
2010-12-27 09:05:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2010-12-27 09:04:56 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2010-12-27 09:04:36 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-12-27 09:04:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2010-12-27 09:03:00 ----HDC---- C:\WINDOWS\$NtUninstallKB981852$
2010-12-27 09:02:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2443685$
2010-12-27 09:01:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2010-12-27 09:01:32 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2010-12-27 09:01:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2010-12-27 09:00:57 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2010-12-27 09:00:40 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2010-12-27 09:00:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2436673$
2010-12-27 08:59:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2467659$
2010-12-27 08:58:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2416400$
2010-12-27 08:57:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2286198$
2010-12-27 08:56:02 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2010-12-27 08:51:27 ----SHD---- C:\Config.Msi
2010-12-27 00:31:04 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2010-12-27 00:31:02 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2010-12-27 00:30:58 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2010-12-27 00:30:55 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2010-12-27 00:30:52 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2010-12-27 00:30:52 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2010-12-27 00:30:51 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2010-12-27 00:28:23 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-12-27 00:26:36 ----D---- C:\Documents and Settings\All Users\Application Data\Alwil Software
2010-12-27 00:02:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2141007$
2010-12-27 00:01:59 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2010-12-27 00:00:51 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-12-26 23:58:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2010-12-26 23:57:50 ----A---- C:\WINDOWS\imsins.BAK
2010-12-26 23:57:37 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2010-12-26 23:56:32 ----D---- C:\Program Files\Defraggler
2010-12-26 20:16:04 ----D---- C:\Documents and Settings\Hojo\Application Data\SUPERAntiSpyware.com
2010-12-26 20:16:04 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2010-12-26 20:13:19 ----D---- C:\Program Files\SUPERAntiSpyware
2010-12-26 20:03:24 ----D---- C:\Documents and Settings\Hojo\Application Data\Adobe
2010-12-26 17:03:14 ----D---- C:\Documents and Settings\All Users\Application Data\COMODO
2010-12-26 16:27:34 ----SHD---- C:\RECYCLER
2010-12-26 16:21:08 ----D---- C:\Documents and Settings\Hojo\Application Data\Google
2010-12-26 16:11:10 ----D---- C:\Program Files\Google
2010-12-26 16:11:10 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2010-12-26 14:42:15 ----D---- C:\WINDOWS\temp
2010-12-26 12:24:34 ----A---- C:\Boot.bak
2010-12-26 12:23:37 ----RASHD---- C:\cmdcons
2010-12-26 12:00:48 ----D---- C:\Qoobox
2010-12-26 11:42:10 ----D---- C:\Program Files\trend micro
2010-12-26 10:30:02 ----D---- C:\Documents and Settings\All Users\Application Data\Comodo Downloader
2010-12-26 00:52:09 ----D---- C:\WINDOWS\system32\NtmsData
2010-12-25 21:45:14 ----D---- C:\WINDOWS\Prefetch
2010-12-25 15:08:39 ----D---- C:\WINDOWS\system32\en-us
2010-12-25 15:08:12 ----D---- C:\WINDOWS\system32\scripting
2010-12-25 15:07:29 ----D---- C:\WINDOWS\l2schemas
2010-12-25 15:07:13 ----D---- C:\WINDOWS\system32\en
2010-12-25 15:07:11 ----D---- C:\WINDOWS\system32\bits
2010-12-25 14:05:26 ----D---- C:\WINDOWS\network diagnostic
2010-12-25 13:32:16 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-12-25 13:31:42 ----D---- C:\WINDOWS\EHome
2010-12-25 00:14:32 ----D---- C:\Program Files\Alwil Software
2010-12-24 20:40:41 ----HD---- C:\Documents and Settings\All Users\Application Data\Common Files
2010-12-24 20:15:26 ----D---- C:\Documents and Settings\Hojo\Application Data\Macromedia
2010-12-24 19:47:40 ----D---- C:\Documents and Settings\All Users\Application Data\MFAData
2010-12-23 21:33:39 ----D---- C:\Documents and Settings\Hojo\Application Data\Immunet
2010-12-23 20:17:38 ----A---- C:\WINDOWS\system32\browserchoice.exe
2010-12-23 19:30:12 ----D---- C:\WINDOWS\ServicePackFiles
2010-12-23 19:27:29 ----D---- C:\Program Files\MSXML 4.0
2010-12-23 19:13:17 ----N---- C:\WINDOWS\system32\drivers\watv10nt.sys
2010-12-23 19:13:16 ----N---- C:\WINDOWS\system32\drivers\watv06nt.sys
2010-12-23 19:13:16 ----N---- C:\WINDOWS\system32\drivers\wadv11nt.sys
2010-12-23 19:13:16 ----N---- C:\WINDOWS\system32\drivers\wadv09nt.sys
2010-12-23 19:13:16 ----N---- C:\WINDOWS\system32\drivers\wadv08nt.sys
2010-12-23 19:13:16 ----N---- C:\WINDOWS\system32\drivers\wadv07nt.sys
2010-12-23 19:12:57 ----N---- C:\WINDOWS\system32\drivers\slwdmsup.sys
2010-12-23 19:12:57 ----N---- C:\WINDOWS\system32\drivers\slnthal.sys
2010-12-23 19:12:56 ----N---- C:\WINDOWS\system32\drivers\slntamr.sys
2010-12-23 19:12:56 ----N---- C:\WINDOWS\system32\drivers\slnt7554.sys
2010-12-23 19:12:53 ----N---- C:\WINDOWS\system32\drivers\s3gnbm.sys
2010-12-23 19:12:53 ----N---- C:\WINDOWS\system32\drivers\recagent.sys
2010-12-23 19:12:48 ----N---- C:\WINDOWS\system32\drivers\nv4_mini.sys
2010-12-23 19:12:47 ----N---- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2010-12-23 19:12:44 ----N---- C:\WINDOWS\system32\drivers\mtxparhm.sys
2010-12-23 19:12:43 ----N---- C:\WINDOWS\system32\drivers\mtlstrm.sys
2010-12-23 19:12:43 ----N---- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2010-12-23 19:12:32 ----N---- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2010-12-23 19:12:20 ----N---- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2010-12-23 19:12:20 ----N---- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2010-12-23 19:12:19 ----N---- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2010-12-23 19:04:17 ----N---- C:\WINDOWS\system32\drivers\atinxsxx.sys
2010-12-23 19:04:17 ----N---- C:\WINDOWS\system32\drivers\atinxbxx.sys
2010-12-23 19:04:17 ----N---- C:\WINDOWS\system32\drivers\atintuxx.sys
2010-12-23 19:04:17 ----N---- C:\WINDOWS\system32\drivers\atinttxx.sys
2010-12-23 19:04:17 ----N---- C:\WINDOWS\system32\drivers\atinsnxx.sys
2010-12-23 19:04:16 ----N---- C:\WINDOWS\system32\drivers\atinrvxx.sys
2010-12-23 19:04:16 ----N---- C:\WINDOWS\system32\drivers\atinraxx.sys
2010-12-23 19:04:16 ----N---- C:\WINDOWS\system32\drivers\atinpdxx.sys
2010-12-23 19:04:16 ----N---- C:\WINDOWS\system32\drivers\atinmdxx.sys
2010-12-23 19:04:16 ----N---- C:\WINDOWS\system32\drivers\atinbtxx.sys
2010-12-23 19:04:15 ----N---- C:\WINDOWS\system32\drivers\ati2mtag.sys
2010-12-23 19:04:15 ----N---- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2010-12-23 19:04:15 ----N---- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2010-12-23 19:04:15 ----N---- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1snxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1raxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2010-12-23 19:04:14 ----N---- C:\WINDOWS\system32\drivers\ati1btxx.sys
2010-12-23 16:32:17 ----N---- C:\WINDOWS\system32\drivers\bthport.sys
2010-12-23 16:13:32 ----N---- C:\WINDOWS\system32\tzchange.exe
2010-12-23 15:45:19 ----A---- C:\WINDOWS\system32\xpsp4res.dll
2010-12-23 15:39:15 ----D---- C:\WINDOWS\system32\MpEngineStore
2010-12-23 15:05:28 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2010-12-23 15:05:26 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2010-12-23 15:05:24 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2010-12-23 14:31:54 ----D---- C:\WINDOWS\system32\LogFiles
2010-12-23 14:27:43 ----D---- C:\Program Files\Spybot - Search & Destroy

======List of files/folders modified in the last 1 months======

2010-12-27 09:55:04 ----HD---- C:\WINDOWS\inf
2010-12-27 09:54:51 ----D---- C:\WINDOWS
2010-12-27 09:54:43 ----D---- C:\WINDOWS\system32\CatRoot2
2010-12-27 09:48:03 ----D---- C:\WINDOWS\system32
2010-12-27 09:48:02 ----RD---- C:\Program Files
2010-12-27 09:47:07 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-12-27 09:09:43 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-12-27 09:09:38 ----D---- C:\WINDOWS\system32\CatRoot
2010-12-27 09:08:56 ----HD---- C:\WINDOWS\$hf_mig$
2010-12-27 09:08:48 ----D---- C:\WINDOWS\system32\drivers
2010-12-27 09:08:12 ----D---- C:\WINDOWS\WinSxS
2010-12-27 08:56:10 ----D---- C:\Program Files\Movie Maker
2010-12-27 08:53:53 ----SHD---- C:\WINDOWS\Installer
2010-12-27 00:29:14 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-12-26 23:58:51 ----D---- C:\Program Files\Outlook Express
2010-12-26 20:07:58 ----D---- C:\WINDOWS\Minidump
2010-12-26 17:08:05 ----D---- C:\Documents and Settings
2010-12-26 17:04:05 ----D---- C:\WINDOWS\system32\Restore
2010-12-26 17:04:04 ----SHD---- C:\System Volume Information
2010-12-26 16:17:57 ----D---- C:\WINDOWS\Debug
2010-12-26 16:12:48 ----D---- C:\Program Files\CCleaner
2010-12-26 16:12:22 ----SD---- C:\WINDOWS\Tasks
2010-12-26 14:32:28 ----A---- C:\WINDOWS\system.ini
2010-12-26 14:32:01 ----D---- C:\WINDOWS\system32\drivers\etc
2010-12-26 14:29:24 ----D---- C:\WINDOWS\system32\config
2010-12-26 14:24:14 ----D---- C:\WINDOWS\AppPatch
2010-12-26 14:24:11 ----D---- C:\Program Files\Common Files
2010-12-26 13:58:27 ----D---- C:\WINDOWS\repair
2010-12-26 12:24:59 ----RASH---- C:\boot.ini
2010-12-26 00:51:37 ----D---- C:\WINDOWS\Registration
2010-12-26 00:20:49 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-12-25 21:41:13 ----D---- C:\WINDOWS\system32\Setup
2010-12-25 21:41:12 ----D---- C:\WINDOWS\system32\wbem
2010-12-25 21:41:09 ----RSD---- C:\WINDOWS\Fonts
2010-12-25 15:47:23 ----D---- C:\Program Files\Messenger
2010-12-25 15:37:52 ----D---- C:\WINDOWS\security
2010-12-25 15:21:22 ----D---- C:\WINDOWS\system32\inetsrv
2010-12-25 15:13:13 ----D---- C:\WINDOWS\ime
2010-12-25 15:11:57 ----D---- C:\WINDOWS\Help
2010-12-25 15:10:20 ----D---- C:\WINDOWS\system32\usmt
2010-12-25 15:09:29 ----D---- C:\WINDOWS\PeerNet
2010-12-25 15:07:33 ----D---- C:\Program Files\Internet Explorer
2010-12-25 14:36:42 ----D---- C:\WINDOWS\msagent
2010-12-25 14:36:28 ----D---- C:\WINDOWS\system32\oobe
2010-12-25 14:36:24 ----D---- C:\WINDOWS\system32\npp
2010-12-25 14:36:16 ----D---- C:\WINDOWS\mui
2010-12-25 14:35:50 ----D---- C:\WINDOWS\system32\Com
2010-12-25 14:34:50 ----D---- C:\WINDOWS\srchasst
2010-12-25 14:27:15 ----D---- C:\WINDOWS\system
2010-12-25 14:22:32 ----D---- C:\Program Files\NetMeeting
2010-12-25 14:21:58 ----D---- C:\Program Files\Windows Media Player
2010-12-25 14:21:50 ----D---- C:\Program Files\Windows NT
2010-12-25 14:21:22 ----D---- C:\Program Files\Common Files\System
2010-12-25 13:56:16 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-12-24 23:29:58 ----A---- C:\WINDOWS\system32\MRT.exe
2010-12-24 20:00:35 ----D---- C:\Program Files\Common Files\Teleca Shared
2010-12-24 19:53:10 ----D---- C:\Program Files\Codec Pack - All In 1
2010-12-24 19:36:07 ----D---- C:\Garmin
2010-12-24 10:59:43 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-12-23 16:20:40 ----D---- C:\WINDOWS\SoftwareDistribution
2010-12-23 14:51:30 ----SD---- C:\WINDOWS\Downloaded Program Files

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Texas Instruments OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-09-07 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-09-07 165584]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-09-07 46672]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-09-07 17744]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-09-07 100176]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2006-02-28 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2006-02-28 55936]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2006-01-31 176128]
R3 AEAudioService;AEAudio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2005-06-07 152960]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2008-03-21 1203776]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-09-07 23376]
R3 BCM43XX;Broadcom 802.11 ovládač sieťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2006-04-28 429184]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2005-08-05 45312]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2006-06-06 1168860]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2006-03-31 193056]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 grmnusb;grmnusb; C:\WINDOWS\system32\drivers\grmnusb.sys [2003-09-23 7296]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM); C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys [2006-11-10 61600]
S3 SE2Emdfl;Sony Ericsson Device 046 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\SE2Emdfl.sys [2006-11-10 9360]
S3 SE2Emdm;Sony Ericsson Device 046 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\SE2Emdm.sys [2006-11-10 97184]
S3 SE2Emgmt;Sony Ericsson Device 046 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\SE2Emgmt.sys [2006-11-10 88688]
S3 se2End5;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (NDIS); C:\WINDOWS\system32\DRIVERS\se2End5.sys [2006-11-10 18704]
S3 SE2Eobex;Sony Ericsson Device 046 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\SE2Eobex.sys [2006-11-10 86560]
S3 se2Eunic;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (WDM); C:\WINDOWS\system32\DRIVERS\se2Eunic.sys [2006-11-10 90800]
S3 Ser2pl;Prolific Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2004-06-28 42752]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\WINDOWS\system32\agrsmsvc.exe [2008-03-18 13312]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-12-26 135664]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-12-26 182768]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problem notebook

#11 Příspěvek od vyosek »

Log jiz vypada v poradku :wink:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět