Stránka 1 z 1

Kontrola logu

Napsal: 24 říj 2011 18:27
od zipicek
prosim o kontrolu logu
Logfile of random's system information tool 1.09 (written by random/random)
Run by Thomas at 2011-10-24 19:16:55
Systém Microsoft Windows XP Professional
System drive C: has 127 GB (97%) free of 131 GB
Total RAM: 3327 MB (90% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:17:00, on 24.10.2011
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Thomas\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\Thomas.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe

--
End of file - 2042 bytes

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Thomas\Data aplikací\Mozilla\Firefox\Profiles\cc9n5gay.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E718888-423F-11D2-876E-00A0C9082467} - &Rádio - C:\WINDOWS\System32\msdxm.ocx [2001-10-25 846364]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-09-06 3722416]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\System32\ctfmon.exe [2001-10-25 13312]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2001-08-02 1077277]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\System32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\System32\l3codeca.acm

======List of files/folders created in the last 1 month======

2011-10-24 19:16:55 ----D---- C:\rsit
2011-10-24 19:16:55 ----D---- C:\Program Files\trend micro
2011-10-24 18:57:47 ----ASH---- C:\pagefile.sys
2011-10-24 17:42:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\ParetoLogic
2011-10-24 16:40:20 ----A---- C:\WINDOWS\System32\drivers\usbprint.sys
2011-10-24 16:10:00 ----SHD---- C:\WINDOWS\CSC
2011-10-24 16:09:56 ----A---- C:\WINDOWS\ntbtlog.txt
2011-10-24 15:24:26 ----A---- C:\WINDOWS\System32\drivers\aswSP.sys
2011-10-24 15:24:25 ----A---- C:\WINDOWS\System32\drivers\aswTdi.sys
2011-10-24 15:24:25 ----A---- C:\WINDOWS\System32\drivers\aswRdr.sys
2011-10-24 15:24:25 ----A---- C:\WINDOWS\System32\drivers\aswmon2.sys
2011-10-24 15:24:25 ----A---- C:\WINDOWS\System32\drivers\aswmon.sys
2011-10-24 15:24:24 ----A---- C:\WINDOWS\System32\drivers\aavmker4.sys
2011-10-24 15:24:13 ----A---- C:\WINDOWS\System32\aswBoot.exe
2011-10-24 15:24:13 ----A---- C:\WINDOWS\avastSS.scr
2011-10-24 15:23:58 ----SHD---- C:\RECYCLER
2011-10-24 15:20:31 ----D---- C:\Program Files\CCleaner
2011-10-24 15:19:26 ----D---- C:\Documents and Settings\Thomas\Data aplikací\Mozilla
2011-10-24 15:19:19 ----D---- C:\Program Files\Mozilla Firefox
2011-10-24 15:12:05 ----RA---- C:\WINDOWS\System32\RtNicProp32.dll
2011-10-24 15:12:05 ----RA---- C:\WINDOWS\System32\drivers\Rtenicxp.sys
2011-10-24 15:12:05 ----D---- C:\WINDOWS\LastGood
2011-10-23 19:32:38 ----A---- C:\WINDOWS\System32\h323log.txt
2011-10-23 19:28:50 ----A---- C:\WINDOWS\System32\drivers\audstub.sys
2011-10-23 19:28:38 ----A---- C:\WINDOWS\System32\hidserv.dll
2011-10-23 19:28:23 ----A---- C:\WINDOWS\System32\drivers\redbook.sys
2011-10-23 19:27:38 ----A---- C:\WINDOWS\System32\usbui.dll
2011-10-23 19:27:32 ----A---- C:\WINDOWS\System32\drivers\wmiacpi.sys
2011-10-23 19:26:57 ----D---- C:\Program Files\Common Files\ODBC
2011-10-23 19:26:57 ----A---- C:\WINDOWS\System32\PerfStringBackup.INI
2011-10-23 19:26:57 ----A---- C:\WINDOWS\ODBCINST.INI
2011-10-23 19:26:54 ----D---- C:\Program Files\Common Files\SpeechEngines
2011-10-23 19:26:53 ----RD---- C:\Program Files
2011-10-23 19:26:53 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-10-23 19:26:53 ----D---- C:\Program Files\Common Files
2011-10-23 19:26:51 ----RA---- C:\WINDOWS\System32\kbdtuq.dll
2011-10-23 19:26:51 ----RA---- C:\WINDOWS\System32\kbdtuf.dll
2011-10-23 19:26:51 ----RA---- C:\WINDOWS\System32\kbdazel.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdycc.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbduzb.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdur.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdtat.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdru1.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdru.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdmon.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdkyr.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdkaz.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdbu.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdblr.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdaze.dll
2011-10-23 19:26:47 ----RA---- C:\WINDOWS\System32\kbdhept.dll
2011-10-23 19:26:47 ----RA---- C:\WINDOWS\System32\kbdhela3.dll
2011-10-23 19:26:47 ----RA---- C:\WINDOWS\System32\kbdhela2.dll
2011-10-23 19:26:47 ----RA---- C:\WINDOWS\System32\kbdhe319.dll
2011-10-23 19:26:47 ----RA---- C:\WINDOWS\System32\kbdhe220.dll
2011-10-23 19:26:47 ----RA---- C:\WINDOWS\System32\kbdhe.dll
2011-10-23 19:26:47 ----RA---- C:\WINDOWS\System32\kbdgkl.dll
2011-10-23 19:26:46 ----RA---- C:\WINDOWS\System32\kbdlv1.dll
2011-10-23 19:26:46 ----RA---- C:\WINDOWS\System32\kbdlv.dll
2011-10-23 19:26:46 ----RA---- C:\WINDOWS\System32\kbdlt1.dll
2011-10-23 19:26:46 ----RA---- C:\WINDOWS\System32\kbdlt.dll
2011-10-23 19:26:45 ----RA---- C:\WINDOWS\System32\kbdest.dll
2011-10-23 19:26:43 ----A---- C:\WINDOWS\System32\kbdsl1.dll
2011-10-23 19:26:43 ----A---- C:\WINDOWS\System32\kbdsl.dll
2011-10-23 19:26:43 ----A---- C:\WINDOWS\System32\kbdro.dll
2011-10-23 19:26:43 ----A---- C:\WINDOWS\System32\kbdpl1.dll
2011-10-23 19:26:43 ----A---- C:\WINDOWS\System32\kbdpl.dll
2011-10-23 19:26:43 ----A---- C:\WINDOWS\System32\kbdhu1.dll
2011-10-23 19:26:43 ----A---- C:\WINDOWS\System32\kbdhu.dll
2011-10-23 19:26:42 ----A---- C:\WINDOWS\System32\kbdycl.dll
2011-10-23 19:26:42 ----A---- C:\WINDOWS\System32\kbdcr.dll
2011-10-23 19:26:42 ----A---- C:\WINDOWS\System32\KBDAL.DLL
2011-10-23 19:26:41 ----A---- C:\WINDOWS\System32\spxcoins.dll
2011-10-23 19:26:41 ----A---- C:\WINDOWS\System32\irclass.dll
2011-10-23 19:26:41 ----A---- C:\WINDOWS\System32\EqnClass.Dll
2011-10-23 19:26:41 ----A---- C:\WINDOWS\System32\drivers\irenum.sys
2011-10-23 19:26:41 ----A---- C:\WINDOWS\System32\dgsetup.dll
2011-10-23 19:26:41 ----A---- C:\WINDOWS\System32\dgrpsetu.dll
2011-10-23 19:26:41 ----A---- C:\WINDOWS\System32\batt.dll
2011-10-23 19:26:38 ----N---- C:\WINDOWS\System32\CONFIG.TMP
2011-10-23 19:26:38 ----A---- C:\WINDOWS\TASKMAN.EXE
2011-10-23 19:26:38 ----A---- C:\WINDOWS\System32\storprop.dll
2011-10-23 19:26:38 ----A---- C:\WINDOWS\NOTEPAD.EXE
2011-10-23 19:26:32 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\desktop.ini
2011-10-23 19:26:31 ----RA---- C:\WINDOWS\SET7.tmp
2011-10-23 19:26:29 ----RA---- C:\WINDOWS\SET3.tmp
2011-10-23 19:26:25 ----D---- C:\WINDOWS\System32\CatRoot2
2011-10-23 19:26:25 ----D---- C:\WINDOWS\System32\CatRoot
2011-10-23 19:26:19 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-10-23 19:26:07 ----D---- C:\Documents and Settings
2011-10-23 19:26:07 ----A---- C:\WINDOWS\System32\FNTCACHE.DAT
2011-10-23 19:25:24 ----SH---- C:\boot.ini
2011-10-23 19:21:30 ----RSHDC---- C:\WINDOWS\System32\dllcache
2011-10-23 19:21:30 ----RSD---- C:\WINDOWS\Fonts
2011-10-23 19:21:30 ----RD---- C:\WINDOWS\Web
2011-10-23 19:21:30 ----HD---- C:\WINDOWS\inf
2011-10-23 19:21:30 ----D---- C:\WINDOWS\WinSxS
2011-10-23 19:21:30 ----D---- C:\WINDOWS\twain_32
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Temp
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\wins
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\wbem
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\usmt
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\spool
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\ShellExt
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\Setup
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\ras
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\oobe
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\npp
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\mui
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\inetsrv
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\IME
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\icsxml
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\ias
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\export
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\drivers\etc
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\drivers\disdn
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\drivers
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\dhcp
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\config
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\3com_dmi
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\3076
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\2052
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1054
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1042
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1041
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1037
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1033
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1031
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1029
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1028
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1025
2011-10-23 19:21:30 ----D---- C:\WINDOWS\system32
2011-10-23 19:21:30 ----D---- C:\WINDOWS\system
2011-10-23 19:21:30 ----D---- C:\WINDOWS\security
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Resources
2011-10-23 19:21:30 ----D---- C:\WINDOWS\repair
2011-10-23 19:21:30 ----D---- C:\WINDOWS\mui
2011-10-23 19:21:30 ----D---- C:\WINDOWS\msapps
2011-10-23 19:21:30 ----D---- C:\WINDOWS\msagent
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Media
2011-10-23 19:21:30 ----D---- C:\WINDOWS\java
2011-10-23 19:21:30 ----D---- C:\WINDOWS\ime
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Help
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Driver Cache
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Debug
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Cursors
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Connection Wizard
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Config
2011-10-23 19:21:30 ----D---- C:\WINDOWS\AppPatch
2011-10-23 19:21:30 ----D---- C:\WINDOWS\addins
2011-10-23 19:21:30 ----D---- C:\WINDOWS
2011-10-23 17:56:26 ----D---- C:\Program Files\AVAST Software
2011-10-23 17:56:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2011-10-23 17:49:56 ----D---- C:\WINDOWS\System32\ReinstallBackups
2011-10-23 17:49:55 ----DC---- C:\WINDOWS\System32\DRVSTORE
2011-10-23 17:49:55 ----A---- C:\WINDOWS\System32\drivers\AmdPPM.sys
2011-10-23 17:49:54 ----D---- C:\Program Files\AMD
2011-10-23 17:49:41 ----D---- C:\Documents and Settings\Thomas\Data aplikací\InstallShield
2011-10-23 17:49:19 ----D---- C:\WINDOWS\LastGood.Tmp
2011-10-23 17:49:12 ----D---- C:\Program Files\Realtek
2011-10-23 17:47:56 ----D---- C:\Program Files\ATI Technologies
2011-10-23 17:47:55 ----HD---- C:\Program Files\InstallShield Installation Information
2011-10-23 17:47:31 ----D---- C:\Program Files\Common Files\InstallShield
2011-10-23 17:40:39 ----SHD---- C:\WINDOWS\Installer
2011-10-23 17:40:38 ----D---- C:\Documents and Settings\Thomas\Data aplikací\Identities
2011-10-23 17:40:36 ----HD---- C:\Program Files\Uninstall Information
2011-10-23 17:40:34 ----SD---- C:\Documents and Settings\Thomas\Data aplikací\Microsoft
2011-10-23 17:40:34 ----ASH---- C:\Documents and Settings\Thomas\Data aplikací\desktop.ini
2011-10-23 17:39:17 ----SHD---- C:\System Volume Information
2011-10-23 17:39:17 ----D---- C:\WINDOWS\Prefetch
2011-10-23 17:39:17 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-10-23 17:38:27 ----AS---- C:\WINDOWS\bootstat.dat
2011-10-23 17:37:17 ----D---- C:\WINDOWS\System32\xircom
2011-10-23 17:37:17 ----D---- C:\Program Files\xerox
2011-10-23 17:37:17 ----D---- C:\Program Files\microsoft frontpage
2011-10-23 17:37:05 ----RASH---- C:\MSDOS.SYS
2011-10-23 17:37:05 ----RASH---- C:\IO.SYS
2011-10-23 17:37:05 ----A---- C:\WINDOWS\control.ini
2011-10-23 17:37:05 ----A---- C:\CONFIG.SYS
2011-10-23 17:37:05 ----A---- C:\AUTOEXEC.BAT
2011-10-23 17:36:58 ----A---- C:\WINDOWS\System32\mapi32.dll
2011-10-23 17:36:27 ----SD---- C:\WINDOWS\Downloaded Program Files
2011-10-23 17:36:27 ----RD---- C:\WINDOWS\Offline Web Pages
2011-10-23 17:36:11 ----D---- C:\WINDOWS\srchasst
2011-10-23 17:36:03 ----D---- C:\WINDOWS\System32\Macromed
2011-10-23 17:36:03 ----D---- C:\WINDOWS\System32\DirectX
2011-10-23 17:35:50 ----A---- C:\WINDOWS\System32\qmgrprxy.dll
2011-10-23 17:35:50 ----A---- C:\WINDOWS\System32\qmgr.dll
2011-10-23 17:35:48 ----D---- C:\Program Files\Movie Maker
2011-10-23 17:35:32 ----A---- C:\WINDOWS\System32\safrslv.dll
2011-10-23 17:35:31 ----A---- C:\WINDOWS\System32\safrdm.dll
2011-10-23 17:35:31 ----A---- C:\WINDOWS\System32\safrcdlg.dll
2011-10-23 17:35:31 ----A---- C:\WINDOWS\System32\racpldlg.dll
2011-10-23 17:35:31 ----A---- C:\WINDOWS\System32\atrace.dll
2011-10-23 17:35:26 ----A---- C:\WINDOWS\System32\desktop.ini
2011-10-23 17:35:26 ----A---- C:\WINDOWS\desktop.ini
2011-10-23 17:35:20 ----D---- C:\WINDOWS\System32\Restore
2011-10-23 17:35:20 ----A---- C:\WINDOWS\System32\srsvc.dll
2011-10-23 17:35:20 ----A---- C:\WINDOWS\System32\srrstr.dll
2011-10-23 17:35:20 ----A---- C:\WINDOWS\System32\srclient.dll
2011-10-23 17:35:19 ----D---- C:\Program Files\Windows Media Player
2011-10-23 17:35:19 ----A---- C:\WINDOWS\System32\drivers\sr.sys
2011-10-23 17:35:18 ----A---- C:\WINDOWS\System32\nmmkcert.dll
2011-10-23 17:35:18 ----A---- C:\WINDOWS\System32\nmevtmsg.dll
2011-10-23 17:35:18 ----A---- C:\WINDOWS\System32\mnmsrvc.exe
2011-10-23 17:35:18 ----A---- C:\WINDOWS\System32\mnmdd.dll
2011-10-23 17:35:18 ----A---- C:\WINDOWS\System32\isrdbg32.dll
2011-10-23 17:35:18 ----A---- C:\WINDOWS\System32\ils.dll
2011-10-23 17:35:17 ----A---- C:\WINDOWS\System32\msconf.dll
2011-10-23 17:35:14 ----D---- C:\WINDOWS\PCHEALTH
2011-10-23 17:35:14 ----D---- C:\Program Files\NetMeeting
2011-10-23 17:35:14 ----A---- C:\WINDOWS\System32\msoert2.dll
2011-10-23 17:35:14 ----A---- C:\WINDOWS\System32\msoeacct.dll
2011-10-23 17:35:14 ----A---- C:\WINDOWS\System32\acctres.dll
2011-10-23 17:35:13 ----D---- C:\Program Files\Common Files\Services
2011-10-23 17:35:12 ----A---- C:\WINDOWS\System32\inetres.dll
2011-10-23 17:35:11 ----A---- C:\WINDOWS\System32\inetcomm.dll
2011-10-23 17:35:07 ----SD---- C:\WINDOWS\Tasks
2011-10-23 17:35:07 ----D---- C:\Program Files\Outlook Express
2011-10-23 17:35:07 ----A---- C:\WINDOWS\System32\schedsvc.dll
2011-10-23 17:35:07 ----A---- C:\WINDOWS\System32\mstinit.exe
2011-10-23 17:35:07 ----A---- C:\WINDOWS\System32\mstask.dll
2011-10-23 17:35:07 ----A---- C:\WINDOWS\System32\icwphbk.dll
2011-10-23 17:35:07 ----A---- C:\WINDOWS\System32\icwdial.dll
2011-10-23 17:35:06 ----A---- C:\WINDOWS\System32\isign32.dll
2011-10-23 17:35:06 ----A---- C:\WINDOWS\System32\inetcfg.dll
2011-10-23 17:35:06 ----A---- C:\WINDOWS\System32\icfgnt5.dll
2011-10-23 17:35:04 ----D---- C:\Program Files\Common Files\MSSoap
2011-10-23 17:34:59 ----D---- C:\Program Files\Common Files\System
2011-10-23 17:34:58 ----D---- C:\Program Files\Internet Explorer
2011-10-23 17:34:45 ----A---- C:\WINDOWS\System32\emptyregdb.dat
2011-10-23 17:34:33 ----D---- C:\Program Files\ComPlus Applications
2011-10-23 17:34:31 ----A---- C:\WINDOWS\vbaddin.ini
2011-10-23 17:34:31 ----A---- C:\WINDOWS\vb.ini
2011-10-23 17:34:27 ----D---- C:\WINDOWS\Registration
2011-10-23 17:34:22 ----HD---- C:\Program Files\WindowsUpdate
2011-10-23 17:34:22 ----D---- C:\Program Files\Online Services
2011-10-23 17:34:18 ----D---- C:\Program Files\Messenger
2011-10-23 17:34:12 ----D---- C:\Program Files\MSN
2011-10-23 17:34:09 ----D---- C:\Program Files\MSN Gaming Zone
2011-10-23 17:34:09 ----A---- C:\WINDOWS\System32\write.exe
2011-10-23 17:33:59 ----A---- C:\WINDOWS\System32\sndvol32.exe
2011-10-23 17:33:59 ----A---- C:\WINDOWS\System32\accwiz.exe
2011-10-23 17:33:58 ----A---- C:\WINDOWS\System32\sndrec32.exe
2011-10-23 17:33:58 ----A---- C:\WINDOWS\System32\mplay32.exe
2011-10-23 17:33:58 ----A---- C:\WINDOWS\System32\hypertrm.dll
2011-10-23 17:33:58 ----A---- C:\WINDOWS\System32\hticons.dll
2011-10-23 17:33:58 ----A---- C:\WINDOWS\System32\avwav.dll
2011-10-23 17:33:58 ----A---- C:\WINDOWS\System32\avtapi.dll
2011-10-23 17:33:58 ----A---- C:\WINDOWS\System32\avmeter.dll
2011-10-23 17:33:57 ----D---- C:\Program Files\Windows NT
2011-10-23 17:33:57 ----A---- C:\WINDOWS\System32\winchat.exe
2011-10-23 17:33:56 ----A---- C:\WINDOWS\System32\mspaint.exe
2011-10-23 17:33:51 ----A---- C:\WINDOWS\System32\clipbrd.exe
2011-10-23 17:33:50 ----A---- C:\WINDOWS\System32\charmap.exe
2011-10-23 17:33:50 ----A---- C:\WINDOWS\System32\getuname.dll
2011-10-23 17:33:50 ----A---- C:\WINDOWS\System32\calc.exe
2011-10-23 17:33:49 ----A---- C:\WINDOWS\System32\winmine.exe
2011-10-23 17:33:49 ----A---- C:\WINDOWS\System32\spider.exe
2011-10-23 17:33:49 ----A---- C:\WINDOWS\System32\sol.exe
2011-10-23 17:33:49 ----A---- C:\WINDOWS\System32\mshearts.exe
2011-10-23 17:33:48 ----A---- C:\WINDOWS\System32\wuauserv.dll
2011-10-23 17:33:48 ----A---- C:\WINDOWS\System32\wuaueng.dll
2011-10-23 17:33:48 ----A---- C:\WINDOWS\System32\wuauclt.exe
2011-10-23 17:33:48 ----A---- C:\WINDOWS\System32\tscfgwmi.dll
2011-10-23 17:33:48 ----A---- C:\WINDOWS\System32\freecell.exe
2011-10-23 17:33:48 ----A---- C:\WINDOWS\System32\drivers\tdtcp.sys
2011-10-23 17:33:48 ----A---- C:\WINDOWS\System32\drivers\tdpipe.sys
2011-10-23 17:33:48 ----A---- C:\WINDOWS\System32\drivers\rdpwd.sys
2011-10-23 17:33:47 ----A---- C:\WINDOWS\System32\sessmgr.exe
2011-10-23 17:33:47 ----A---- C:\WINDOWS\System32\reset.exe
2011-10-23 17:33:47 ----A---- C:\WINDOWS\System32\remotepg.dll
2011-10-23 17:33:47 ----A---- C:\WINDOWS\System32\rdshost.exe
2011-10-23 17:33:47 ----A---- C:\WINDOWS\System32\rdsaddin.exe
2011-10-23 17:33:47 ----A---- C:\WINDOWS\System32\rdchost.dll
2011-10-23 17:33:47 ----A---- C:\WINDOWS\System32\mstscax.dll
2011-10-23 17:33:47 ----A---- C:\WINDOWS\System32\mstsc.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\usrlogon.cmd
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\tsshutdn.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\tslabels.ini
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\tskill.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\tsdiscon.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\tscupgrd.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\tscon.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\termsrv.dll
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\shadow.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\rwinsta.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\regini.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\rdpwsx.dll
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\rdpsnd.dll
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\rdpclip.exe
2011-10-23 17:33:45 ----D---- C:\WINDOWS\System32\MsDtc
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\rdpcfgex.dll
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\qwinsta.exe
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\qprocess.exe
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\qappsrv.exe
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\msg.exe
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\msdtcuiu.dll
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\logoff.exe
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\icaapi.dll
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\cfgbkend.dll
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\cdmodem.dll
2011-10-23 17:33:44 ----A---- C:\WINDOWS\System32\xolehlp.dll
2011-10-23 17:33:44 ----A---- C:\WINDOWS\System32\mtxoci.dll
2011-10-23 17:33:44 ----A---- C:\WINDOWS\System32\msdtctm.dll
2011-10-23 17:33:44 ----A---- C:\WINDOWS\System32\msdtcprx.dll
2011-10-23 17:33:44 ----A---- C:\WINDOWS\System32\msdtcprf.ini
2011-10-23 17:33:44 ----A---- C:\WINDOWS\System32\msdtclog.dll
2011-10-23 17:33:44 ----A---- C:\WINDOWS\System32\msdtc.exe
2011-10-23 17:33:42 ----D---- C:\WINDOWS\System32\Com
2011-10-23 17:33:42 ----A---- C:\WINDOWS\System32\stclient.dll
2011-10-23 17:33:42 ----A---- C:\WINDOWS\System32\mtxlegih.dll
2011-10-23 17:33:42 ----A---- C:\WINDOWS\System32\mtxex.dll
2011-10-23 17:33:42 ----A---- C:\WINDOWS\System32\mtxdm.dll
2011-10-23 17:33:42 ----A---- C:\WINDOWS\System32\dcomcnfg.exe
2011-10-23 17:33:42 ----A---- C:\WINDOWS\System32\comrepl.dll
2011-10-23 17:33:42 ----A---- C:\WINDOWS\System32\comaddin.dll
2011-10-23 17:33:42 ----A---- C:\WINDOWS\System32\colbact.dll
2011-10-23 17:33:41 ----A---- C:\WINDOWS\System32\clbcatex.dll
2011-10-23 17:33:41 ----A---- C:\WINDOWS\System32\catsrvut.dll
2011-10-23 17:33:41 ----A---- C:\WINDOWS\System32\catsrvps.dll
2011-10-23 17:33:41 ----A---- C:\WINDOWS\System32\catsrv.dll
2011-10-23 17:33:40 ----A---- C:\WINDOWS\System32\comuid.dll
2011-10-23 17:33:40 ----A---- C:\WINDOWS\System32\comsvcs.dll
2011-10-23 17:33:40 ----A---- C:\WINDOWS\System32\comsnap.dll
2011-10-23 17:33:40 ----A---- C:\WINDOWS\System32\clbcatq.dll
2011-10-23 17:33:29 ----A---- C:\WINDOWS\System32\wmimgmt.msc
2011-10-23 17:33:29 ----A---- C:\WINDOWS\System32\servdeps.dll
2011-10-23 17:33:29 ----A---- C:\WINDOWS\System32\mmfutil.dll
2011-10-23 17:33:29 ----A---- C:\WINDOWS\System32\licwmi.dll
2011-10-23 17:33:29 ----A---- C:\WINDOWS\System32\cmprops.dll
2011-10-23 17:33:28 ----A---- C:\WINDOWS\System32\drivers\termdd.sys
2011-10-23 17:33:28 ----A---- C:\WINDOWS\System32\drivers\rdpdr.sys

======List of files/folders modified in the last 1 month======

2011-10-23 19:26:53 ----A---- C:\WINDOWS\system.ini
2011-10-23 17:37:05 ----A---- C:\WINDOWS\win.ini
2011-10-23 17:36:51 ----ASH---- C:\WINDOWS\fonts\desktop.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 aswRdr;aswRdr; C:\WINDOWS\System32\drivers\aswRdr.sys [2011-09-06 34392]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2001-10-25 13952]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\System32\DRIVERS\wmiacpi.sys [2001-08-17 8064]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtenicxp.sys [2009-05-25 142336]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2001-10-25 24960]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2001-10-25 21760]
S1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\System32\drivers\Aavmker4.sys [2011-09-06 30808]
S1 aswSP;aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [2011-09-06 320856]
S1 aswTdi;avast! Network Shield Support; C:\WINDOWS\System32\drivers\aswTdi.sys [2011-09-06 52568]
S2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\System32\drivers\aswMon2.sys [2011-09-06 110552]
S3 usbprint;Třída USB Printer; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2001-08-17 24832]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

S2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-09-06 44768]

-----------------EOF-----------------

Re: Kontrola logu

Napsal: 24 říj 2011 19:12
od Rudy
Dvouklikem na soubor C:\Program Files\trend micro\Thomas.exe spusťte HiajckThis. V otevřeném okně vlevo ve čtverečku zaškrtněte:
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
a klikněte na >Fix checked<. Restartujte PC. Jinak čisto.