kontrola
Napsal: 24 dub 2011 20:51
Ahoj, avira mi hlasi trojana.Tak prosim o kontrolu...
Logfile of random's system information tool 1.08 (written by random/random)
Run by showlee at 2011-04-24 21:39:35
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 9 GB (25%) free of 38 GB
Total RAM: 1023 MB (60% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:40:36, on 24.4.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Sandboxie\SbieSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
C:\WINDOWS\system32\vmnat.exe
D:\Program Files\VmWare\vmware-authd.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\dllhost.exe
C:\Documents and Settings\UraBoy\Plocha\RSIT.exe
C:\Program Files\trend micro\showlee.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [vmware-tray] "D:\Program Files\VmWare\vmware-tray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-299502267-602609370-725345543-1009\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'UraBoy')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-21-299502267-602609370-725345543-1009 Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'UraBoy')
O4 - S-1-5-21-299502267-602609370-725345543-1009 User Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'UraBoy')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: d:\program files\vmware\vsocklib.dll
O10 - Unknown file in Winsock LSP: d:\program files\vmware\vsocklib.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 9958816562
O17 - HKLM\System\CCS\Services\Tcpip\..\{51E11F44-2033-4143-B486-A09DA6CC78AE}: NameServer = 213.226.248.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{51E11F44-2033-4143-B486-A09DA6CC78AE}: NameServer = 213.226.248.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{51E11F44-2033-4143-B486-A09DA6CC78AE}: NameServer = 213.226.248.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\System32\GameMon.des.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - D:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - D:\Program Files\VmWare\vmware-ufad.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - D:\Program Files\VmWare\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 5987 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2010-06-17 61888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-04 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-11-13 281768]
"ZoneAlarm Client"=D:\Program Files\ZoneAlarm\zlclient.exe [2010-07-20 1038848]
"vmware-tray"=D:\Program Files\VmWare\vmware-tray.exe [2009-10-22 129584]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
D:\Program Files\Sandboxie\SbieCtrl.exe [2011-03-24 409320]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SCDEmuApp.exe]
D:\Program Files\PowerISO\SCDEmuApp.exe [2005-10-16 167936]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2011-01-26 15026056]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmware-tray]
D:\Program Files\Nová složka\vmware-tray.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^showlee^Nabídka Start^Programy^Po spuštění^_uninst_setup_9.0.0.722_07.10.2010_12-34.exe.lnk]
C:\Documents and Settings\showlee\Local Settings\temp\_uninst_setup_9.0.0.722_07.10.2010_12-34.exe.bat []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^showlee^Nabídka Start^Programy^Po spuštění^_uninst_setup_9.0.0.722_30.09.2010_20-30.exe.lnk]
C:\Documents and Settings\showlee\Local Settings\temp\_uninst_setup_9.0.0.722_30.09.2010_20-30.exe.bat []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-08-30 86016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-02-12 190976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe"="C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"D:\Program Files\VmWare\vmware-authd.exe"="D:\Program Files\VmWare\vmware-authd.exe:*:Enabled:VMware Authd"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2011-04-24 21:39:39 ----D---- C:\Program Files\trend micro
2011-04-24 21:39:35 ----D---- C:\rsit
2011-04-23 10:53:53 ----RA---- C:\WINDOWS\system32\vnetinst.dll
2011-04-23 10:53:53 ----RA---- C:\WINDOWS\system32\drivers\vmnetadapter.sys
2011-04-23 10:53:46 ----A---- C:\WINDOWS\system32\vmnetdhcp.exe
2011-04-23 10:53:42 ----A---- C:\WINDOWS\system32\vmnat.exe
2011-04-23 10:53:41 ----A---- C:\WINDOWS\system32\drivers\vmnetuserif.sys
2011-04-23 10:53:31 ----RA---- C:\WINDOWS\system32\drivers\vmnet.sys
2011-04-23 10:53:16 ----A---- C:\WINDOWS\system32\vnetlib.dll
2011-04-23 10:52:47 ----A---- C:\WINDOWS\system32\drivers\VMkbd.sys
2011-04-23 10:51:47 ----D---- C:\Program Files\Common Files\VMware
2011-04-23 10:49:49 ----D---- C:\Program Files\VMware
2011-04-23 09:14:10 ----D---- C:\Documents and Settings\showlee\Data aplikací\VMware
2011-04-23 08:50:33 ----D---- C:\Users
2011-04-22 11:11:16 ----A---- C:\WINDOWS\system32\muweb.dll
2011-04-22 11:11:16 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2011-04-22 11:11:16 ----A---- C:\WINDOWS\system32\mucltui.dll
2011-04-22 10:37:38 ----D---- C:\Program Files\Microsoft Works
2011-04-22 10:37:05 ----D---- C:\Program Files\Microsoft Visual Studio
2011-04-22 10:37:04 ----D---- C:\Program Files\Common Files\DESIGNER
2011-04-22 10:33:25 ----D---- C:\WINDOWS\SHELLNEW
2011-04-22 07:36:37 ----D---- C:\Documents and Settings\showlee\Data aplikací\CadSoft
2011-04-15 01:28:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2011-04-15 01:28:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2510581$
2011-04-15 01:27:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2506223$
2011-04-15 01:27:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2412687$
2011-04-15 01:22:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2508272$
2011-04-15 01:22:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2503658$
2011-04-15 01:22:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2507618$
2011-04-15 01:22:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2497640$
2011-04-15 01:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2011-04-15 01:21:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2511455$
2011-04-15 01:21:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2011-04-15 01:18:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2011-04-12 21:45:37 ----D---- C:\Program Files\MySQL
2011-04-12 21:45:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\MySQL
2011-04-10 11:21:56 ----D---- C:\Documents and Settings\showlee\Data aplikací\gnupg
2011-04-10 11:21:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\GNU
2011-04-07 04:21:38 ----D---- C:\Program Files\GNU
2011-04-05 20:58:06 ----D---- C:\Program Files\WinPcap
2011-04-02 11:16:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\VMware
2011-04-02 11:08:24 ----RD---- C:\Sandbox
2011-04-02 11:06:44 ----A---- C:\WINDOWS\Sandboxie.ini
2011-04-01 21:44:40 ----D---- C:\Mozilla
2011-03-27 19:05:49 ----HDC---- C:\WINDOWS\$NtUninstallKB2524375$
======List of files/folders modified in the last 1 months======
2011-04-24 21:40:29 ----D---- C:\WINDOWS\Prefetch
2011-04-24 21:40:28 ----D---- C:\WINDOWS\Internet Logs
2011-04-24 21:39:39 ----RD---- C:\Program Files
2011-04-24 21:32:52 ----D---- C:\WINDOWS\system32\NtmsData
2011-04-24 20:59:28 ----D---- C:\WINDOWS\Registration
2011-04-24 18:24:22 ----D---- C:\WINDOWS\temp
2011-04-24 07:46:48 ----D---- C:\WINDOWS\system32\CatRoot2
2011-04-24 07:46:31 ----D---- C:\Program Files\Microsoft Silverlight
2011-04-24 00:05:17 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-04-24 00:04:41 ----SHD---- C:\WINDOWS\Installer
2011-04-23 11:01:34 ----D---- C:\WINDOWS
2011-04-23 10:54:10 ----D---- C:\WINDOWS\system32\drivers
2011-04-23 10:54:10 ----D---- C:\WINDOWS\system32
2011-04-23 10:53:52 ----HD---- C:\WINDOWS\inf
2011-04-23 10:52:25 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-04-23 10:51:47 ----D---- C:\Program Files\Common Files
2011-04-23 10:12:46 ----RASH---- C:\boot.ini
2011-04-23 10:12:46 ----A---- C:\WINDOWS\win.ini
2011-04-23 10:12:46 ----A---- C:\WINDOWS\system.ini
2011-04-23 09:53:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2011-04-23 09:51:45 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-04-23 09:50:01 ----RSD---- C:\WINDOWS\assembly
2011-04-23 09:48:35 ----RSD---- C:\WINDOWS\Fonts
2011-04-23 09:48:25 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-04-22 11:10:53 ----SD---- C:\Documents and Settings\showlee\Data aplikací\Microsoft
2011-04-22 10:00:19 ----D---- C:\WINDOWS\system32\config
2011-04-22 09:58:47 ----D---- C:\WINDOWS\WinSxS
2011-04-22 07:45:16 ----D---- C:\Program Files\OpenOffice.org 3
2011-04-19 09:33:06 ----D---- C:\Documents and Settings\showlee\Data aplikací\Adobe
2011-04-19 08:42:27 ----SHD---- C:\System Volume Information
2011-04-19 08:42:27 ----D---- C:\WINDOWS\system32\Restore
2011-04-15 14:26:50 ----D---- C:\WINDOWS\Microsoft.NET
2011-04-15 01:28:33 ----A---- C:\WINDOWS\imsins.BAK
2011-04-15 01:28:21 ----HD---- C:\WINDOWS\$hf_mig$
2011-04-15 01:28:15 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-04-15 01:18:43 ----A---- C:\WINDOWS\system32\MRT.exe
2011-04-12 22:34:47 ----D---- C:\Documents and Settings\showlee\Data aplikací\Skype
2011-04-12 22:23:14 ----D---- C:\Documents and Settings\showlee\Data aplikací\skypePM
2011-04-06 11:33:35 ----RD---- C:\Program Files\Skype
2011-04-05 19:53:24 ----D---- C:\WINDOWS\security
2011-04-05 19:41:10 ----D---- C:\WINDOWS\pss
2011-04-05 19:34:49 ----D---- C:\WINDOWS\system32\appmgmt
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\System32\DRIVERS\agp440.sys [2008-04-13 42368]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2011-03-18 137656]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2005-10-16 27171]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 UserPort;UserPort; C:\WINDOWS\System32\Drivers\UserPort.sys [2000-11-28 4256]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2010-06-09 528128]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-11-25 61960]
R2 hcmon;VMware hcmon; \??\C:\WINDOWS\system32\drivers\hcmon.sys []
R2 vmci;VMware vmci; \??\C:\WINDOWS\system32\Drivers\vmci.sys []
R2 VMnetBridge;VMware Bridge Protocol; C:\WINDOWS\system32\DRIVERS\vmnetbridge.sys [2009-10-22 32688]
R2 VMnetuserif;VMware Network Application Interface; \??\C:\WINDOWS\system32\drivers\vmnetuserif.sys []
R2 VMparport;VMware VMparport; \??\C:\WINDOWS\system32\Drivers\VMparport.sys []
R2 vmx86;VMware vmx86; \??\C:\WINDOWS\system32\Drivers\vmx86.sys []
R2 vstor2-ws60;Vstor2 WS60 Virtual Storage Driver; \??\D:\Program Files\VmWare\vstor2-ws60.sys []
R3 ALCXWDM;Service for Avance AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2002-09-05 667543]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2006-08-30 1723904]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
R3 rtl8139;Realtek RTL8139/810X Family PCI Fast Ethernet NIC NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2001-08-23 25434]
R3 SbieDrv;SbieDrv; \??\D:\Program Files\Sandboxie\SbieDrv.sys []
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 vmkbd;VMware kbd; \??\C:\WINDOWS\system32\drivers\VMkbd.sys []
R3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\vmnetadapter.sys [2009-10-22 16560]
R3 WinDriver6;WinDriver6; C:\WINDOWS\system32\drivers\windrvr6.sys [2009-09-02 195424]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 DLPortIO;DriverLINX Port I/O Driver; \??\C:\WINDOWS\System32\DRIVERS\DLPortIO.SYS []
S3 FTDIBUS;USB Serial Converter Driver; C:\WINDOWS\system32\drivers\ftdibus.sys [2009-10-22 57800]
S3 FTSER2K;USB Serial Port Driver; C:\WINDOWS\system32\drivers\ftser2k.sys [2009-10-22 72520]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2011-02-11 35088]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 RsFx0102;RsFx0102 Driver; C:\WINDOWS\system32\DRIVERS\RsFx0102.sys [2008-07-10 242712]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2011-03-18 269480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-11-13 135336]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\System32\Ati2evxx.exe [2006-08-30 413696]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-07-17 153376]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2008-07-11 40999448]
R2 SbieSvc;Sandboxie Service; D:\Program Files\Sandboxie\SbieSvc.exe [2011-03-24 72936]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 98840]
R2 VMAuthdService;VMware Authorization Service; D:\Program Files\VmWare\vmware-authd.exe [2009-10-22 113200]
R2 VMnetDHCP;VMware DHCP Service; C:\WINDOWS\system32\vmnetdhcp.exe [2009-10-22 334384]
R2 VMUSBArbService;VMware USB Arbitration Service; C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe [2009-10-22 563760]
R2 VMware NAT Service;VMware NAT Service; C:\WINDOWS\system32\vmnat.exe [2009-10-22 395824]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2010-07-20 2434568]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2006-08-29 520192]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 npggsvc;nProtect GameGuard Service; C:\WINDOWS\System32\GameMon.des [2009-10-11 3369044]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ufad-ws60;VMware Agent Service; D:\Program Files\VmWare\vmware-ufad.exe [2009-10-12 191024]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-11 47128]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-11 369688]
S4 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-07-10 258072]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by showlee at 2011-04-24 21:39:35
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 9 GB (25%) free of 38 GB
Total RAM: 1023 MB (60% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:40:36, on 24.4.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Sandboxie\SbieSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
C:\WINDOWS\system32\vmnat.exe
D:\Program Files\VmWare\vmware-authd.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\dllhost.exe
C:\Documents and Settings\UraBoy\Plocha\RSIT.exe
C:\Program Files\trend micro\showlee.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [vmware-tray] "D:\Program Files\VmWare\vmware-tray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-299502267-602609370-725345543-1009\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'UraBoy')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-21-299502267-602609370-725345543-1009 Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'UraBoy')
O4 - S-1-5-21-299502267-602609370-725345543-1009 User Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'UraBoy')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: d:\program files\vmware\vsocklib.dll
O10 - Unknown file in Winsock LSP: d:\program files\vmware\vsocklib.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 9958816562
O17 - HKLM\System\CCS\Services\Tcpip\..\{51E11F44-2033-4143-B486-A09DA6CC78AE}: NameServer = 213.226.248.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{51E11F44-2033-4143-B486-A09DA6CC78AE}: NameServer = 213.226.248.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{51E11F44-2033-4143-B486-A09DA6CC78AE}: NameServer = 213.226.248.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\System32\GameMon.des.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - D:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - D:\Program Files\VmWare\vmware-ufad.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - D:\Program Files\VmWare\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 5987 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2010-06-17 61888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-04 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-11-13 281768]
"ZoneAlarm Client"=D:\Program Files\ZoneAlarm\zlclient.exe [2010-07-20 1038848]
"vmware-tray"=D:\Program Files\VmWare\vmware-tray.exe [2009-10-22 129584]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
D:\Program Files\Sandboxie\SbieCtrl.exe [2011-03-24 409320]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SCDEmuApp.exe]
D:\Program Files\PowerISO\SCDEmuApp.exe [2005-10-16 167936]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2011-01-26 15026056]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmware-tray]
D:\Program Files\Nová složka\vmware-tray.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^showlee^Nabídka Start^Programy^Po spuštění^_uninst_setup_9.0.0.722_07.10.2010_12-34.exe.lnk]
C:\Documents and Settings\showlee\Local Settings\temp\_uninst_setup_9.0.0.722_07.10.2010_12-34.exe.bat []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^showlee^Nabídka Start^Programy^Po spuštění^_uninst_setup_9.0.0.722_30.09.2010_20-30.exe.lnk]
C:\Documents and Settings\showlee\Local Settings\temp\_uninst_setup_9.0.0.722_30.09.2010_20-30.exe.bat []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-08-30 86016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-02-12 190976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe"="C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"D:\Program Files\VmWare\vmware-authd.exe"="D:\Program Files\VmWare\vmware-authd.exe:*:Enabled:VMware Authd"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2011-04-24 21:39:39 ----D---- C:\Program Files\trend micro
2011-04-24 21:39:35 ----D---- C:\rsit
2011-04-23 10:53:53 ----RA---- C:\WINDOWS\system32\vnetinst.dll
2011-04-23 10:53:53 ----RA---- C:\WINDOWS\system32\drivers\vmnetadapter.sys
2011-04-23 10:53:46 ----A---- C:\WINDOWS\system32\vmnetdhcp.exe
2011-04-23 10:53:42 ----A---- C:\WINDOWS\system32\vmnat.exe
2011-04-23 10:53:41 ----A---- C:\WINDOWS\system32\drivers\vmnetuserif.sys
2011-04-23 10:53:31 ----RA---- C:\WINDOWS\system32\drivers\vmnet.sys
2011-04-23 10:53:16 ----A---- C:\WINDOWS\system32\vnetlib.dll
2011-04-23 10:52:47 ----A---- C:\WINDOWS\system32\drivers\VMkbd.sys
2011-04-23 10:51:47 ----D---- C:\Program Files\Common Files\VMware
2011-04-23 10:49:49 ----D---- C:\Program Files\VMware
2011-04-23 09:14:10 ----D---- C:\Documents and Settings\showlee\Data aplikací\VMware
2011-04-23 08:50:33 ----D---- C:\Users
2011-04-22 11:11:16 ----A---- C:\WINDOWS\system32\muweb.dll
2011-04-22 11:11:16 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2011-04-22 11:11:16 ----A---- C:\WINDOWS\system32\mucltui.dll
2011-04-22 10:37:38 ----D---- C:\Program Files\Microsoft Works
2011-04-22 10:37:05 ----D---- C:\Program Files\Microsoft Visual Studio
2011-04-22 10:37:04 ----D---- C:\Program Files\Common Files\DESIGNER
2011-04-22 10:33:25 ----D---- C:\WINDOWS\SHELLNEW
2011-04-22 07:36:37 ----D---- C:\Documents and Settings\showlee\Data aplikací\CadSoft
2011-04-15 01:28:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2011-04-15 01:28:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2510581$
2011-04-15 01:27:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2506223$
2011-04-15 01:27:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2412687$
2011-04-15 01:22:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2508272$
2011-04-15 01:22:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2503658$
2011-04-15 01:22:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2507618$
2011-04-15 01:22:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2497640$
2011-04-15 01:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2011-04-15 01:21:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2511455$
2011-04-15 01:21:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2011-04-15 01:18:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2011-04-12 21:45:37 ----D---- C:\Program Files\MySQL
2011-04-12 21:45:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\MySQL
2011-04-10 11:21:56 ----D---- C:\Documents and Settings\showlee\Data aplikací\gnupg
2011-04-10 11:21:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\GNU
2011-04-07 04:21:38 ----D---- C:\Program Files\GNU
2011-04-05 20:58:06 ----D---- C:\Program Files\WinPcap
2011-04-02 11:16:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\VMware
2011-04-02 11:08:24 ----RD---- C:\Sandbox
2011-04-02 11:06:44 ----A---- C:\WINDOWS\Sandboxie.ini
2011-04-01 21:44:40 ----D---- C:\Mozilla
2011-03-27 19:05:49 ----HDC---- C:\WINDOWS\$NtUninstallKB2524375$
======List of files/folders modified in the last 1 months======
2011-04-24 21:40:29 ----D---- C:\WINDOWS\Prefetch
2011-04-24 21:40:28 ----D---- C:\WINDOWS\Internet Logs
2011-04-24 21:39:39 ----RD---- C:\Program Files
2011-04-24 21:32:52 ----D---- C:\WINDOWS\system32\NtmsData
2011-04-24 20:59:28 ----D---- C:\WINDOWS\Registration
2011-04-24 18:24:22 ----D---- C:\WINDOWS\temp
2011-04-24 07:46:48 ----D---- C:\WINDOWS\system32\CatRoot2
2011-04-24 07:46:31 ----D---- C:\Program Files\Microsoft Silverlight
2011-04-24 00:05:17 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-04-24 00:04:41 ----SHD---- C:\WINDOWS\Installer
2011-04-23 11:01:34 ----D---- C:\WINDOWS
2011-04-23 10:54:10 ----D---- C:\WINDOWS\system32\drivers
2011-04-23 10:54:10 ----D---- C:\WINDOWS\system32
2011-04-23 10:53:52 ----HD---- C:\WINDOWS\inf
2011-04-23 10:52:25 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-04-23 10:51:47 ----D---- C:\Program Files\Common Files
2011-04-23 10:12:46 ----RASH---- C:\boot.ini
2011-04-23 10:12:46 ----A---- C:\WINDOWS\win.ini
2011-04-23 10:12:46 ----A---- C:\WINDOWS\system.ini
2011-04-23 09:53:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2011-04-23 09:51:45 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-04-23 09:50:01 ----RSD---- C:\WINDOWS\assembly
2011-04-23 09:48:35 ----RSD---- C:\WINDOWS\Fonts
2011-04-23 09:48:25 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-04-22 11:10:53 ----SD---- C:\Documents and Settings\showlee\Data aplikací\Microsoft
2011-04-22 10:00:19 ----D---- C:\WINDOWS\system32\config
2011-04-22 09:58:47 ----D---- C:\WINDOWS\WinSxS
2011-04-22 07:45:16 ----D---- C:\Program Files\OpenOffice.org 3
2011-04-19 09:33:06 ----D---- C:\Documents and Settings\showlee\Data aplikací\Adobe
2011-04-19 08:42:27 ----SHD---- C:\System Volume Information
2011-04-19 08:42:27 ----D---- C:\WINDOWS\system32\Restore
2011-04-15 14:26:50 ----D---- C:\WINDOWS\Microsoft.NET
2011-04-15 01:28:33 ----A---- C:\WINDOWS\imsins.BAK
2011-04-15 01:28:21 ----HD---- C:\WINDOWS\$hf_mig$
2011-04-15 01:28:15 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-04-15 01:18:43 ----A---- C:\WINDOWS\system32\MRT.exe
2011-04-12 22:34:47 ----D---- C:\Documents and Settings\showlee\Data aplikací\Skype
2011-04-12 22:23:14 ----D---- C:\Documents and Settings\showlee\Data aplikací\skypePM
2011-04-06 11:33:35 ----RD---- C:\Program Files\Skype
2011-04-05 19:53:24 ----D---- C:\WINDOWS\security
2011-04-05 19:41:10 ----D---- C:\WINDOWS\pss
2011-04-05 19:34:49 ----D---- C:\WINDOWS\system32\appmgmt
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\System32\DRIVERS\agp440.sys [2008-04-13 42368]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2011-03-18 137656]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2005-10-16 27171]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 UserPort;UserPort; C:\WINDOWS\System32\Drivers\UserPort.sys [2000-11-28 4256]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2010-06-09 528128]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-11-25 61960]
R2 hcmon;VMware hcmon; \??\C:\WINDOWS\system32\drivers\hcmon.sys []
R2 vmci;VMware vmci; \??\C:\WINDOWS\system32\Drivers\vmci.sys []
R2 VMnetBridge;VMware Bridge Protocol; C:\WINDOWS\system32\DRIVERS\vmnetbridge.sys [2009-10-22 32688]
R2 VMnetuserif;VMware Network Application Interface; \??\C:\WINDOWS\system32\drivers\vmnetuserif.sys []
R2 VMparport;VMware VMparport; \??\C:\WINDOWS\system32\Drivers\VMparport.sys []
R2 vmx86;VMware vmx86; \??\C:\WINDOWS\system32\Drivers\vmx86.sys []
R2 vstor2-ws60;Vstor2 WS60 Virtual Storage Driver; \??\D:\Program Files\VmWare\vstor2-ws60.sys []
R3 ALCXWDM;Service for Avance AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2002-09-05 667543]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2006-08-30 1723904]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
R3 rtl8139;Realtek RTL8139/810X Family PCI Fast Ethernet NIC NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2001-08-23 25434]
R3 SbieDrv;SbieDrv; \??\D:\Program Files\Sandboxie\SbieDrv.sys []
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 vmkbd;VMware kbd; \??\C:\WINDOWS\system32\drivers\VMkbd.sys []
R3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\vmnetadapter.sys [2009-10-22 16560]
R3 WinDriver6;WinDriver6; C:\WINDOWS\system32\drivers\windrvr6.sys [2009-09-02 195424]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 DLPortIO;DriverLINX Port I/O Driver; \??\C:\WINDOWS\System32\DRIVERS\DLPortIO.SYS []
S3 FTDIBUS;USB Serial Converter Driver; C:\WINDOWS\system32\drivers\ftdibus.sys [2009-10-22 57800]
S3 FTSER2K;USB Serial Port Driver; C:\WINDOWS\system32\drivers\ftser2k.sys [2009-10-22 72520]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2011-02-11 35088]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 RsFx0102;RsFx0102 Driver; C:\WINDOWS\system32\DRIVERS\RsFx0102.sys [2008-07-10 242712]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2011-03-18 269480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-11-13 135336]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\System32\Ati2evxx.exe [2006-08-30 413696]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-07-17 153376]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2008-07-11 40999448]
R2 SbieSvc;Sandboxie Service; D:\Program Files\Sandboxie\SbieSvc.exe [2011-03-24 72936]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 98840]
R2 VMAuthdService;VMware Authorization Service; D:\Program Files\VmWare\vmware-authd.exe [2009-10-22 113200]
R2 VMnetDHCP;VMware DHCP Service; C:\WINDOWS\system32\vmnetdhcp.exe [2009-10-22 334384]
R2 VMUSBArbService;VMware USB Arbitration Service; C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe [2009-10-22 563760]
R2 VMware NAT Service;VMware NAT Service; C:\WINDOWS\system32\vmnat.exe [2009-10-22 395824]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2010-07-20 2434568]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2006-08-29 520192]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 npggsvc;nProtect GameGuard Service; C:\WINDOWS\System32\GameMon.des [2009-10-11 3369044]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ufad-ws60;VMware Agent Service; D:\Program Files\VmWare\vmware-ufad.exe [2009-10-12 191024]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-11 47128]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-11 369688]
S4 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-07-10 258072]
-----------------EOF-----------------