Preventivna_kontrola-podozrenie_na_havet
Napsal: 20 úno 2011 16:21
Zdravim,
Ziadam a preventivnu kontrolu logu, mam podozrenie ze nie je nieco v poriadku, asi pred tydnem sa mi dostalo neco do PC. Prejavovalo sa to tak ze sa spustila ako keby nejaka kontrola ale pri tom nic neslo robit (spravca uloh nesel spustit, restartovat pc, vypinali sa spustene programy atd) na ploche sa zobrazilo pozadie (modre s cislami 0 a 1) bohuzial neslo mi spravit screen. Zistil som ze v C:\ProgramData som mal nejaky adresar v ktorom bol nejaky spustac, nazov bol ako keby hatlanina pismen a cisiel s priponou exe. Po odstraneni sa uz neprejavovali zaidne priznaky. Tak ziadam o kontrolu.
RSIT log:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Martin at 2011-02-20 16:03:51
Microsoft Windows 7 Ultimate
System drive C: has 28 GB (28%) free of 100 GB
Total RAM: 3063 MB (55% free)
HijackThis download failed
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\AEADISRV.EXE
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
C:\ASUS.SYS\CONFIG\DVMExportService.exe
"C:\Program Files\NetLimiter 3\nlsvc.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
"C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe"
C:\Windows\System32\alg.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
taskeng.exe {F999D546-9677-452D-9637-B04BE2E02350}
C:\Windows\Explorer.EXE
"C:\Program Files\ASUS\Six Engine\SixEngine.exe" -b
"C:\Program Files (x86)\Analog Devices\SoundMAX\SoundMAX.exe" /tray
"C:\Program Files (x86)\uTorrent\uTorrent.exe"
"C:\Program Files\NetLimiter 3\NLClientApp.exe" /tray
"C:\Program Files (x86)\Pidgin\pidgin.exe"
"C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe"
"C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe"
"taskhost.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
C:\Windows\System32\msdtc.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=536.9ccfe80.1080500612 "C:\Windows\system32\Macromed\Flash\NPSWF32.dll" 536 plugin \\.\pipe\gecko-crash-server-pipe.536
"C:\Users\Martin\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-05-23 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAX"=C:\Program Files (x86)\Analog Devices\SoundMAX\soundmax.exe [2009-05-18 3866624]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"=C:\Program Files (x86)\uTorrent\uTorrent.exe [2010-10-03 328056]
"NetLimiter"=C:\Program Files\NetLimiter 3\NLClientApp.exe [2010-03-25 2832384]
"SpywareTerminatorUpdate"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-12-22 3037696]
"Pidgin"=C:\Program Files (x86)\Pidgin\pidgin.exe [2010-12-27 48618]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeBridge]
C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe [2010-03-09 11989960]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2010-09-16 1164584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2009-02-25 2387968]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MultiScreen]
C:\Program Files (x86)\MultiScreen\MultiScreen.exe [2008-06-30 114688]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeSyncProcess]
C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [2010-03-16 718208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TurboV]
C:\Program Files\ASUS\TurboV\TurboV.exe [2009-10-20 5516800]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Martin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^GIGABYTE Gamer HUD Lite.lnk]
C:\PROGRA~2\GIGABYTE\GAMERH~1\HUD.exe [2009-06-30 1678848]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Martin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft SharePoint Workspace.lnk]
C:\PROGRA~2\MICROS~1\Office14\GROOVE.EXE [2010-03-25 30969208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Martin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
C:\PROGRA~2\OPENOF~1.ORG\program\QUICKS~1.EXE [2010-02-16 384512]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [2009-06-05 1310720]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"SpywareTerminator"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2010-12-22 2176512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS5\Dreamweaver.exe","%1"
.vbs - edit -
.vbs - open - "C:\Program Files (x86)\Bluefish\bluefish.exe" "%1"
======List of files/folders created in the last 1 months======
2011-02-20 16:03:51 ----D---- C:\rsit
2011-02-20 16:03:51 ----D---- C:\Program Files\trend micro
2011-02-09 12:32:22 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-02-09 12:32:22 ----A---- C:\Windows\system32\mshtml.dll
2011-02-09 12:32:19 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-02-09 12:32:18 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-02-09 12:32:18 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-02-09 12:32:18 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-02-09 12:32:18 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-02-09 12:32:18 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-02-09 12:32:18 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-02-09 12:32:18 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-02-09 12:32:18 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-02-09 12:32:18 ----A---- C:\Windows\system32\mstime.dll
2011-02-09 12:32:18 ----A---- C:\Windows\system32\mshtmled.dll
2011-02-09 12:32:18 ----A---- C:\Windows\system32\msfeedssync.exe
2011-02-09 12:32:18 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-02-09 12:32:18 ----A---- C:\Windows\system32\msfeeds.dll
2011-02-09 12:32:18 ----A---- C:\Windows\system32\licmgr10.dll
2011-02-09 12:32:18 ----A---- C:\Windows\system32\iertutil.dll
2011-02-09 12:32:18 ----A---- C:\Windows\system32\iepeers.dll
2011-02-09 12:32:18 ----A---- C:\Windows\system32\iedkcs32.dll
2011-02-09 12:31:48 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2011-02-09 12:31:48 ----A---- C:\Windows\system32\kerberos.dll
2011-02-09 12:31:46 ----A---- C:\Windows\system32\win32k.sys
2011-02-09 12:31:44 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-02-09 12:31:44 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-02-09 12:31:44 ----A---- C:\Windows\system32\urlmon.dll
2011-02-09 12:31:44 ----A---- C:\Windows\system32\upnp.dll
2011-02-09 12:31:44 ----A---- C:\Windows\system32\msxml6.dll
2011-02-09 12:31:44 ----A---- C:\Windows\system32\msxml3.dll
2011-02-09 12:31:43 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-02-09 12:31:43 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-02-09 12:31:43 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-02-09 12:31:43 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-02-09 12:31:43 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-02-09 12:31:43 ----A---- C:\Windows\system32\wscapi.dll
2011-02-09 12:31:43 ----A---- C:\Windows\system32\wininet.dll
2011-02-09 12:31:43 ----A---- C:\Windows\system32\winhttp.dll
2011-02-09 12:31:43 ----A---- C:\Windows\system32\WebClnt.dll
2011-02-09 12:31:43 ----A---- C:\Windows\system32\ieframe.dll
2011-02-09 12:31:43 ----A---- C:\Windows\system32\davclnt.dll
2011-02-09 12:31:42 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2011-02-09 12:31:42 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-02-09 12:31:42 ----A---- C:\Windows\SYSWOW64\slwga.dll
2011-02-09 12:31:42 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2011-02-09 12:31:42 ----A---- C:\Windows\system32\wscsvc.dll
2011-02-09 12:31:42 ----A---- C:\Windows\system32\slwga.dll
2011-02-09 12:31:39 ----A---- C:\Windows\system32\winsrv.dll
2011-02-09 12:31:38 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-02-09 12:31:38 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-02-09 12:31:38 ----A---- C:\Windows\system32\cdd.dll
2011-02-09 12:31:36 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-02-09 12:31:36 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-02-09 12:31:36 ----A---- C:\Windows\system32\vbscript.dll
2011-02-09 12:31:36 ----A---- C:\Windows\system32\jscript.dll
2011-02-09 12:31:33 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-02-09 12:31:33 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-02-09 12:31:33 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-02-09 12:31:33 ----A---- C:\Windows\system32\ntdll.dll
2011-02-09 12:31:32 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-02-09 12:31:31 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-02-09 12:31:31 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-02-09 12:31:31 ----A---- C:\Windows\system32\atmlib.dll
2011-02-09 12:31:31 ----A---- C:\Windows\system32\atmfd.dll
2011-01-23 20:57:53 ----D---- C:\Program Files (x86)\World of Warcraft
2011-01-21 22:31:56 ----D---- C:\ProgramData\Blizzard
======List of files/folders modified in the last 1 months======
2011-02-20 16:03:52 ----D---- C:\Windows\Temp
2011-02-20 16:03:51 ----RD---- C:\Program Files
2011-02-20 16:03:47 ----D---- C:\Windows\Prefetch
2011-02-20 16:01:29 ----D---- C:\Users\Martin\AppData\Roaming\.purple
2011-02-20 15:58:49 ----D---- C:\Users\Martin\AppData\Roaming\uTorrent
2011-02-20 15:55:39 ----D---- C:\Windows\registration
2011-02-20 15:49:14 ----D---- C:\Windows
2011-02-20 15:49:07 ----D---- C:\Program Files (x86)\DAEMON Tools Toolbar
2011-02-20 15:48:56 ----SHD---- C:\Windows\Installer
2011-02-20 15:48:48 ----SHD---- C:\System Volume Information
2011-02-20 15:48:32 ----D---- C:\Windows\system32\appmgmt
2011-02-20 15:04:57 ----D---- C:\Windows\system32\LogFiles
2011-02-20 14:32:14 ----D---- C:\Windows\system32\Tasks
2011-02-20 11:21:14 ----D---- C:\Windows\system32\config
2011-02-20 11:08:00 ----D---- C:\ProgramData\NVIDIA
2011-02-19 22:43:33 ----D---- C:\Users\Martin\AppData\Roaming\FileZilla
2011-02-16 11:45:53 ----D---- C:\Windows\system32\NDF
2011-02-16 01:00:25 ----D---- C:\Windows\system32\catroot2
2011-02-15 17:21:52 ----D---- C:\Windows\debug
2011-02-15 17:18:51 ----HD---- C:\ProgramData
2011-02-15 17:12:07 ----D---- C:\ProgramData\Spyware Terminator
2011-02-15 17:11:28 ----D---- C:\Program Files (x86)\Spyware Terminator
2011-02-15 17:10:05 ----D---- C:\Users\Martin\AppData\Roaming\Spyware Terminator
2011-02-14 23:01:38 ----D---- C:\Users\Martin\AppData\Roaming\dvdcss
2011-02-14 21:29:28 ----SD---- C:\Users\Martin\AppData\Roaming\Microsoft
2011-02-12 20:21:09 ----D---- C:\Users\Martin\AppData\Roaming\Adobe
2011-02-10 15:10:15 ----RSD---- C:\Windows\assembly
2011-02-10 15:10:15 ----D---- C:\Windows\Microsoft.NET
2011-02-10 12:51:10 ----D---- C:\Windows\winsxs
2011-02-10 12:49:16 ----D---- C:\Windows\SysWOW64
2011-02-10 12:49:16 ----D---- C:\Windows\System32
2011-02-10 12:49:16 ----D---- C:\Program Files\Internet Explorer
2011-02-10 12:49:16 ----D---- C:\Program Files (x86)\Internet Explorer
2011-02-10 12:49:14 ----D---- C:\Windows\system32\drivers
2011-02-10 01:11:42 ----SHD---- C:\Config.Msi
2011-02-10 01:11:32 ----D---- C:\ProgramData\Microsoft Help
2011-02-10 01:09:41 ----A---- C:\Windows\system32\MRT.exe
2011-02-10 01:08:00 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-02-10 01:07:59 ----D---- C:\Windows\inf
2011-02-09 12:31:22 ----D---- C:\Windows\system32\catroot
2011-02-08 13:01:16 ----D---- C:\Windows\SYSWOW64\en-US
2011-02-08 13:01:16 ----D---- C:\Windows\system32\en-US
2011-02-08 13:01:14 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-01-30 22:04:34 ----D---- C:\Users\Martin\AppData\Roaming\gtk-2.0
2011-01-30 21:11:44 ----D---- C:\Users\Martin\AppData\Roaming\DivX
2011-01-24 02:24:46 ----D---- C:\Users\Martin\AppData\Roaming\Skype
2011-01-24 00:01:43 ----D---- C:\Users\Martin\AppData\Roaming\skypePM
2011-01-23 20:57:53 ----D---- C:\Program Files (x86)
2011-01-22 23:55:55 ----D---- C:\Program Files (x86)\Valve
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 mv61xx;mv61xx; C:\Windows\system32\DRIVERS\mv61xx.sys [2009-05-11 178728]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-04-11 834544]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-08-04 13440]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 nltdi;nltdi; \??\C:\Program Files\NetLimiter 3\nltdi.sys [2010-03-25 88200]
R1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys [2010-10-08 203024]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows\system32\DRIVERS\VBoxUSBMon.sys [2010-10-08 53968]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-05-10 314016]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-05-10 43680]
R2 sp_rsdrv2;Spyware Terminator Driver Filter; C:\Windows\system32\DRIVERS\stflt.sys [2010-07-07 50696]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2009-06-05 475136]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 NLNdisMP;NLNdisMP; C:\Windows\system32\DRIVERS\nlndis.sys [2010-03-25 33416]
R3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2010-10-08 144784]
R3 VBoxNetFlt;VBoxNetFlt Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys [2010-10-08 164304]
S3 a4ni7cud;a4ni7cud; C:\Windows\system32\drivers\a4ni7cud.sys []
S3 KMWDFILTER;HIDServiceDesc; C:\Windows\system32\DRIVERS\KMWDFILTER.sys [2009-04-29 30208]
S3 NLNdisPT;NetLimiter Ndis Protocol Service; C:\Windows\system32\DRIVERS\nlndis.sys [2010-03-25 33416]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys []
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 teamviewervpn;TeamViewer VPN Adapter; C:\Windows\system32\DRIVERS\teamviewervpn.sys [2010-11-30 35112]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2009-06-05 111616]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-08-19 90112]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2009-02-25 73728]
R2 MDES;DVM Meta Data Export Service; C:\ASUS.SYS\CONFIG\DVMExportService.exe [2009-02-18 315392]
R2 nlsvc;NetLimiter 3 Service; C:\Program Files\NetLimiter 3\nlsvc.exe [2010-03-25 1740288]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-09 159336]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2010-04-14 75064]
R2 PnkBstrB;PnkBstrB; C:\Windows\syswow64\PnkBstrB.exe [2010-04-14 189248]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe [2010-12-22 488960]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-09 248936]
R2 TeamViewer6;TeamViewer 6; C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-06-29 135664]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-29 1255736]
-----------------EOF-----------------
PS:// na NB mi robilo to same, pre log s RSIT mam zalozit novu temu? ci staci to vlozit sem?
Vdaka,
Ziadam a preventivnu kontrolu logu, mam podozrenie ze nie je nieco v poriadku, asi pred tydnem sa mi dostalo neco do PC. Prejavovalo sa to tak ze sa spustila ako keby nejaka kontrola ale pri tom nic neslo robit (spravca uloh nesel spustit, restartovat pc, vypinali sa spustene programy atd) na ploche sa zobrazilo pozadie (modre s cislami 0 a 1) bohuzial neslo mi spravit screen. Zistil som ze v C:\ProgramData som mal nejaky adresar v ktorom bol nejaky spustac, nazov bol ako keby hatlanina pismen a cisiel s priponou exe. Po odstraneni sa uz neprejavovali zaidne priznaky. Tak ziadam o kontrolu.
RSIT log:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Martin at 2011-02-20 16:03:51
Microsoft Windows 7 Ultimate
System drive C: has 28 GB (28%) free of 100 GB
Total RAM: 3063 MB (55% free)
HijackThis download failed
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\AEADISRV.EXE
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
C:\ASUS.SYS\CONFIG\DVMExportService.exe
"C:\Program Files\NetLimiter 3\nlsvc.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
"C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe"
C:\Windows\System32\alg.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
taskeng.exe {F999D546-9677-452D-9637-B04BE2E02350}
C:\Windows\Explorer.EXE
"C:\Program Files\ASUS\Six Engine\SixEngine.exe" -b
"C:\Program Files (x86)\Analog Devices\SoundMAX\SoundMAX.exe" /tray
"C:\Program Files (x86)\uTorrent\uTorrent.exe"
"C:\Program Files\NetLimiter 3\NLClientApp.exe" /tray
"C:\Program Files (x86)\Pidgin\pidgin.exe"
"C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe"
"C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe"
"taskhost.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
C:\Windows\System32\msdtc.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=536.9ccfe80.1080500612 "C:\Windows\system32\Macromed\Flash\NPSWF32.dll" 536 plugin \\.\pipe\gecko-crash-server-pipe.536
"C:\Users\Martin\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-05-23 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAX"=C:\Program Files (x86)\Analog Devices\SoundMAX\soundmax.exe [2009-05-18 3866624]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"=C:\Program Files (x86)\uTorrent\uTorrent.exe [2010-10-03 328056]
"NetLimiter"=C:\Program Files\NetLimiter 3\NLClientApp.exe [2010-03-25 2832384]
"SpywareTerminatorUpdate"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-12-22 3037696]
"Pidgin"=C:\Program Files (x86)\Pidgin\pidgin.exe [2010-12-27 48618]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeBridge]
C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe [2010-03-09 11989960]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2010-09-16 1164584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2009-02-25 2387968]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MultiScreen]
C:\Program Files (x86)\MultiScreen\MultiScreen.exe [2008-06-30 114688]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeSyncProcess]
C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [2010-03-16 718208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TurboV]
C:\Program Files\ASUS\TurboV\TurboV.exe [2009-10-20 5516800]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Martin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^GIGABYTE Gamer HUD Lite.lnk]
C:\PROGRA~2\GIGABYTE\GAMERH~1\HUD.exe [2009-06-30 1678848]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Martin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft SharePoint Workspace.lnk]
C:\PROGRA~2\MICROS~1\Office14\GROOVE.EXE [2010-03-25 30969208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Martin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
C:\PROGRA~2\OPENOF~1.ORG\program\QUICKS~1.EXE [2010-02-16 384512]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [2009-06-05 1310720]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"SpywareTerminator"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2010-12-22 2176512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS5\Dreamweaver.exe","%1"
.vbs - edit -
.vbs - open - "C:\Program Files (x86)\Bluefish\bluefish.exe" "%1"
======List of files/folders created in the last 1 months======
2011-02-20 16:03:51 ----D---- C:\rsit
2011-02-20 16:03:51 ----D---- C:\Program Files\trend micro
2011-02-09 12:32:22 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-02-09 12:32:22 ----A---- C:\Windows\system32\mshtml.dll
2011-02-09 12:32:19 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-02-09 12:32:18 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-02-09 12:32:18 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-02-09 12:32:18 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-02-09 12:32:18 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-02-09 12:32:18 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-02-09 12:32:18 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-02-09 12:32:18 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-02-09 12:32:18 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-02-09 12:32:18 ----A---- C:\Windows\system32\mstime.dll
2011-02-09 12:32:18 ----A---- C:\Windows\system32\mshtmled.dll
2011-02-09 12:32:18 ----A---- C:\Windows\system32\msfeedssync.exe
2011-02-09 12:32:18 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-02-09 12:32:18 ----A---- C:\Windows\system32\msfeeds.dll
2011-02-09 12:32:18 ----A---- C:\Windows\system32\licmgr10.dll
2011-02-09 12:32:18 ----A---- C:\Windows\system32\iertutil.dll
2011-02-09 12:32:18 ----A---- C:\Windows\system32\iepeers.dll
2011-02-09 12:32:18 ----A---- C:\Windows\system32\iedkcs32.dll
2011-02-09 12:31:48 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2011-02-09 12:31:48 ----A---- C:\Windows\system32\kerberos.dll
2011-02-09 12:31:46 ----A---- C:\Windows\system32\win32k.sys
2011-02-09 12:31:44 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-02-09 12:31:44 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-02-09 12:31:44 ----A---- C:\Windows\system32\urlmon.dll
2011-02-09 12:31:44 ----A---- C:\Windows\system32\upnp.dll
2011-02-09 12:31:44 ----A---- C:\Windows\system32\msxml6.dll
2011-02-09 12:31:44 ----A---- C:\Windows\system32\msxml3.dll
2011-02-09 12:31:43 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-02-09 12:31:43 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-02-09 12:31:43 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-02-09 12:31:43 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-02-09 12:31:43 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-02-09 12:31:43 ----A---- C:\Windows\system32\wscapi.dll
2011-02-09 12:31:43 ----A---- C:\Windows\system32\wininet.dll
2011-02-09 12:31:43 ----A---- C:\Windows\system32\winhttp.dll
2011-02-09 12:31:43 ----A---- C:\Windows\system32\WebClnt.dll
2011-02-09 12:31:43 ----A---- C:\Windows\system32\ieframe.dll
2011-02-09 12:31:43 ----A---- C:\Windows\system32\davclnt.dll
2011-02-09 12:31:42 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2011-02-09 12:31:42 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-02-09 12:31:42 ----A---- C:\Windows\SYSWOW64\slwga.dll
2011-02-09 12:31:42 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2011-02-09 12:31:42 ----A---- C:\Windows\system32\wscsvc.dll
2011-02-09 12:31:42 ----A---- C:\Windows\system32\slwga.dll
2011-02-09 12:31:39 ----A---- C:\Windows\system32\winsrv.dll
2011-02-09 12:31:38 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-02-09 12:31:38 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-02-09 12:31:38 ----A---- C:\Windows\system32\cdd.dll
2011-02-09 12:31:36 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-02-09 12:31:36 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-02-09 12:31:36 ----A---- C:\Windows\system32\vbscript.dll
2011-02-09 12:31:36 ----A---- C:\Windows\system32\jscript.dll
2011-02-09 12:31:33 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-02-09 12:31:33 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-02-09 12:31:33 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-02-09 12:31:33 ----A---- C:\Windows\system32\ntdll.dll
2011-02-09 12:31:32 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-02-09 12:31:31 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-02-09 12:31:31 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-02-09 12:31:31 ----A---- C:\Windows\system32\atmlib.dll
2011-02-09 12:31:31 ----A---- C:\Windows\system32\atmfd.dll
2011-01-23 20:57:53 ----D---- C:\Program Files (x86)\World of Warcraft
2011-01-21 22:31:56 ----D---- C:\ProgramData\Blizzard
======List of files/folders modified in the last 1 months======
2011-02-20 16:03:52 ----D---- C:\Windows\Temp
2011-02-20 16:03:51 ----RD---- C:\Program Files
2011-02-20 16:03:47 ----D---- C:\Windows\Prefetch
2011-02-20 16:01:29 ----D---- C:\Users\Martin\AppData\Roaming\.purple
2011-02-20 15:58:49 ----D---- C:\Users\Martin\AppData\Roaming\uTorrent
2011-02-20 15:55:39 ----D---- C:\Windows\registration
2011-02-20 15:49:14 ----D---- C:\Windows
2011-02-20 15:49:07 ----D---- C:\Program Files (x86)\DAEMON Tools Toolbar
2011-02-20 15:48:56 ----SHD---- C:\Windows\Installer
2011-02-20 15:48:48 ----SHD---- C:\System Volume Information
2011-02-20 15:48:32 ----D---- C:\Windows\system32\appmgmt
2011-02-20 15:04:57 ----D---- C:\Windows\system32\LogFiles
2011-02-20 14:32:14 ----D---- C:\Windows\system32\Tasks
2011-02-20 11:21:14 ----D---- C:\Windows\system32\config
2011-02-20 11:08:00 ----D---- C:\ProgramData\NVIDIA
2011-02-19 22:43:33 ----D---- C:\Users\Martin\AppData\Roaming\FileZilla
2011-02-16 11:45:53 ----D---- C:\Windows\system32\NDF
2011-02-16 01:00:25 ----D---- C:\Windows\system32\catroot2
2011-02-15 17:21:52 ----D---- C:\Windows\debug
2011-02-15 17:18:51 ----HD---- C:\ProgramData
2011-02-15 17:12:07 ----D---- C:\ProgramData\Spyware Terminator
2011-02-15 17:11:28 ----D---- C:\Program Files (x86)\Spyware Terminator
2011-02-15 17:10:05 ----D---- C:\Users\Martin\AppData\Roaming\Spyware Terminator
2011-02-14 23:01:38 ----D---- C:\Users\Martin\AppData\Roaming\dvdcss
2011-02-14 21:29:28 ----SD---- C:\Users\Martin\AppData\Roaming\Microsoft
2011-02-12 20:21:09 ----D---- C:\Users\Martin\AppData\Roaming\Adobe
2011-02-10 15:10:15 ----RSD---- C:\Windows\assembly
2011-02-10 15:10:15 ----D---- C:\Windows\Microsoft.NET
2011-02-10 12:51:10 ----D---- C:\Windows\winsxs
2011-02-10 12:49:16 ----D---- C:\Windows\SysWOW64
2011-02-10 12:49:16 ----D---- C:\Windows\System32
2011-02-10 12:49:16 ----D---- C:\Program Files\Internet Explorer
2011-02-10 12:49:16 ----D---- C:\Program Files (x86)\Internet Explorer
2011-02-10 12:49:14 ----D---- C:\Windows\system32\drivers
2011-02-10 01:11:42 ----SHD---- C:\Config.Msi
2011-02-10 01:11:32 ----D---- C:\ProgramData\Microsoft Help
2011-02-10 01:09:41 ----A---- C:\Windows\system32\MRT.exe
2011-02-10 01:08:00 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-02-10 01:07:59 ----D---- C:\Windows\inf
2011-02-09 12:31:22 ----D---- C:\Windows\system32\catroot
2011-02-08 13:01:16 ----D---- C:\Windows\SYSWOW64\en-US
2011-02-08 13:01:16 ----D---- C:\Windows\system32\en-US
2011-02-08 13:01:14 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-01-30 22:04:34 ----D---- C:\Users\Martin\AppData\Roaming\gtk-2.0
2011-01-30 21:11:44 ----D---- C:\Users\Martin\AppData\Roaming\DivX
2011-01-24 02:24:46 ----D---- C:\Users\Martin\AppData\Roaming\Skype
2011-01-24 00:01:43 ----D---- C:\Users\Martin\AppData\Roaming\skypePM
2011-01-23 20:57:53 ----D---- C:\Program Files (x86)
2011-01-22 23:55:55 ----D---- C:\Program Files (x86)\Valve
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 mv61xx;mv61xx; C:\Windows\system32\DRIVERS\mv61xx.sys [2009-05-11 178728]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-04-11 834544]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-08-04 13440]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 nltdi;nltdi; \??\C:\Program Files\NetLimiter 3\nltdi.sys [2010-03-25 88200]
R1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys [2010-10-08 203024]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows\system32\DRIVERS\VBoxUSBMon.sys [2010-10-08 53968]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-05-10 314016]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-05-10 43680]
R2 sp_rsdrv2;Spyware Terminator Driver Filter; C:\Windows\system32\DRIVERS\stflt.sys [2010-07-07 50696]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2009-06-05 475136]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 NLNdisMP;NLNdisMP; C:\Windows\system32\DRIVERS\nlndis.sys [2010-03-25 33416]
R3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2010-10-08 144784]
R3 VBoxNetFlt;VBoxNetFlt Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys [2010-10-08 164304]
S3 a4ni7cud;a4ni7cud; C:\Windows\system32\drivers\a4ni7cud.sys []
S3 KMWDFILTER;HIDServiceDesc; C:\Windows\system32\DRIVERS\KMWDFILTER.sys [2009-04-29 30208]
S3 NLNdisPT;NetLimiter Ndis Protocol Service; C:\Windows\system32\DRIVERS\nlndis.sys [2010-03-25 33416]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys []
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 teamviewervpn;TeamViewer VPN Adapter; C:\Windows\system32\DRIVERS\teamviewervpn.sys [2010-11-30 35112]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2009-06-05 111616]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-08-19 90112]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2009-02-25 73728]
R2 MDES;DVM Meta Data Export Service; C:\ASUS.SYS\CONFIG\DVMExportService.exe [2009-02-18 315392]
R2 nlsvc;NetLimiter 3 Service; C:\Program Files\NetLimiter 3\nlsvc.exe [2010-03-25 1740288]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-09 159336]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2010-04-14 75064]
R2 PnkBstrB;PnkBstrB; C:\Windows\syswow64\PnkBstrB.exe [2010-04-14 189248]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe [2010-12-22 488960]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-09 248936]
R2 TeamViewer6;TeamViewer 6; C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-06-29 135664]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-29 1255736]
-----------------EOF-----------------
PS:// na NB mi robilo to same, pre log s RSIT mam zalozit novu temu? ci staci to vlozit sem?
Vdaka,