Bez zjevných závad
Napsal: 09 úno 2011 10:26
Logfile of random's system information tool 1.08 (written by random/random)
Run by ivo at 2011-02-09 10:13:38
Microsoft Windows 7 Ultimate
System drive C: has 85 GB (61%) free of 140 GB
Total RAM: 2047 MB (73% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:13:50, on 9.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
C:\Windows\system32\wuauclt.exe
C:\Users\ivo\Pictures\RSIT.exe
C:\Program Files\trend micro\ivo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\IPS\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\coIEPlg.dll
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{27142A06-3188-4F43-B2C6-D8DA4864F6C3}: NameServer = 212.96.161.6,212.96.160.7
O17 - HKLM\System\CS1\Services\Tcpip\..\{27142A06-3188-4F43-B2C6-D8DA4864F6C3}: NameServer = 212.96.161.6,212.96.160.7
O17 - HKLM\System\CS2\Services\Tcpip\..\{27142A06-3188-4F43-B2C6-D8DA4864F6C3}: NameServer = 212.96.161.6,212.96.160.7
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: avast! Firewall - Unknown owner - C:\Program Files\Alwil Software\Avast5\afwServ.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
--
End of file - 5248 bytes
======Scheduled tasks folder======
C:\Windows\tasks\PCConfidential.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\coIEPlg.dll [2010-12-04 433080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\IPS\IPSBHO.DLL [2010-12-01 210360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-01-03 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\coIEPlg.dll [2010-12-04 433080]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-12-20 443728]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2010-04-12 180224]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe"
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-02-09 10:13:38 ----D---- C:\rsit
2011-02-06 12:14:15 ----D---- C:\Users\ivo\AppData\Roaming\Ubisoft
2011-02-06 12:14:15 ----D---- C:\ProgramData\Ubisoft
2011-02-06 11:43:07 ----D---- C:\Program Files\PowerISO
2011-02-04 01:04:46 ----D---- C:\ProgramData\DivX
2011-02-03 00:07:24 ----D---- C:\Program Files\GoldWave
2011-02-02 00:21:32 ----D---- C:\Program Files\ICQ7.4
2011-02-01 11:58:11 ----D---- C:\Users\ivo\AppData\Roaming\Media Player Classic
2011-02-01 11:50:31 ----A---- C:\Windows\system32\unrar.dll
2011-02-01 11:50:31 ----A---- C:\Windows\avisplitter.ini
2011-02-01 11:50:29 ----A---- C:\Windows\system32\yv12vfw.dll
2011-02-01 11:50:29 ----A---- C:\Windows\system32\xvidvfw.dll
2011-02-01 11:50:29 ----A---- C:\Windows\system32\xvidcore.dll
2011-02-01 11:50:29 ----A---- C:\Windows\system32\ff_vfw.dll.manifest
2011-02-01 11:50:28 ----A---- C:\Windows\system32\ff_vfw.dll
2011-02-01 11:50:24 ----D---- C:\Program Files\K-Lite Codec Pack
2011-01-30 08:59:32 ----D---- C:\Program Files\7-Zip
2011-01-25 14:51:13 ----D---- C:\Program Files\Microsoft.NET
2011-01-25 14:50:43 ----SHD---- C:\Config.Msi
2011-01-25 14:49:07 ----D---- C:\a8772e57f43449a3d2
2011-01-21 09:55:02 ----D---- C:\ProgramData\vsosdk
2011-01-19 16:49:13 ----D---- C:\ProgramData\Easy Driver Pro
2011-01-19 09:18:39 ----D---- C:\Program Files\MSECache
2011-01-19 00:46:15 ----D---- C:\Program Files\Microsoft Silverlight
2011-01-19 00:45:59 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2011-01-18 15:32:40 ----A---- C:\Windows\videoimp.ini
2011-01-18 15:32:39 ----A---- C:\Windows\system32\LMRTREND.dll
2011-01-18 15:32:39 ----A---- C:\Windows\system32\LMRT.dll
2011-01-18 15:32:38 ----A---- C:\Windows\system32\dxtmsft3.dll
2011-01-18 15:32:36 ----A---- C:\Windows\system32\strmdll.dll
2011-01-18 15:32:35 ----A---- C:\Windows\system32\unam4ie.exe
2011-01-18 15:32:32 ----A---- C:\Windows\system32\vidx16.dll
2011-01-18 15:32:32 ----A---- C:\Windows\system32\qcut.dll
2011-01-18 15:32:32 ----A---- C:\Windows\system32\danim.dll
2011-01-18 15:32:31 ----A---- C:\Windows\system32\w95inf32.dll
2011-01-18 15:32:31 ----A---- C:\Windows\system32\w95inf16.dll
2011-01-17 12:23:34 ----D---- C:\ProgramData\Nokia
2011-01-16 00:58:17 ----D---- C:\Users\ivo\AppData\Roaming\Uniblue
2011-01-16 00:57:24 ----D---- C:\Users\ivo\AppData\Roaming\FreeFileViewer
2011-01-16 00:55:30 ----D---- C:\Program Files\Free Offers from Freeze.com
2011-01-16 00:54:11 ----A---- C:\Windows\system32\WINUTIL5.DLL
2011-01-16 00:54:10 ----A---- C:\Windows\system32\WINLCTL5.DLL
2011-01-16 00:53:50 ----D---- C:\Program Files\Winferno
2011-01-14 19:18:55 ----D---- C:\Program Files\Symantec
2011-01-14 19:18:55 ----D---- C:\Program Files\Common Files\Symantec Shared
2011-01-14 19:18:55 ----A---- C:\Windows\system32\drivers\SYMEVENT.SYS
2011-01-14 19:18:13 ----D---- C:\Windows\system32\drivers\NIS
2011-01-14 19:18:08 ----D---- C:\Program Files\Norton Internet Security
2011-01-14 19:17:59 ----D---- C:\Program Files\NortonInstaller
2011-01-14 15:06:47 ----A---- C:\Windows\system32\drivers\aswFW.sys
2011-01-14 15:06:33 ----A---- C:\Windows\system32\drivers\aswNdis2.sys
2011-01-14 15:06:05 ----D---- C:\ProgramData\Alwil Software
2011-01-14 08:56:17 ----D---- C:\Program Files\AVG
2011-01-13 12:50:40 ----D---- C:\Users\ivo\AppData\Roaming\Tific
2011-01-12 18:40:31 ----D---- C:\Program Files\MSXML 4.0
2011-01-12 18:40:22 ----A---- C:\Windows\system32\d3d10warp.dll
2011-01-12 18:40:21 ----A---- C:\Windows\system32\XpsPrint.dll
2011-01-12 18:40:21 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-01-12 18:40:21 ----A---- C:\Windows\system32\mf.dll
2011-01-12 18:40:21 ----A---- C:\Windows\system32\FntCache.dll
2011-01-12 18:40:21 ----A---- C:\Windows\system32\DWrite.dll
2011-01-12 18:40:21 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-01-12 18:40:21 ----A---- C:\Windows\system32\d2d1.dll
2011-01-12 18:40:20 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-01-12 18:40:20 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-01-12 18:40:20 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-01-12 18:40:20 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-01-12 18:40:20 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-01-12 18:40:20 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-01-12 18:40:20 ----A---- C:\Windows\system32\d3d10_1.dll
2011-01-12 18:40:20 ----A---- C:\Windows\system32\cdd.dll
2011-01-12 18:40:17 ----A---- C:\Windows\system32\odbc32.dll
2011-01-11 17:38:24 ----D---- C:\Users\ivo\AppData\Roaming\Nokia
2011-01-11 17:38:00 ----D---- C:\ProgramData\PC Suite
2011-01-11 17:37:27 ----D---- C:\Users\ivo\AppData\Roaming\PC Suite
2011-01-11 17:35:27 ----D---- C:\Program Files\Common Files\Nokia
2011-01-11 17:34:38 ----D---- C:\Program Files\DIFX
2011-01-11 17:34:35 ----A---- C:\Windows\system32\drivers\pccsmcfd.sys
2011-01-11 17:34:26 ----DC---- C:\Windows\system32\DRVSTORE
2011-01-11 17:34:15 ----D---- C:\Program Files\PC Connectivity Solution
2011-01-11 17:33:22 ----A---- C:\Windows\system32\nmwcdcls.dll
2011-01-11 17:29:54 ----D---- C:\ProgramData\NokiaInstallerCache
2011-01-11 17:29:53 ----D---- C:\Program Files\Nokia
2011-01-10 12:17:37 ----D---- C:\Users\ivo\AppData\Roaming\Voipwise
======List of files/folders modified in the last 1 months======
2011-02-09 10:13:44 ----D---- C:\Program Files\trend micro
2011-02-09 10:13:39 ----D---- C:\Windows\Temp
2011-02-09 09:02:08 ----SHD---- C:\System Volume Information
2011-02-09 09:01:48 ----D---- C:\Windows
2011-02-09 09:00:47 ----D---- C:\Windows\system32\config
2011-02-09 09:00:20 ----D---- C:\Windows\system32\catroot
2011-02-09 08:59:42 ----D---- C:\Windows\system32\catroot2
2011-02-09 08:59:09 ----D---- C:\Windows\winsxs
2011-02-09 08:56:59 ----D---- C:\Windows\Prefetch
2011-02-09 06:34:13 ----D---- C:\Windows\system32\drivers
2011-02-08 19:34:30 ----D---- C:\Windows\ShellNew
2011-02-08 18:39:57 ----RD---- C:\Program Files
2011-02-06 12:14:15 ----HD---- C:\ProgramData
2011-02-06 12:05:09 ----HD---- C:\Program Files\InstallShield Installation Information
2011-02-06 09:15:02 ----D---- C:\Users\ivo\AppData\Roaming\Vso
2011-02-05 17:34:13 ----A---- C:\Windows\BlendSettings.ini
2011-02-04 19:26:57 ----D---- C:\Windows\System32
2011-02-04 00:56:12 ----D---- C:\Users\ivo\AppData\Roaming\Skype
2011-02-04 00:00:09 ----D---- C:\Users\ivo\AppData\Roaming\skypePM
2011-02-02 20:41:24 ----D---- C:\Users\ivo\AppData\Roaming\ICQ
2011-02-01 12:11:28 ----SD---- C:\Users\ivo\AppData\Roaming\Microsoft
2011-01-27 15:41:57 ----SHD---- C:\Windows\Installer
2011-01-26 10:27:36 ----D---- C:\Windows\system32\wdi
2011-01-26 07:28:35 ----RSD---- C:\Windows\assembly
2011-01-26 07:28:35 ----D---- C:\Windows\Microsoft.NET
2011-01-25 23:47:13 ----D---- C:\Program Files\CCleaner
2011-01-25 14:51:45 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-01-25 14:51:43 ----D---- C:\Windows\inf
2011-01-25 14:51:16 ----D---- C:\Windows\system32\en-US
2011-01-20 14:30:56 ----D---- C:\Program Files\Common Files\microsoft shared
2011-01-19 09:38:12 ----A---- C:\Windows\ODBC.INI
2011-01-19 09:22:53 ----D---- C:\Program Files\Microsoft Office
2011-01-19 09:19:16 ----RSD---- C:\Windows\Fonts
2011-01-19 00:47:59 ----D---- C:\Windows\system32\DriverStore
2011-01-19 00:47:08 ----SD---- C:\ProgramData\Microsoft
2011-01-19 00:41:27 ----A---- C:\Windows\win.ini
2011-01-18 22:48:58 ----D---- C:\Program Files\Common Files\InstallShield
2011-01-18 15:32:39 ----D---- C:\Program Files\Windows Media Player
2011-01-18 15:32:36 ----D---- C:\Windows\Help
2011-01-16 14:07:57 ----D---- C:\Windows\Panther
2011-01-16 11:52:53 ----D---- C:\Program Files\Mozilla Firefox
2011-01-16 01:17:41 ----D---- C:\Program Files\Common Files
2011-01-16 01:17:40 ----D---- C:\Program Files\Adobe
2011-01-16 01:06:47 ----D---- C:\Windows\Tasks
2011-01-16 01:06:47 ----D---- C:\Windows\system32\Tasks
2011-01-16 00:56:30 ----D---- C:\Users\ivo\AppData\Roaming\Adobe
2011-01-15 15:02:30 ----D---- C:\Program Files\Webteh
2011-01-14 19:36:24 ----D---- C:\ProgramData\NortonInstaller
2011-01-14 19:32:50 ----D---- C:\ProgramData\Norton
2011-01-14 17:44:56 ----SHD---- C:\Boot
2011-01-13 10:35:44 ----D---- C:\Windows\debug
2011-01-12 18:41:04 ----A---- C:\Windows\system32\MRT.exe
2011-01-12 16:37:48 ----D---- C:\Windows\rescache
2011-01-11 17:40:12 ----D---- C:\Windows\system32\drivers\UMDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswNdis2;avast! Firewall Core Firewall Service; C:\Windows\system32\drivers\aswNdis2.sys [2010-12-30 189776]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\NIS\1205000.07D\SYMDS.SYS [2010-10-21 340016]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\NIS\1205000.07D\SYMEFA.SYS [2010-11-18 652336]
R1 aswFW;avast! TDI Firewall driver; C:\Windows\system32\drivers\aswFW.sys [2010-12-30 99792]
R1 BHDrvx86;BHDrvx86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110114.001\BHDrvx86.sys [2010-11-23 691248]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2011-01-14 371248]
R1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20110208.003\IDSvix86.sys [2010-11-09 353912]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2010-04-12 59388]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\Windows\system32\drivers\NIS\1205000.07D\SRTSPX.SYS [2010-11-23 50168]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NIS\1205000.07D\Ironx86.SYS [2010-11-16 136312]
R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\System32\Drivers\NIS\1205000.07D\SYMNETS.SYS [2010-12-01 295032]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2011/01/03 05:09:36]; \??\C:\Program Files\CyberLink\PowerDVD9\000.fcl [2009-02-28 87536]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-11-26 6650368]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-11-26 231936]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2010-11-17 101392]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-01-15 102448]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2010-12-20 20952]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110208.021\NAVENG.SYS [2011-01-15 86008]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110208.021\NAVEX15.SYS [2011-01-15 1360760]
R3 PAC207;SoC PC-Camera; C:\Windows\system32\DRIVERS\PFC027.SYS [2006-12-05 507136]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2011-01-03 47360]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R3 SRTSP;Symantec Real Time Storage Protection; C:\Windows\System32\Drivers\NIS\1205000.07D\SRTSP.SYS [2010-11-23 509560]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2011-01-14 126512]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [2010-11-29 10064]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-11-26 6650368]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2009-07-14 27648]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-11-26 176128]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-12-20 363344]
R2 NIS;Norton Internet Security; C:\Program Files\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe [2010-11-24 130000]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [2010-12-14 1517376]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 avast! Firewall;avast! Firewall; C:\Program Files\Alwil Software\Avast5\afwServ.exe []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-01-03 1343400]
S4 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-06-14 615936]
-----------------EOF-----------------
Run by ivo at 2011-02-09 10:13:38
Microsoft Windows 7 Ultimate
System drive C: has 85 GB (61%) free of 140 GB
Total RAM: 2047 MB (73% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:13:50, on 9.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
C:\Windows\system32\wuauclt.exe
C:\Users\ivo\Pictures\RSIT.exe
C:\Program Files\trend micro\ivo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\IPS\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\coIEPlg.dll
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{27142A06-3188-4F43-B2C6-D8DA4864F6C3}: NameServer = 212.96.161.6,212.96.160.7
O17 - HKLM\System\CS1\Services\Tcpip\..\{27142A06-3188-4F43-B2C6-D8DA4864F6C3}: NameServer = 212.96.161.6,212.96.160.7
O17 - HKLM\System\CS2\Services\Tcpip\..\{27142A06-3188-4F43-B2C6-D8DA4864F6C3}: NameServer = 212.96.161.6,212.96.160.7
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: avast! Firewall - Unknown owner - C:\Program Files\Alwil Software\Avast5\afwServ.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
--
End of file - 5248 bytes
======Scheduled tasks folder======
C:\Windows\tasks\PCConfidential.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\coIEPlg.dll [2010-12-04 433080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\IPS\IPSBHO.DLL [2010-12-01 210360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-01-03 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Engine\18.5.0.125\coIEPlg.dll [2010-12-04 433080]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-12-20 443728]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2010-04-12 180224]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe"
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-02-09 10:13:38 ----D---- C:\rsit
2011-02-06 12:14:15 ----D---- C:\Users\ivo\AppData\Roaming\Ubisoft
2011-02-06 12:14:15 ----D---- C:\ProgramData\Ubisoft
2011-02-06 11:43:07 ----D---- C:\Program Files\PowerISO
2011-02-04 01:04:46 ----D---- C:\ProgramData\DivX
2011-02-03 00:07:24 ----D---- C:\Program Files\GoldWave
2011-02-02 00:21:32 ----D---- C:\Program Files\ICQ7.4
2011-02-01 11:58:11 ----D---- C:\Users\ivo\AppData\Roaming\Media Player Classic
2011-02-01 11:50:31 ----A---- C:\Windows\system32\unrar.dll
2011-02-01 11:50:31 ----A---- C:\Windows\avisplitter.ini
2011-02-01 11:50:29 ----A---- C:\Windows\system32\yv12vfw.dll
2011-02-01 11:50:29 ----A---- C:\Windows\system32\xvidvfw.dll
2011-02-01 11:50:29 ----A---- C:\Windows\system32\xvidcore.dll
2011-02-01 11:50:29 ----A---- C:\Windows\system32\ff_vfw.dll.manifest
2011-02-01 11:50:28 ----A---- C:\Windows\system32\ff_vfw.dll
2011-02-01 11:50:24 ----D---- C:\Program Files\K-Lite Codec Pack
2011-01-30 08:59:32 ----D---- C:\Program Files\7-Zip
2011-01-25 14:51:13 ----D---- C:\Program Files\Microsoft.NET
2011-01-25 14:50:43 ----SHD---- C:\Config.Msi
2011-01-25 14:49:07 ----D---- C:\a8772e57f43449a3d2
2011-01-21 09:55:02 ----D---- C:\ProgramData\vsosdk
2011-01-19 16:49:13 ----D---- C:\ProgramData\Easy Driver Pro
2011-01-19 09:18:39 ----D---- C:\Program Files\MSECache
2011-01-19 00:46:15 ----D---- C:\Program Files\Microsoft Silverlight
2011-01-19 00:45:59 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2011-01-18 15:32:40 ----A---- C:\Windows\videoimp.ini
2011-01-18 15:32:39 ----A---- C:\Windows\system32\LMRTREND.dll
2011-01-18 15:32:39 ----A---- C:\Windows\system32\LMRT.dll
2011-01-18 15:32:38 ----A---- C:\Windows\system32\dxtmsft3.dll
2011-01-18 15:32:36 ----A---- C:\Windows\system32\strmdll.dll
2011-01-18 15:32:35 ----A---- C:\Windows\system32\unam4ie.exe
2011-01-18 15:32:32 ----A---- C:\Windows\system32\vidx16.dll
2011-01-18 15:32:32 ----A---- C:\Windows\system32\qcut.dll
2011-01-18 15:32:32 ----A---- C:\Windows\system32\danim.dll
2011-01-18 15:32:31 ----A---- C:\Windows\system32\w95inf32.dll
2011-01-18 15:32:31 ----A---- C:\Windows\system32\w95inf16.dll
2011-01-17 12:23:34 ----D---- C:\ProgramData\Nokia
2011-01-16 00:58:17 ----D---- C:\Users\ivo\AppData\Roaming\Uniblue
2011-01-16 00:57:24 ----D---- C:\Users\ivo\AppData\Roaming\FreeFileViewer
2011-01-16 00:55:30 ----D---- C:\Program Files\Free Offers from Freeze.com
2011-01-16 00:54:11 ----A---- C:\Windows\system32\WINUTIL5.DLL
2011-01-16 00:54:10 ----A---- C:\Windows\system32\WINLCTL5.DLL
2011-01-16 00:53:50 ----D---- C:\Program Files\Winferno
2011-01-14 19:18:55 ----D---- C:\Program Files\Symantec
2011-01-14 19:18:55 ----D---- C:\Program Files\Common Files\Symantec Shared
2011-01-14 19:18:55 ----A---- C:\Windows\system32\drivers\SYMEVENT.SYS
2011-01-14 19:18:13 ----D---- C:\Windows\system32\drivers\NIS
2011-01-14 19:18:08 ----D---- C:\Program Files\Norton Internet Security
2011-01-14 19:17:59 ----D---- C:\Program Files\NortonInstaller
2011-01-14 15:06:47 ----A---- C:\Windows\system32\drivers\aswFW.sys
2011-01-14 15:06:33 ----A---- C:\Windows\system32\drivers\aswNdis2.sys
2011-01-14 15:06:05 ----D---- C:\ProgramData\Alwil Software
2011-01-14 08:56:17 ----D---- C:\Program Files\AVG
2011-01-13 12:50:40 ----D---- C:\Users\ivo\AppData\Roaming\Tific
2011-01-12 18:40:31 ----D---- C:\Program Files\MSXML 4.0
2011-01-12 18:40:22 ----A---- C:\Windows\system32\d3d10warp.dll
2011-01-12 18:40:21 ----A---- C:\Windows\system32\XpsPrint.dll
2011-01-12 18:40:21 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-01-12 18:40:21 ----A---- C:\Windows\system32\mf.dll
2011-01-12 18:40:21 ----A---- C:\Windows\system32\FntCache.dll
2011-01-12 18:40:21 ----A---- C:\Windows\system32\DWrite.dll
2011-01-12 18:40:21 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-01-12 18:40:21 ----A---- C:\Windows\system32\d2d1.dll
2011-01-12 18:40:20 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-01-12 18:40:20 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-01-12 18:40:20 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-01-12 18:40:20 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-01-12 18:40:20 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-01-12 18:40:20 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-01-12 18:40:20 ----A---- C:\Windows\system32\d3d10_1.dll
2011-01-12 18:40:20 ----A---- C:\Windows\system32\cdd.dll
2011-01-12 18:40:17 ----A---- C:\Windows\system32\odbc32.dll
2011-01-11 17:38:24 ----D---- C:\Users\ivo\AppData\Roaming\Nokia
2011-01-11 17:38:00 ----D---- C:\ProgramData\PC Suite
2011-01-11 17:37:27 ----D---- C:\Users\ivo\AppData\Roaming\PC Suite
2011-01-11 17:35:27 ----D---- C:\Program Files\Common Files\Nokia
2011-01-11 17:34:38 ----D---- C:\Program Files\DIFX
2011-01-11 17:34:35 ----A---- C:\Windows\system32\drivers\pccsmcfd.sys
2011-01-11 17:34:26 ----DC---- C:\Windows\system32\DRVSTORE
2011-01-11 17:34:15 ----D---- C:\Program Files\PC Connectivity Solution
2011-01-11 17:33:22 ----A---- C:\Windows\system32\nmwcdcls.dll
2011-01-11 17:29:54 ----D---- C:\ProgramData\NokiaInstallerCache
2011-01-11 17:29:53 ----D---- C:\Program Files\Nokia
2011-01-10 12:17:37 ----D---- C:\Users\ivo\AppData\Roaming\Voipwise
======List of files/folders modified in the last 1 months======
2011-02-09 10:13:44 ----D---- C:\Program Files\trend micro
2011-02-09 10:13:39 ----D---- C:\Windows\Temp
2011-02-09 09:02:08 ----SHD---- C:\System Volume Information
2011-02-09 09:01:48 ----D---- C:\Windows
2011-02-09 09:00:47 ----D---- C:\Windows\system32\config
2011-02-09 09:00:20 ----D---- C:\Windows\system32\catroot
2011-02-09 08:59:42 ----D---- C:\Windows\system32\catroot2
2011-02-09 08:59:09 ----D---- C:\Windows\winsxs
2011-02-09 08:56:59 ----D---- C:\Windows\Prefetch
2011-02-09 06:34:13 ----D---- C:\Windows\system32\drivers
2011-02-08 19:34:30 ----D---- C:\Windows\ShellNew
2011-02-08 18:39:57 ----RD---- C:\Program Files
2011-02-06 12:14:15 ----HD---- C:\ProgramData
2011-02-06 12:05:09 ----HD---- C:\Program Files\InstallShield Installation Information
2011-02-06 09:15:02 ----D---- C:\Users\ivo\AppData\Roaming\Vso
2011-02-05 17:34:13 ----A---- C:\Windows\BlendSettings.ini
2011-02-04 19:26:57 ----D---- C:\Windows\System32
2011-02-04 00:56:12 ----D---- C:\Users\ivo\AppData\Roaming\Skype
2011-02-04 00:00:09 ----D---- C:\Users\ivo\AppData\Roaming\skypePM
2011-02-02 20:41:24 ----D---- C:\Users\ivo\AppData\Roaming\ICQ
2011-02-01 12:11:28 ----SD---- C:\Users\ivo\AppData\Roaming\Microsoft
2011-01-27 15:41:57 ----SHD---- C:\Windows\Installer
2011-01-26 10:27:36 ----D---- C:\Windows\system32\wdi
2011-01-26 07:28:35 ----RSD---- C:\Windows\assembly
2011-01-26 07:28:35 ----D---- C:\Windows\Microsoft.NET
2011-01-25 23:47:13 ----D---- C:\Program Files\CCleaner
2011-01-25 14:51:45 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-01-25 14:51:43 ----D---- C:\Windows\inf
2011-01-25 14:51:16 ----D---- C:\Windows\system32\en-US
2011-01-20 14:30:56 ----D---- C:\Program Files\Common Files\microsoft shared
2011-01-19 09:38:12 ----A---- C:\Windows\ODBC.INI
2011-01-19 09:22:53 ----D---- C:\Program Files\Microsoft Office
2011-01-19 09:19:16 ----RSD---- C:\Windows\Fonts
2011-01-19 00:47:59 ----D---- C:\Windows\system32\DriverStore
2011-01-19 00:47:08 ----SD---- C:\ProgramData\Microsoft
2011-01-19 00:41:27 ----A---- C:\Windows\win.ini
2011-01-18 22:48:58 ----D---- C:\Program Files\Common Files\InstallShield
2011-01-18 15:32:39 ----D---- C:\Program Files\Windows Media Player
2011-01-18 15:32:36 ----D---- C:\Windows\Help
2011-01-16 14:07:57 ----D---- C:\Windows\Panther
2011-01-16 11:52:53 ----D---- C:\Program Files\Mozilla Firefox
2011-01-16 01:17:41 ----D---- C:\Program Files\Common Files
2011-01-16 01:17:40 ----D---- C:\Program Files\Adobe
2011-01-16 01:06:47 ----D---- C:\Windows\Tasks
2011-01-16 01:06:47 ----D---- C:\Windows\system32\Tasks
2011-01-16 00:56:30 ----D---- C:\Users\ivo\AppData\Roaming\Adobe
2011-01-15 15:02:30 ----D---- C:\Program Files\Webteh
2011-01-14 19:36:24 ----D---- C:\ProgramData\NortonInstaller
2011-01-14 19:32:50 ----D---- C:\ProgramData\Norton
2011-01-14 17:44:56 ----SHD---- C:\Boot
2011-01-13 10:35:44 ----D---- C:\Windows\debug
2011-01-12 18:41:04 ----A---- C:\Windows\system32\MRT.exe
2011-01-12 16:37:48 ----D---- C:\Windows\rescache
2011-01-11 17:40:12 ----D---- C:\Windows\system32\drivers\UMDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswNdis2;avast! Firewall Core Firewall Service; C:\Windows\system32\drivers\aswNdis2.sys [2010-12-30 189776]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\NIS\1205000.07D\SYMDS.SYS [2010-10-21 340016]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\NIS\1205000.07D\SYMEFA.SYS [2010-11-18 652336]
R1 aswFW;avast! TDI Firewall driver; C:\Windows\system32\drivers\aswFW.sys [2010-12-30 99792]
R1 BHDrvx86;BHDrvx86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110114.001\BHDrvx86.sys [2010-11-23 691248]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2011-01-14 371248]
R1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20110208.003\IDSvix86.sys [2010-11-09 353912]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2010-04-12 59388]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\Windows\system32\drivers\NIS\1205000.07D\SRTSPX.SYS [2010-11-23 50168]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NIS\1205000.07D\Ironx86.SYS [2010-11-16 136312]
R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\System32\Drivers\NIS\1205000.07D\SYMNETS.SYS [2010-12-01 295032]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2011/01/03 05:09:36]; \??\C:\Program Files\CyberLink\PowerDVD9\000.fcl [2009-02-28 87536]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-11-26 6650368]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-11-26 231936]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2010-11-17 101392]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-01-15 102448]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2010-12-20 20952]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110208.021\NAVENG.SYS [2011-01-15 86008]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110208.021\NAVEX15.SYS [2011-01-15 1360760]
R3 PAC207;SoC PC-Camera; C:\Windows\system32\DRIVERS\PFC027.SYS [2006-12-05 507136]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2011-01-03 47360]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R3 SRTSP;Symantec Real Time Storage Protection; C:\Windows\System32\Drivers\NIS\1205000.07D\SRTSP.SYS [2010-11-23 509560]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2011-01-14 126512]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [2010-11-29 10064]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-11-26 6650368]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2009-07-14 27648]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-11-26 176128]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-12-20 363344]
R2 NIS;Norton Internet Security; C:\Program Files\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe [2010-11-24 130000]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [2010-12-14 1517376]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 avast! Firewall;avast! Firewall; C:\Program Files\Alwil Software\Avast5\afwServ.exe []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-01-03 1343400]
S4 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-06-14 615936]
-----------------EOF-----------------