Stránka 1 z 1

prosim o preventivku

Napsal: 09 dub 2011 08:10
od 00Inferno00
Díky

Logfile of random's system information tool 1.08 (written by random/random)
Run by Jan at 2011-04-09 09:09:12
Systém Microsoft Windows XP Professional Service Pack 3
System drive D: has 15 GB (6%) free of 238 GB
Total RAM: 3327 MB (81% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:09:16, on 9.4.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\AVAST Software\Avast\AvastSvc.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Analog Devices\Core\smax4pnp.exe
D:\Program Files\AVAST Software\Avast\avastUI.exe
D:\Program Files\Analog Devices\SoundMAX\Smax4.exe
D:\Program Files\Microsoft ActiveSync\Wcescomm.exe
D:\Program Files\Logitech\Profiler\lwemon.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Documents and Settings\Jan\Plocha\O.C\Core Temp.exe
D:\PROGRA~1\MI3AA1~1\rapimgr.exe
D:\Documents and Settings\Jan\Plocha\SpeedFan\speedfan.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\ICQ6Toolbar\ICQ Service.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
D:\WINDOWS\system32\wbem\wmiapsrv.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Winamp\winamp.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Mozilla Firefox\plugin-container.exe
D:\Documents and Settings\Jan\Plocha\RSIT.exe
D:\WINDOWS\system32\wscntfy.exe
D:\Program Files\trend micro\Jan.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/sm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - D:\Documents and Settings\Jan\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - D:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - D:\Documents and Settings\Jan\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - D:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [SoundMAXPnP] D:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [avast] "D:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SoundMax] "D:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [uTorrent] "D:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Start WingMan Profiler] "D:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Core Temp] D:\Documents and Settings\Jan\Plocha\O.C\Core Temp.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Zástupce - speedfan.lnk = D:\Documents and Settings\Jan\Plocha\SpeedFan\speedfan.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{4FE42FBC-A8C6-4C80-AF62-CF7D532108D9}: NameServer = 212.71.150.16,82.209.19.226
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - AVAST Software - D:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: ICQ Service - Unknown owner - D:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 7479 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\1-Click Maintenance.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - D:\Program Files\Winamp Toolbar\winamptb.dll [2011-03-11 1373512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - D:\Documents and Settings\Jan\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2011-02-01 141184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-03 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-02-03 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-06-21 1018680]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - D:\Program Files\Winamp Toolbar\winamptb.dll [2011-03-11 1373512]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=D:\Program Files\Analog Devices\Core\smax4pnp.exe [2006-12-18 868352]
"avast"=D:\Program Files\AVAST Software\Avast\avastUI.exe [2011-02-23 3451496]
"SoundMax"=D:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2006-07-13 729088]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"=D:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
"uTorrent"=D:\Program Files\uTorrent\uTorrent.exe [2011-03-29 399736]
"Start WingMan Profiler"=D:\Program Files\Logitech\Profiler\lwemon.exe [2005-04-18 73728]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Core Temp"=D:\Documents and Settings\Jan\Plocha\O.C\Core Temp.exe [2009-05-29 260624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
D:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe []

D:\Documents and Settings\Jan\Nabídka Start\Programy\Po spuštění
Zástupce - speedfan.lnk - D:\Documents and Settings\Jan\Plocha\SpeedFan\speedfan.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
D:\WINDOWS\system32\Ati2evxx.dll [2010-02-11 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
D:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\Codemasters\GRID\GRID.exe"="D:\Program Files\Codemasters\GRID\GRID.exe:*:Enabled:GRID"
"D:\Program Files\uTorrent\uTorrent.exe"="D:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"="D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"D:\Program Files\Codemasters\DiRT2\dirt2_game.exe"="D:\Program Files\Codemasters\DiRT2\dirt2_game.exe:*:Enabled:DiRT2"
"D:\Program Files\ICQ7.4\ICQ.exe"="D:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"
"D:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab Setup Files\Kaspersky Internet Security 2009\Czech\setup.exe"="D:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab Setup Files\Kaspersky Internet Security 2009\Czech\setup.exe:*:Disabled:Kaspersky Internet Security 2009 Setup"
"D:\Program Files\Valve\Half-Life 2\hl2.exe"="D:\Program Files\Valve\Half-Life 2\hl2.exe:*:Enabled:HL2_1"
"D:\Program Files\Valve\Half-Life 2 Episode One\hl2.exe"="D:\Program Files\Valve\Half-Life 2 Episode One\hl2.exe:*:Enabled:HL2_2"
"D:\Program Files\Valve\Half-Life 2 Episode Two\hl2.exe"="D:\Program Files\Valve\Half-Life 2 Episode Two\hl2.exe:*:Enabled:HL2_3"
"D:\Program Files\SIERRA\Half-Life\hl.exe"="D:\Program Files\SIERRA\Half-Life\hl.exe:*:Enabled:Half-Life Launcher"
"D:\Program Files\Electronic Arts\SHIFT 2 UNLEASHED\shift2u.exe"="D:\Program Files\Electronic Arts\SHIFT 2 UNLEASHED\shift2u.exe:*:Enabled:SHIFT 2 UNLEASHED™"
"D:\Program Files\Winamp\winamp.exe"="D:\Program Files\Winamp\winamp.exe:*:Enabled:Winamp"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"="D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"D:\Program Files\ICQ7.4\ICQ.exe"="D:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"

======List of files/folders created in the last 1 months======

2011-04-08 13:34:42 ----D---- D:\Program Files\Winamp Detect
2011-04-08 13:34:39 ----D---- D:\Program Files\Winamp Toolbar
2011-04-08 13:34:39 ----D---- D:\Documents and Settings\All Users\Data aplikací\Winamp Toolbar
2011-04-08 13:34:37 ----D---- D:\Program Files\Common Files\Software Update Utility
2011-04-08 13:34:12 ----N---- D:\WINDOWS\system32\pxwma.dll
2011-04-08 13:34:12 ----N---- D:\WINDOWS\system32\pxinsi64.exe
2011-04-08 13:34:12 ----N---- D:\WINDOWS\system32\pxcpyi64.exe
2011-04-07 09:17:48 ----D---- D:\Program Files\18 WoS Extreme Trucker 2
2011-04-06 08:56:16 ----D---- D:\WINDOWS\system32\Scania V8 dir
2011-04-06 08:55:06 ----D---- D:\WINDOWS\ScaniaScr
2011-04-06 08:55:06 ----A---- D:\WINDOWS\unbud001.exe
2011-04-05 21:30:22 ----D---- D:\totalcmd
2011-04-05 21:30:22 ----A---- D:\WINDOWS\wincmd.ini
2011-04-05 21:30:22 ----A---- D:\WINDOWS\UC.PIF
2011-04-05 21:30:22 ----A---- D:\WINDOWS\RAR.PIF
2011-04-05 21:30:22 ----A---- D:\WINDOWS\PKZIP.PIF
2011-04-05 21:30:22 ----A---- D:\WINDOWS\PKUNZIP.PIF
2011-04-05 21:30:22 ----A---- D:\WINDOWS\NOCLOSE.PIF
2011-04-05 21:30:22 ----A---- D:\WINDOWS\LHA.PIF
2011-04-05 21:30:22 ----A---- D:\WINDOWS\ARJ.PIF
2011-04-05 13:12:36 ----D---- D:\Documents and Settings\Jan\Data aplikací\TomTom
2011-04-04 23:20:55 ----SHD---- D:\RECYCLER
2011-04-04 09:32:15 ----D---- D:\Program Files\Multiple Image Resizer .NET
2011-04-04 09:09:16 ----D---- D:\WINDOWS\pss
2011-04-03 20:44:24 ----D---- D:\Documents and Settings\Jan\Data aplikací\PriceGong
2011-04-03 18:55:08 ----D---- D:\Program Files\NVIDIA Corporation
2011-04-03 14:14:55 ----A---- D:\ComboFix.txt
2011-04-03 13:31:11 ----A---- D:\WINDOWS\zip.exe
2011-04-03 13:31:11 ----A---- D:\WINDOWS\SWXCACLS.exe
2011-04-03 13:31:11 ----A---- D:\WINDOWS\SWSC.exe
2011-04-03 13:31:11 ----A---- D:\WINDOWS\SWREG.exe
2011-04-03 13:31:11 ----A---- D:\WINDOWS\sed.exe
2011-04-03 13:31:11 ----A---- D:\WINDOWS\PEV.exe
2011-04-03 13:31:11 ----A---- D:\WINDOWS\NIRCMD.exe
2011-04-03 13:31:11 ----A---- D:\WINDOWS\MBR.exe
2011-04-03 13:31:11 ----A---- D:\WINDOWS\grep.exe
2011-04-03 11:28:34 ----D---- D:\Documents and Settings\Jan\Data aplikací\TuneUp Software
2011-04-03 11:28:20 ----D---- D:\Program Files\TuneUp Utilities 2008
2011-04-03 11:28:00 ----D---- D:\Program Files\Common Files\Wise Installation Wizard
2011-04-02 07:30:49 ----D---- D:\Config.Msi
2011-04-01 21:37:45 ----D---- D:\Program Files\prjMegaTrain
2011-03-31 21:39:10 ----D---- D:\Program Files\mega_train
2011-03-31 21:38:21 ----N---- D:\WINDOWS\Setup1.exe
2011-03-31 21:38:20 ----A---- D:\WINDOWS\ST6UNST.EXE
2011-03-31 19:57:49 ----A---- D:\WINDOWS\system32\SNWValid.dll
2011-03-31 19:57:49 ----A---- D:\WINDOWS\system32\SierraNW.dll
2011-03-31 19:57:45 ----D---- D:\Program Files\Sierra On-Line
2011-03-31 19:57:44 ----D---- D:\Program Files\SIERRA
2011-03-31 19:54:11 ----A---- D:\WINDOWS\SIERRA.INI
2011-03-31 15:08:46 ----D---- D:\Documents and Settings\All Users\Data aplikací\EA Core
2011-03-30 22:42:34 ----D---- D:\Program Files\Valve
2011-03-30 21:26:20 ----D---- D:\Program Files\Common Files\ATI Technologies
2011-03-30 21:26:08 ----D---- D:\Program Files\DIFX
2011-03-30 19:53:19 ----D---- D:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab Setup Files
2011-03-30 12:15:58 ----D---- D:\Documents and Settings\All Users\Data aplikací\U3
2011-03-29 20:39:26 ----D---- D:\Program Files\MG4
2011-03-29 18:28:12 ----A---- D:\WINDOWS\system32\drivers\AsIO.sys
2011-03-29 18:28:12 ----A---- D:\WINDOWS\system32\AsIO.dll
2011-03-29 18:28:10 ----D---- D:\Program Files\ASUS
2011-03-29 18:28:10 ----A---- D:\WINDOWS\system32\drivers\AsInsHelp64.sys
2011-03-29 18:28:10 ----A---- D:\WINDOWS\system32\drivers\AsInsHelp32.sys
2011-03-28 09:10:36 ----D---- D:\Program Files\podXP
2011-03-28 09:07:30 ----D---- D:\Program Files\Common Files\Adobe
2011-03-28 09:07:30 ----D---- D:\Program Files\Adobe
2011-03-28 09:07:07 ----D---- D:\Documents and Settings\All Users\Data aplikací\Adobe
2011-03-27 19:15:13 ----D---- D:\WINDOWS\temp
2011-03-27 15:57:38 ----D---- D:\Program Files\ICQ6Toolbar
2011-03-27 15:57:10 ----D---- D:\Documents and Settings\All Users\Data aplikací\ICQ
2011-03-27 15:39:20 ----D---- D:\Documents and Settings\Jan\Data aplikací\ICQ
2011-03-27 15:35:31 ----D---- D:\Program Files\ICQ7.4
2011-03-27 13:01:48 ----A---- D:\WINDOWS\system32\drivers\aswSP.sys
2011-03-27 13:01:48 ----A---- D:\WINDOWS\system32\drivers\aswFsBlk.sys
2011-03-27 13:01:47 ----A---- D:\WINDOWS\system32\drivers\aswRdr.sys
2011-03-27 13:01:46 ----A---- D:\WINDOWS\system32\drivers\aswTdi.sys
2011-03-27 13:01:46 ----A---- D:\WINDOWS\system32\drivers\aswSnx.sys
2011-03-27 13:01:45 ----A---- D:\WINDOWS\system32\drivers\aswmon2.sys
2011-03-27 13:01:45 ----A---- D:\WINDOWS\system32\drivers\aswmon.sys
2011-03-27 13:01:44 ----A---- D:\WINDOWS\system32\drivers\aavmker4.sys
2011-03-27 13:01:34 ----A---- D:\WINDOWS\system32\aswBoot.exe
2011-03-27 13:01:30 ----D---- D:\Program Files\AVAST Software
2011-03-27 13:01:30 ----D---- D:\Documents and Settings\All Users\Data aplikací\AVAST Software
2011-03-27 12:22:55 ----D---- D:\WINDOWS\ERDNT
2011-03-27 12:17:12 ----D---- D:\Qoobox
2011-03-27 10:43:26 ----D---- D:\rsit
2011-03-27 10:43:26 ----D---- D:\Program Files\trend micro
2011-03-27 00:14:29 ----A---- D:\WINDOWS\ntbtlog.txt
2011-03-26 21:31:03 ----HD---- D:\WINDOWS\system32\GroupPolicy
2011-03-26 00:50:49 ----D---- D:\WINDOWS\system32\NtmsData
2011-03-26 00:26:00 ----D---- D:\WINDOWS\system32\xlive
2011-03-26 00:26:00 ----D---- D:\Program Files\Microsoft Games for Windows - LIVE
2011-03-25 20:40:06 ----D---- D:\Program Files\Free YouTube Downloader Converter
2011-03-24 23:32:26 ----D---- D:\Documents and Settings\All Users\Data aplikací\Electronic Arts
2011-03-24 22:21:11 ----D---- D:\Program Files\7-Zip
2011-03-24 21:28:19 ----A---- D:\WINDOWS\system32\XAudio2_6.dll
2011-03-24 21:28:19 ----A---- D:\WINDOWS\system32\XAPOFX1_4.dll
2011-03-24 21:28:18 ----A---- D:\WINDOWS\system32\xactengine3_6.dll
2011-03-24 21:28:17 ----A---- D:\WINDOWS\system32\X3DAudio1_7.dll
2011-03-24 21:28:16 ----A---- D:\WINDOWS\system32\XAudio2_5.dll
2011-03-24 21:28:15 ----A---- D:\WINDOWS\system32\xactengine3_5.dll
2011-03-24 21:28:14 ----A---- D:\WINDOWS\system32\D3DCompiler_42.dll
2011-03-24 21:28:13 ----A---- D:\WINDOWS\system32\d3dcsx_42.dll
2011-03-24 21:28:12 ----A---- D:\WINDOWS\system32\d3dx11_42.dll
2011-03-24 21:28:11 ----A---- D:\WINDOWS\system32\d3dx10_42.dll
2011-03-24 21:28:10 ----A---- D:\WINDOWS\system32\D3DX9_42.dll
2011-03-24 07:57:59 ----HDC---- D:\WINDOWS\$NtUninstallKB2524375$
2011-03-23 23:09:58 ----D---- D:\WINDOWS\system32\appmgmt
2011-03-23 17:55:37 ----A---- D:\WINDOWS\system32\mkl_vml_p4.dll
2011-03-23 17:55:36 ----A---- D:\WINDOWS\system32\mkl_vml_p3.dll
2011-03-23 17:55:36 ----A---- D:\WINDOWS\system32\mkl_vml_def.dll
2011-03-23 17:55:35 ----A---- D:\WINDOWS\system32\mkl_p4.dll
2011-03-23 17:55:34 ----A---- D:\WINDOWS\system32\mkl_p3.dll
2011-03-23 17:55:33 ----A---- D:\WINDOWS\system32\mkl_lapack64.dll
2011-03-23 17:55:31 ----A---- D:\WINDOWS\system32\mkl_lapack32.dll
2011-03-23 17:55:29 ----A---- D:\WINDOWS\system32\mkl_def.dll
2011-03-23 17:55:29 ----A---- D:\WINDOWS\system32\libguide40.dll
2011-03-23 17:55:28 ----A---- D:\WINDOWS\system32\rapture3d_oal.dll
2011-03-23 17:55:25 ----D---- D:\Program Files\BRS
2011-03-23 15:18:35 ----D---- D:\Program Files\Feneris
2011-03-23 12:59:07 ----D---- D:\Program Files\Micro DVD Player
2011-03-23 00:37:45 ----D---- D:\Program Files\Earth 3D Screensaver
2011-03-22 23:50:19 ----D---- D:\Program Files\3Planesoft Screensaver Manager
2011-03-22 23:50:19 ----D---- D:\Documents and Settings\All Users\Data aplikací\3Planesoft
2011-03-22 23:50:00 ----D---- D:\Program Files\The One Ring 3D Screensaver
2011-03-22 23:45:39 ----A---- D:\WINDOWS\LOTR_Orcs.exe
2011-03-22 23:42:14 ----A---- D:\WINDOWS\LOTR Dark Rider.exe
2011-03-22 23:40:11 ----A---- D:\WINDOWS\mickey32.dll
2011-03-22 23:40:11 ----A---- D:\WINDOWS\LOTR Eye of Sauron.exe
2011-03-22 19:08:00 ----D---- D:\Program Files\Microsoft Games
2011-03-22 15:49:37 ----HD---- D:\WINDOWS\PIF
2011-03-22 10:28:15 ----A---- D:\WINDOWS\Q3version.ini
2011-03-22 10:28:08 ----D---- D:\Program Files\Quake III Arena
2011-03-20 20:10:51 ----RA---- D:\WINDOWS\system32\drivers\senfilt.sys
2011-03-20 20:10:51 ----RA---- D:\WINDOWS\system32\drivers\aeaudio.sys
2011-03-20 20:10:50 ----RA---- D:\WINDOWS\system32\drivers\ADIHdAud.sys
2011-03-20 20:10:37 ----N---- D:\WINDOWS\system32\wdmioctl.dll
2011-03-20 20:10:36 ----N---- D:\WINDOWS\system32\SMMedia.dll
2011-03-20 20:10:32 ----N---- D:\WINDOWS\system32\DSndUp.exe
2011-03-20 20:10:32 ----D---- D:\Program Files\Analog Devices
2011-03-20 20:10:31 ----N---- D:\WINDOWS\system32\CleanUp.exe
2011-03-20 20:10:01 ----A---- D:\WINDOWS\Ascd_tmp.ini
2011-03-20 19:52:41 ----D---- D:\swsetup
2011-03-20 19:38:17 ----D---- D:\Documents and Settings\All Users\Data aplikací\PC Drivers HeadQuarters
2011-03-20 19:05:59 ----A---- D:\WINDOWS\AS_Debug.txt
2011-03-20 18:18:16 ----D---- D:\Documents and Settings\Jan\Data aplikací\InstallShield
2011-03-20 10:48:44 ----D---- D:\Program Files\Ubisoft
2011-03-20 09:35:41 ----A---- D:\WINDOWS\Qiii.INI
2011-03-20 09:30:39 ----A---- D:\WINDOWS\NeroDigital.ini
2011-03-20 08:54:46 ----D---- D:\Program Files\MSXML 4.0
2011-03-19 19:53:26 ----A---- D:\WINDOWS\system32\MsiExec.exe.log
2011-03-19 19:47:35 ----D---- D:\Documents and Settings\Jan\Data aplikací\U3
2011-03-19 19:08:43 ----D---- D:\Documents and Settings\Jan\Data aplikací\F-Secure
2011-03-16 20:28:21 ----D---- D:\Program Files\18 Wheels of Steel Haulin
2011-03-16 16:17:46 ----HDC---- D:\WINDOWS\$NtUninstallKB971029$
2011-03-13 14:52:44 ----A---- D:\WINDOWS\treeskp.sys
2011-03-12 14:16:01 ----A---- D:\WINDOWS\IE4 Error Log.txt

======List of files/folders modified in the last 1 months======

2011-04-09 09:09:12 ----D---- D:\WINDOWS\Prefetch
2011-04-09 08:50:33 ----D---- D:\Documents and Settings\Jan\Data aplikací\uTorrent
2011-04-09 08:46:44 ----RD---- D:\Program Files
2011-04-09 08:46:44 ----D---- D:\WINDOWS\system32
2011-04-08 23:49:42 ----A---- D:\WINDOWS\SchedLgU.Txt
2011-04-08 23:49:39 ----D---- D:\WINDOWS\system32\CatRoot2
2011-04-08 22:49:41 ----D---- D:\Program Files\rFactor
2011-04-08 18:29:02 ----SHD---- D:\WINDOWS\Installer
2011-04-08 18:06:18 ----HD---- D:\WINDOWS\inf
2011-04-08 18:06:18 ----HD---- D:\Program Files\InstallShield Installation Information
2011-04-08 18:06:14 ----DC---- D:\WINDOWS\system32\DRVSTORE
2011-04-08 18:05:33 ----D---- D:\WINDOWS
2011-04-08 14:24:35 ----D---- D:\Program Files\Winamp
2011-04-08 13:34:37 ----D---- D:\Program Files\Common Files
2011-04-07 17:35:35 ----D---- D:\WINDOWS\system32\config
2011-04-07 17:33:21 ----A---- D:\WINDOWS\win.ini
2011-04-07 17:33:21 ----A---- D:\WINDOWS\system.ini
2011-04-07 14:59:02 ----D---- D:\WINDOWS\system32\drivers
2011-04-06 13:24:46 ----SD---- D:\Documents and Settings\Jan\Data aplikací\Microsoft
2011-04-03 21:55:29 ----D---- D:\Program Files\Electronic Arts
2011-04-03 19:01:08 ----D---- D:\WINDOWS\system32\DirectX
2011-04-03 18:59:42 ----RSD---- D:\WINDOWS\assembly
2011-04-03 17:45:40 ----D---- D:\Program Files\Microsoft ActiveSync
2011-04-03 17:43:31 ----D---- D:\WINDOWS\Help
2011-04-03 14:07:00 ----D---- D:\WINDOWS\system32\drivers\etc
2011-04-03 13:58:49 ----D---- D:\WINDOWS\AppPatch
2011-04-03 11:28:36 ----SD---- D:\WINDOWS\Tasks
2011-04-03 11:27:34 ----D---- D:\Install
2011-04-03 11:22:49 ----D---- D:\WINDOWS\network diagnostic
2011-04-02 21:44:20 ----D---- D:\WINDOWS\system32\wbem
2011-04-02 21:44:12 ----D---- D:\WINDOWS\Registration
2011-04-01 20:13:05 ----A---- D:\WINDOWS\RTacDbg.txt
2011-04-01 12:57:34 ----D---- D:\WINDOWS\system32\ReinstallBackups
2011-04-01 12:57:21 ----RSHDC---- D:\WINDOWS\system32\dllcache
2011-03-31 13:47:45 ----D---- D:\Documents and Settings\Jan\Data aplikací\Adobe
2011-03-30 21:26:44 ----D---- D:\WINDOWS\system32\CatRoot
2011-03-27 20:41:26 ----SD---- D:\WINDOWS\Downloaded Program Files
2011-03-27 19:08:25 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2011-03-27 19:03:11 ----D---- D:\Program Files\F-Secure
2011-03-27 15:28:11 ----D---- D:\Program Files\QIP 2010
2011-03-27 13:01:41 ----D---- D:\WINDOWS\WinSxS
2011-03-26 01:13:41 ----D---- D:\Documents and Settings\All Users\Data aplikací\Codemasters
2011-03-26 00:36:09 ----A---- D:\WINDOWS\system32\wrap_oal.dll
2011-03-26 00:36:09 ----A---- D:\WINDOWS\system32\OpenAL32.dll
2011-03-26 00:26:00 ----SD---- D:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-03-25 23:51:17 ----D---- D:\Program Files\Codemasters
2011-03-24 12:55:25 ----D---- D:\Program Files\Mozilla Firefox
2011-03-24 12:50:29 ----D---- D:\WINDOWS\Minidump
2011-03-24 07:57:56 ----HD---- D:\WINDOWS\$hf_mig$
2011-03-23 23:11:29 ----D---- D:\Program Files\Nero
2011-03-23 23:09:29 ----D---- D:\Documents and Settings\All Users\Data aplikací\Nero
2011-03-22 19:18:08 ----RSD---- D:\WINDOWS\Fonts
2011-03-20 20:10:56 ----D---- D:\WINDOWS\system
2011-03-19 19:53:48 ----D---- D:\Documents and Settings\Jan\Data aplikací\Nero
2011-03-19 19:52:01 ----D---- D:\WINDOWS\Cursors
2011-03-16 16:17:55 ----A---- D:\WINDOWS\imsins.BAK
2011-03-13 15:22:13 ----D---- D:\Program Files\SpeedFan

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 giveio;giveio; D:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 JGOGO;JMicron Hot-Plug Driver; D:\WINDOWS\system32\DRIVERS\JGOGO.sys [2006-02-07 6912]
R0 JRAID;JRAID; D:\WINDOWS\system32\DRIVERS\jraid.sys [2007-03-24 46208]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI; D:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; D:\WINDOWS\System32\Drivers\PxHelp20.sys [2011-03-04 45648]
R0 speedfan;speedfan; D:\WINDOWS\system32\speedfan.sys [2006-09-24 5248]
R1 Aavmker4;avast! Asynchronous Virus Monitor; D:\WINDOWS\system32\drivers\Aavmker4.sys [2011-02-23 30680]
R1 AsIO;AsIO; D:\WINDOWS\system32\drivers\AsIO.sys [2009-08-04 11296]
R1 aswRdr;aswRdr; D:\WINDOWS\system32\drivers\aswRdr.sys [2011-02-23 25432]
R1 aswSnx;aswSnx; D:\WINDOWS\system32\drivers\aswSnx.sys [2011-02-23 371544]
R1 aswSP;aswSP; D:\WINDOWS\system32\drivers\aswSP.sys [2011-02-23 301528]
R1 aswTdi;avast! Network Shield Support; D:\WINDOWS\system32\drivers\aswTdi.sys [2011-02-23 49240]
R1 intelppm;Řadič procesoru Intel; D:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\D:\Program Files\UltraISO\drivers\ISODrive.sys []
R1 kbdhid;Ovladač klávesnice standardu HID; D:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 SCDEmu;SCDEmu; D:\WINDOWS\system32\drivers\SCDEmu.sys [2010-04-12 59388]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.5.0; D:\WINDOWS\system32\DRIVERS\AegisP.sys [2011-02-08 21035]
R2 aswFsBlk;aswFsBlk; D:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-02-23 19544]
R2 aswMon2;avast! Standard Shield Support; D:\WINDOWS\system32\drivers\aswMon2.sys [2011-02-23 102232]
R2 cpuz135;cpuz135; \??\D:\WINDOWS\system32\drivers\cpuz135_x32.sys []
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; D:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-01-16 293888]
R3 AEAudio;AE Audio Service; D:\WINDOWS\system32\drivers\AEAudio.sys [2006-08-07 93952]
R3 ALSysIO;ALSysIO; \??\D:\DOCUME~1\Jan\LOCALS~1\Temp\ALSysIO.sys []
R3 Arp1394;Protokol 1394 ARP Client; D:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; D:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-02-11 3565056]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; D:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; D:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; D:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter; D:\WINDOWS\system32\DRIVERS\RTL8187.sys [2006-06-16 176128]
R3 SenFiltService;SenFilt Service; D:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; D:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; D:\WINDOWS\system32\drivers\WmBEnum.sys [2005-04-12 10144]
R3 WmFilter;Logitech Gaming HID Filter Driver; D:\WINDOWS\system32\drivers\WmFilter.sys [2005-04-12 22240]
R3 WmHidLo;Logitech Gaming USB Filter Driver; D:\WINDOWS\system32\drivers\WmHidLo.sys [2005-04-12 17632]
R3 WmVirHid;Logitech Virtual Hid Device Driver; D:\WINDOWS\system32\drivers\WmVirHid.sys [2005-04-12 5600]
R3 WmXlCore;Logitech WingMan Translation Layer Driver; D:\WINDOWS\system32\drivers\WmXlCore.sys [2005-04-12 45504]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; D:\WINDOWS\system32\DRIVERS\yk51x86.sys [2007-08-15 265856]
S3 catchme;catchme; \??\D:\DOCUME~1\Jan\LOCALS~1\Temp\catchme.sys []
S3 usb_rndisx;Adaptér USB RNDIS; D:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; D:\WINDOWS\system32\Ati2evxx.exe [2010-02-11 602112]
R2 avast! Antivirus;avast! Antivirus; D:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-02-23 42184]
R2 ICQ Service;ICQ Service; D:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-06-21 246584]
R2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre6\bin\jqs.exe [2011-02-02 153376]
R2 MDM;Machine Debug Manager; D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 UMWdf;Windows User Mode Driver Framework; D:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S2 ATI Smart;ATI Smart; D:\WINDOWS\system32\ati2sgag.exe [2010-02-10 593920]
S3 aspnet_state;ASP.NET State Service; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; d:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; D:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 idsvc;Windows CardSpace; d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; D:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; D:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: prosim o preventivku

Napsal: 09 dub 2011 20:21
od Roli
Opět zdravím, tyhle zbytečnosti fixni v HJT :

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/sm
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - D:\Documents and Settings\Jan\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - D:\Documents and Settings\Jan\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - D:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')


HJT najdeš zde :

D:\Program Files\trend micro\Jan.exe

jak na to jsem ti již psal jinde.


Přes Start >> Ovládací panely >> Přidat nebo odebrat odinstaluj ICQ6Toolbar


Jinak nic špatného nevidím.

Re: prosim o preventivku

Napsal: 09 dub 2011 20:57
od 00Inferno00
Diky, log po fixnuti:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:56:22, on 9.4.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\AVAST Software\Avast\AvastSvc.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Analog Devices\Core\smax4pnp.exe
D:\Program Files\AVAST Software\Avast\avastUI.exe
D:\Program Files\Analog Devices\SoundMAX\Smax4.exe
D:\Program Files\Microsoft ActiveSync\Wcescomm.exe
D:\Program Files\Logitech\Profiler\lwemon.exe
D:\Documents and Settings\Jan\Plocha\O.C\Core Temp.exe
D:\PROGRA~1\MI3AA1~1\rapimgr.exe
D:\Documents and Settings\Jan\Plocha\SpeedFan\speedfan.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
D:\WINDOWS\system32\wbem\wmiapsrv.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\trend micro\hijackthis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - D:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [SoundMAXPnP] D:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [avast] "D:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SoundMax] "D:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [uTorrent] "D:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Start WingMan Profiler] "D:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Core Temp] D:\Documents and Settings\Jan\Plocha\O.C\Core Temp.exe
O4 - Startup: Zástupce - speedfan.lnk = D:\Documents and Settings\Jan\Plocha\SpeedFan\speedfan.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{4FE42FBC-A8C6-4C80-AF62-CF7D532108D9}: NameServer = 212.71.150.16,82.209.19.226
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - AVAST Software - D:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 6241 bytes

Re: prosim o preventivku

Napsal: 09 dub 2011 21:01
od Roli
Ještě tohle fixni :

R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - D:\Program Files\Winamp Toolbar\winamptb.dll


a je to z mé strany vše.

Re: prosim o preventivku

Napsal: 09 dub 2011 21:29
od 00Inferno00
Dalsi log po dalsim fixnuti

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:28:52, on 9.4.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\AVAST Software\Avast\AvastSvc.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Analog Devices\Core\smax4pnp.exe
D:\Program Files\AVAST Software\Avast\avastUI.exe
D:\Program Files\Analog Devices\SoundMAX\Smax4.exe
D:\Program Files\Microsoft ActiveSync\Wcescomm.exe
D:\Program Files\Logitech\Profiler\lwemon.exe
D:\Documents and Settings\Jan\Plocha\O.C\Core Temp.exe
D:\PROGRA~1\MI3AA1~1\rapimgr.exe
D:\Documents and Settings\Jan\Plocha\SpeedFan\speedfan.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
D:\WINDOWS\system32\wbem\wmiapsrv.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\trend micro\Jan.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [SoundMAXPnP] D:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [avast] "D:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SoundMax] "D:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [uTorrent] "D:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Start WingMan Profiler] "D:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Core Temp] D:\Documents and Settings\Jan\Plocha\O.C\Core Temp.exe
O4 - Startup: Zástupce - speedfan.lnk = D:\Documents and Settings\Jan\Plocha\SpeedFan\speedfan.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - D:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{4FE42FBC-A8C6-4C80-AF62-CF7D532108D9}: NameServer = 212.71.150.16,82.209.19.226
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - AVAST Software - D:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 6021 bytes

Re: prosim o preventivku

Napsal: 10 dub 2011 21:02
od Roli
Bezva, tak se mi to líbí :)