Stránka 1 z 1

Prajem pekný deň

Napsal: 07 črc 2012 11:28
od mogon
Ahojte,

prosím o kontrolu logu,vopred dakujem (este som zabudol napisat že mi NOD pri kontrole najde nieco v operacnej pamati ale nevie si s tym poradit):

Logfile of random's system information tool 1.09 (written by random/random)
Run by Mogon at 2012-07-07 12:25:20
Microsoft Windows XP Professional Service Pack 3
System drive I: has 25 GB (32%) free of 80 GB
Total RAM: 3326 MB (76% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:25:26, on 7.7.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\nvsvc32.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\spoolsv.exe
I:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
I:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
I:\Program Files\ESET\ESET Smart Security\ekrn.exe
I:\Program Files\Guard-ICQ\GuardICQ.exe
I:\PROGRA~1\ICQ6TO~1\ICQSER~1.EXE
I:\Program Files\Java\jre6\bin\jqs.exe
I:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
I:\WINDOWS\system32\svchost.exe
I:\TeklaStructures\License\Server\lmgrd.exe
I:\TeklaStructures\License\Server\lmgrd.exe
I:\TeklaStructures\License\Server\tekla.exe
I:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
I:\WINDOWS\Explorer.EXE
I:\WINDOWS\RTHDCPL.EXE
I:\WINDOWS\SOUNDMAN.EXE
I:\WINDOWS\tsnp325.exe
I:\WINDOWS\vsnp325.exe
I:\WINDOWS\system32\RUNDLL32.EXE
I:\Program Files\ESET\ESET Smart Security\egui.exe
I:\Program Files\PeerGuardian2\pg2.exe
I:\WINDOWS\system32\ctfmon.exe
I:\Program Files\ICQ7M\ICQ.exe
I:\WINDOWS\system32\wuauclt.exe
I:\Documents and Settings\Mogon\Desktop\RSIT.exe
I:\Program Files\Trend Micro\Mogon.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mail.ru/cnt/9514
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - I:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - I:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - I:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - I:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - I:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - I:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] I:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [tsnp325] I:\WINDOWS\tsnp325.exe
O4 - HKLM\..\Run: [snp325] I:\WINDOWS\vsnp325.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE I:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE I:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [egui] "I:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [PeerGuardian] I:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [ctfmon.exe] I:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Aktualizovat ESET licenci.lnk = I:\Program Files\ESET\MiNODLogin\MiNODLogin.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://I:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://I:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://I:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://I:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://I:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - I:\Program Files\Stylish Profile\ct.htm (file missing)
O9 - Extra 'Tools' menuitem: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - I:\Program Files\Stylish Profile\ct.htm (file missing)
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - I:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - I:\Program Files\ICQ7M\ICQ.exe
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file:///I:/Program%20Files/AutoCAD%202002%20Cz/InstFred.ocx
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://195.28.70.134/kapor2/lib/mgaxctrl.cab
O16 - DPF: {640373B0-6978-4FA5-A9FC-420ECBBC61C7} (Web Viewer Class) - file:///C:/_Schodiská,%20Balkóny,%20Zábradlia/Zábr.%20točeného%20bet.%20schodiska/PublicWeb/dll/zkitlib.dll
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Ovládací prvek AcDcToday) - file:///I:/Program%20Files/AutoCAD%202002%20Cz/AcDcToday.ocx
O16 - DPF: {AE563723-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file:///I:/Program%20Files/AutoCAD%202002%20Cz/InstBanr.ocx
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Prvek AcPreview) - file:///I:/Program%20Files/AutoCAD%202002%20Cz/AcPreview.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - I:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - I:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - I:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - I:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - I:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - I:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - I:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corp. - I:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - I:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - I:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - I:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - I:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - I:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: Guard.Mail.ru - Unknown owner - I:\Program Files\Guard-ICQ\GuardICQ.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - I:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - I:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - I:\PROGRA~1\ICQ6TO~1\ICQSER~1.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - I:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - I:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - I:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - I:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - I:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - I:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: Tekla Structures Licensing Service - Flexera Software, Inc. - I:\TeklaStructures\License\Server\lmgrd.exe

--
End of file - 10081 bytes

======Scheduled tasks folder======

I:\WINDOWS\tasks\Adobe Flash Player Updater.job
I:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
I:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - I:\Documents and Settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default

prefs.js - "browser.startup.homepage" - "about:home"
prefs.js - "extensions.enabledItems" - "{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.4.2b, jqs@sun.com:1.0, {20a82645-c095-46ed-80e3-08825760534b}:1.2.1, {64161300-e22b-11db-8314-0800200c9a66}:0.9.5.8, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.5.1&q="

"{20a82645-c095-46ed-80e3-08825760534b}"=I:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=I:\Program Files\Java\jre6\lib\deploy\jqs\ff


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.262 Plugin
"Path"=I:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=I:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32]
"Description"=
"Path"=I:\WINDOWS\system32\npdeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=I:\Program Files\Java\jre6\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=I:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=I:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=I:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=I:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=I:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

I:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

I:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt

I:\Program Files\Mozilla Firefox\plugins\
npEModelPlugin.dll
NPOFFICE.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nsEModelPlugin.xpt
QuickTimePlugin.class

I:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

I:\Documents and Settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\extensions\
{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
{20a82645-c095-46ed-80e3-08825760534b}

I:\Documents and Settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\searchplugins\
icqplugin.gif
icqplugin.src
icqplugin.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-03-26 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - I:\Program Files\Java\jre6\bin\ssv.dll [2012-05-06 329504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - I:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-05-06 59168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - I:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2012-05-06 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - I:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26 405504]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - I:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2012-03-20 1056320]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=I:\WINDOWS\RTHDCPL.EXE [2008-07-23 16804864]
"SoundMan"=I:\WINDOWS\SOUNDMAN.EXE [2008-06-18 77824]
"AlcWzrd"=I:\WINDOWS\ALCWZRD.EXE [2008-06-19 2808832]
"JMB36X IDE Setup"=I:\WINDOWS\RaidTool\xInsIDE.exe [2007-03-20 36864]
"tsnp325"=I:\WINDOWS\tsnp325.exe [2007-04-21 270336]
"snp325"=I:\WINDOWS\vsnp325.exe [2007-05-10 835584]
"NvMediaCenter"=I:\WINDOWS\system32\NvMcTray.dll [2010-04-03 110696]
"NvCplDaemon"=I:\WINDOWS\system32\NvCpl.dll [2010-04-03 13670504]
"egui"=I:\Program Files\ESET\ESET Smart Security\egui.exe [2009-09-11 2054360]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"=I:\Program Files\PeerGuardian2\pg2.exe [2005-09-18 1421824]
"ctfmon.exe"=I:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
I:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-02 843712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
I:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2012-03-27 37296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DT PLP]
I:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe [2010-05-17 121456]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Guard.Mail.ru.gui]
I:\Program Files\Guard-ICQ\GuardICQ.exe [2012-06-19 1564368]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
I:\Program Files\ICQ7M\ICQ.exe [2012-06-19 127040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PivotSoftware]
I:\Program Files\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe [2010-05-13 110192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Companion]
I:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [2011-07-25 433360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
I:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-18 254696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
I:\Program Files\Winamp\winampa.exe [2003-12-13 33792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\I:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
I:\PROGRA~1\WI459E~1\WINDOW~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\I:^Documents and Settings^Mogon^Start Menu^Programs^Startup^GIGABYTE Gamer HUD.lnk]
I:\PROGRA~1\GIGABYTE\GAMERH~1\HUD.exe [2008-06-26 1940992]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\I:^Documents and Settings^Mogon^Start Menu^Programs^Startup^SolidWorks Task Scheduler Engine.lnk]
I:\PROGRA~1\SOLIDW~1\SWSCHE~1\SWBOEN~1.EXE [2007-09-09 488728]

I:\Documents and Settings\All Users\Start Menu\Programs\Startup
Aktualizovat ESET licenci.lnk - I:\Program Files\ESET\MiNODLogin\MiNODLogin.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
I:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2007-02-27 282624]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
I:\WINDOWS\system32\WgaLogon.dll [2008-10-18 200064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - I:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=I:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=I:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=I:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"vidc.xvid"=xvidvfw.dll

======File associations======

.scr - open - I:\WINDOWS\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2012-06-19 21:08:49 ----D---- I:\Documents and Settings\Mogon\Application Data\ICQ Search
2012-06-19 21:08:45 ----D---- I:\Program Files\ICQ6Toolbar
2012-06-19 21:08:43 ----D---- I:\Program Files\Guard-ICQ
2012-06-19 21:08:40 ----D---- I:\Documents and Settings\All Users\Application Data\ICQ
2012-06-19 21:07:59 ----D---- I:\Program Files\ICQ7M
2012-06-15 00:42:07 ----HDC---- I:\WINDOWS\$NtUninstallKB2707511$
2012-06-15 00:32:36 ----HDC---- I:\WINDOWS\$NtUninstallKB2685939$
2012-06-15 00:29:59 ----HDC---- I:\WINDOWS\$NtUninstallKB2709162$

======List of files/folders modified in the last 1 month======

2012-07-07 12:25:23 ----D---- I:\Program Files\PeerGuardian2
2012-07-07 12:25:20 ----D---- I:\Program Files\Trend Micro
2012-07-07 12:23:56 ----D---- I:\WINDOWS\Temp
2012-07-07 12:12:38 ----D---- I:\WINDOWS
2012-07-07 09:32:00 ----D---- I:\WINDOWS\system32\drivers
2012-07-07 00:17:35 ----N---- I:\WINDOWS\SchedLgU.Txt
2012-07-06 23:39:09 ----D---- I:\WINDOWS\system32\CatRoot2
2012-07-06 22:35:35 ----D---- I:\WINDOWS\Prefetch
2012-07-06 22:34:38 ----D---- I:\Program Files\SUPERAntiSpyware
2012-07-06 22:29:21 ----D---- I:\Documents and Settings\All Users\Application Data\YouTube Downloader
2012-07-05 17:47:34 ----A---- I:\WINDOWS\NeroDigital.ini
2012-07-05 13:51:36 ----D---- I:\Documents and Settings\Mogon\Application Data\ICQ
2012-07-04 16:39:05 ----A---- I:\WINDOWS\system32\FlashPlayerApp.exe
2012-07-02 20:10:48 ----D---- I:\Documents and Settings\Mogon\Application Data\SolidWorks
2012-06-29 13:36:53 ----D---- I:\WINDOWS\system32
2012-06-25 23:23:32 ----HD---- I:\BJPrinter
2012-06-24 19:21:15 ----HD---- I:\WINDOWS\inf
2012-06-24 11:47:15 ----D---- I:\Documents and Settings\Mogon\Application Data\Skype
2012-06-24 11:05:04 ----D---- I:\Documents and Settings\Mogon\Application Data\skypePM
2012-06-22 18:35:20 ----D---- I:\WINDOWS\Debug
2012-06-21 19:36:15 ----SHD---- I:\WINDOWS\Installer
2012-06-21 19:36:14 ----D---- I:\Config.Msi
2012-06-20 18:34:09 ----RSHDC---- I:\WINDOWS\system32\dllcache
2012-06-19 21:25:49 ----A---- I:\WINDOWS\wincmd.ini
2012-06-19 21:08:45 ----HD---- I:\Program Files\InstallShield Installation Information
2012-06-19 21:08:45 ----D---- I:\Program Files
2012-06-19 18:14:33 ----D---- I:\WINDOWS\Help
2012-06-17 08:54:58 ----D---- I:\Program Files\Mozilla Maintenance Service
2012-06-16 20:53:06 ----D---- I:\Program Files\Mozilla Firefox
2012-06-15 15:14:24 ----RSD---- I:\WINDOWS\assembly
2012-06-15 15:14:24 ----D---- I:\WINDOWS\Microsoft.NET
2012-06-15 00:42:33 ----D---- I:\Documents and Settings\All Users\Application Data\Microsoft Help
2012-06-15 00:41:59 ----A---- I:\WINDOWS\system32\PerfStringBackup.INI
2012-06-15 00:41:55 ----D---- I:\WINDOWS\WinSxS
2012-06-15 00:35:55 ----A---- I:\WINDOWS\system32\MRT.exe
2012-06-15 00:33:04 ----D---- I:\Program Files\Internet Explorer
2012-06-15 00:32:45 ----HD---- I:\WINDOWS\$hf_mig$
2012-06-12 18:36:13 ----D---- I:\Program Files\JDownloader

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 imagedrv;imagedrv; I:\WINDOWS\System32\Drivers\imagedrv.sys [2005-08-15 5888]
R0 imagesrv;imagesrv; I:\WINDOWS\system32\DRIVERS\imagesrv.sys [2005-08-15 127488]
R0 JRAID;JRAID; I:\WINDOWS\system32\DRIVERS\jraid.sys [2008-11-04 83296]
R0 ohci1394;Texas Instruments OHCI Compliant IEEE 1394 Host Controller; I:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; I:\WINDOWS\system32\DRIVERS\PxHelp20.sys [2009-04-28 44944]
R0 sptd;sptd; I:\WINDOWS\System32\Drivers\sptd.sys [2010-12-24 685816]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; I:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 ehdrv;ehdrv; I:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-09-11 108792]
R1 epfwtdi;epfwtdi; I:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-09-11 55768]
R1 intelppm;Intel Processor Driver; I:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 SASDIFSV;SASDIFSV; \??\I:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\I:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R2 Aspi32;Aspi32; I:\WINDOWS\system32\drivers\Aspi32.sys [1999-09-10 25244]
R2 eamon;eamon; I:\WINDOWS\system32\DRIVERS\eamon.sys [2009-09-11 116008]
R2 epfw;epfw; I:\WINDOWS\system32\DRIVERS\epfw.sys [2009-09-11 135048]
R2 Sentinel;Sentinel; I:\WINDOWS\System32\Drivers\SENTINEL.SYS [2006-03-14 90176]
R3 Arp1394;1394 ARP Client Protocol; I:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 Epfwndis;Eset Personal Firewall; I:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-06-19 33096]
R3 gdrv;gdrv; \??\I:\WINDOWS\gdrv.sys []
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; I:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); I:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-07-24 4749824]
R3 NIC1394;1394 Net Driver; I:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; I:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-04-03 10232128]
R3 PdiPorts;Portrait Displays low level device driver; I:\WINDOWS\System32\Drivers\PdiPorts.sys [2010-04-16 17136]
R3 pgfilter;pgfilter; \??\I:\Program Files\PeerGuardian2\pgfilter.sys []
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; I:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-10-16 115840]
R3 SNP325;USB PC Camera (SNPSTD325); I:\WINDOWS\system32\DRIVERS\snp325.sys [2007-07-24 10394624]
R3 usbstor;USB Mass Storage Driver; I:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; I:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 Pivot;Pivot; I:\WINDOWS\System32\drivers\pivot.sys [2010-05-13 17465]
S2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B}; \??\I:\Program Files\CyberLink\PowerDVD\000.fcl []
S3 aepwvini;aepwvini; I:\WINDOWS\system32\drivers\aepwvini.sys []
S3 CCDECODE;Closed Caption Decoder; I:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 C-Dilla;C-Dilla; \??\I:\WINDOWS\system32\drivers\CDANT.SYS []
S3 HidUsb;Microsoft HID Class Driver; I:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 mouhid;Mouse HID Driver; I:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; I:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; I:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; I:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 pivotmou;Pivot Mouse/Pointers Filter Driver; \??\I:\WINDOWS\System32\drivers\pivotmou.sys []
S3 SASENUM;SASENUM; \??\I:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 SLIP;BDA Slip De-Framer; I:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; I:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; I:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; I:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; I:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;Sony Ericsson USB Serial Port; I:\WINDOWS\system32\DRIVERS\usbser.sys [2008-04-13 26112]
S3 WpdUsb;WpdUsb; I:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; I:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; I:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 C-DillaSrv;C-DillaSrv; I:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE [2009-08-18 32256]
R2 DTSRVC;Portrait Displays Display Tune Service; I:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe [2010-05-17 121456]
R2 ekrn;ESET Service; I:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-09-11 735960]
R2 Guard.Mail.ru;Guard.Mail.ru; I:\Program Files\Guard-ICQ\GuardICQ.exe [2012-06-19 1564368]
R2 ICQ Service;ICQ Service; I:\PROGRA~1\ICQ6TO~1\ICQSER~1.EXE [2012-03-20 247872]
R2 JavaQuickStarterService;Java Quick Starter; I:\Program Files\Java\jre6\bin\jqs.exe [2012-05-06 153376]
R2 NVSvc;NVIDIA Display Driver Service; I:\WINDOWS\system32\nvsvc32.exe [2010-04-03 154216]
R2 PdiService;Portrait Displays SDK Service; I:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2010-04-16 109168]
R2 Tekla Structures Licensing Service;Tekla Structures Licensing Service; I:\TeklaStructures\License\Server\lmgrd.exe [2010-07-12 1377104]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; I:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 FLEXnet Licensing Service;FLEXnet Licensing Service; I:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-02-01 1044816]
R3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; I:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; I:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 GEST Service;GEST Service for program management.; I:\Program Files\GIGABYTE\EnergySaver\GSvr.exe [2008-12-08 68136]
S2 gupdate;Služba Google Update (gupdate); I:\Program Files\Google\Update\GoogleUpdate.exe [2010-10-15 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; I:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-04 250056]
S3 aspnet_state;ASP.NET State Service; I:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 Autodesk Licensing Service;Autodesk Licensing Service; I:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2010-04-02 77944]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; I:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service; I:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
S3 EhttpSrv;ESET HTTP Server; I:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-09-11 20680]
S3 gupdatem;Služba Google Update (gupdatem); I:\Program Files\Google\Update\GoogleUpdate.exe [2010-10-15 136176]
S3 IDriverT;InstallDriver Table Manager; I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; I:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; I:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-16 113120]
S3 odserv;Microsoft Office Diagnostics Service; I:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; I:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; I:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2012-02-26 79360]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; I:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; I:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 msvsmon80;Visual Studio 2005 Remote Debugger; I:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
S4 NBService;NBService; I:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-10-09 724992]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; I:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Prajem pekný deň

Napsal: 07 črc 2012 15:25
od vyosek
Zdravim :)

:arrow: Pokud chcete pomoci, tak odinstalujte ten nelegalni NOD a nahradte jej free resenim. Pote dejte novy log z RSIT. Tento muj "pozadavek" vychazi z platnych pravidel fora, ktere jste vy i ja povinnen dodrzovat

:arrow: Jinak se neni cemu divit ze mate PC infikovat - cracknout antivir je jako zamknout byt a nechat otevrena okna

Re: Prajem pekný deň

Napsal: 09 črc 2012 17:56
od mogon
Dobrý deň,

Nod odstránený. Ospravedlňujem sa. Ak možem poprosiť, poradil by ste mi nejaky free antivir?

Prikladám aj obrázok hlásenia z Nod-u, toho čo našiel, pri každom štarte PC sa zobrazila táto hláška: http://www.ulozisko.sk/532702/nod.bmp

Prikladám nový log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Mogon at 2012-07-09 18:47:04
Microsoft Windows XP Professional Service Pack 3
System drive I: has 22 GB (28%) free of 80 GB
Total RAM: 3326 MB (85% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:47:05, on 9.7.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\nvsvc32.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\spoolsv.exe
I:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
I:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
I:\Program Files\Guard-ICQ\GuardICQ.exe
I:\Program Files\Java\jre6\bin\jqs.exe
I:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
I:\WINDOWS\system32\svchost.exe
I:\TeklaStructures\License\Server\lmgrd.exe
I:\TeklaStructures\License\Server\lmgrd.exe
I:\WINDOWS\system32\wuauclt.exe
I:\TeklaStructures\License\Server\tekla.exe
I:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
I:\WINDOWS\Explorer.EXE
I:\WINDOWS\RTHDCPL.EXE
I:\WINDOWS\SOUNDMAN.EXE
I:\WINDOWS\tsnp325.exe
I:\WINDOWS\vsnp325.exe
I:\WINDOWS\system32\RUNDLL32.EXE
I:\Program Files\PeerGuardian2\pg2.exe
I:\WINDOWS\system32\ctfmon.exe
I:\Documents and Settings\Mogon\Desktop\RSIT.exe
I:\Program Files\Trend Micro\Mogon.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mail.ru/cnt/9514
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - I:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - I:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - I:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - I:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] I:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [tsnp325] I:\WINDOWS\tsnp325.exe
O4 - HKLM\..\Run: [snp325] I:\WINDOWS\vsnp325.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE I:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE I:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [PeerGuardian] I:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [ctfmon.exe] I:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://I:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://I:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://I:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://I:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://I:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - I:\Program Files\Stylish Profile\ct.htm (file missing)
O9 - Extra 'Tools' menuitem: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - I:\Program Files\Stylish Profile\ct.htm (file missing)
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - I:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - I:\Program Files\ICQ7M\ICQ.exe
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file:///I:/Program%20Files/AutoCAD%202002%20Cz/InstFred.ocx
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://195.28.70.134/kapor2/lib/mgaxctrl.cab
O16 - DPF: {640373B0-6978-4FA5-A9FC-420ECBBC61C7} (Web Viewer Class) - file:///C:/_Schodiská,%20Balkóny,%20Zábradlia/Zábr.%20točeného%20bet.%20schodiska/PublicWeb/dll/zkitlib.dll
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Ovládací prvek AcDcToday) - file:///I:/Program%20Files/AutoCAD%202002%20Cz/AcDcToday.ocx
O16 - DPF: {AE563723-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file:///I:/Program%20Files/AutoCAD%202002%20Cz/InstBanr.ocx
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Prvek AcPreview) - file:///I:/Program%20Files/AutoCAD%202002%20Cz/AcPreview.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - I:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - I:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - I:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - I:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - I:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - I:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - I:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corp. - I:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - I:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - I:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - I:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: Guard.Mail.ru - Unknown owner - I:\Program Files\Guard-ICQ\GuardICQ.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - I:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - I:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - I:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - I:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - I:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - I:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - I:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - I:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: Tekla Structures Licensing Service - Flexera Software, Inc. - I:\TeklaStructures\License\Server\lmgrd.exe

--
End of file - 9194 bytes

======Scheduled tasks folder======

I:\WINDOWS\tasks\Adobe Flash Player Updater.job
I:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
I:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - I:\Documents and Settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default

prefs.js - "browser.startup.homepage" - "about:home"
prefs.js - "extensions.enabledItems" - "{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.4.2b, jqs@sun.com:1.0, {20a82645-c095-46ed-80e3-08825760534b}:1.2.1, {64161300-e22b-11db-8314-0800200c9a66}:0.9.5.8, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.5.1&q="

"{20a82645-c095-46ed-80e3-08825760534b}"=I:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=I:\Program Files\Java\jre6\lib\deploy\jqs\ff


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.262 Plugin
"Path"=I:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=I:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32]
"Description"=
"Path"=I:\WINDOWS\system32\npdeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=I:\Program Files\Java\jre6\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=I:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=I:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=I:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=I:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=I:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

I:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

I:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt

I:\Program Files\Mozilla Firefox\plugins\
npEModelPlugin.dll
NPOFFICE.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nsEModelPlugin.xpt
QuickTimePlugin.class

I:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

I:\Documents and Settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\extensions\
{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
{20a82645-c095-46ed-80e3-08825760534b}

I:\Documents and Settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\searchplugins\
icqplugin.gif
icqplugin.src
icqplugin.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-03-26 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - I:\Program Files\Java\jre6\bin\ssv.dll [2012-05-06 329504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - I:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-05-06 59168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - I:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2012-05-06 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - I:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26 405504]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=I:\WINDOWS\RTHDCPL.EXE [2008-07-23 16804864]
"SoundMan"=I:\WINDOWS\SOUNDMAN.EXE [2008-06-18 77824]
"AlcWzrd"=I:\WINDOWS\ALCWZRD.EXE [2008-06-19 2808832]
"JMB36X IDE Setup"=I:\WINDOWS\RaidTool\xInsIDE.exe [2007-03-20 36864]
"tsnp325"=I:\WINDOWS\tsnp325.exe [2007-04-21 270336]
"snp325"=I:\WINDOWS\vsnp325.exe [2007-05-10 835584]
"NvMediaCenter"=I:\WINDOWS\system32\NvMcTray.dll [2010-04-03 110696]
"NvCplDaemon"=I:\WINDOWS\system32\NvCpl.dll [2010-04-03 13670504]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"=I:\Program Files\PeerGuardian2\pg2.exe [2005-09-18 1421824]
"ctfmon.exe"=I:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
I:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-02 843712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
I:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2012-03-27 37296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DT PLP]
I:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe [2010-05-17 121456]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Guard.Mail.ru.gui]
I:\Program Files\Guard-ICQ\GuardICQ.exe [2012-06-19 1564368]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
I:\Program Files\ICQ7M\ICQ.exe [2012-06-19 127040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PivotSoftware]
I:\Program Files\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe [2010-05-13 110192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Companion]
I:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [2011-07-25 433360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
I:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-18 254696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
I:\Program Files\Winamp\winampa.exe [2003-12-13 33792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\I:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
I:\PROGRA~1\WI459E~1\WINDOW~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\I:^Documents and Settings^Mogon^Start Menu^Programs^Startup^GIGABYTE Gamer HUD.lnk]
I:\PROGRA~1\GIGABYTE\GAMERH~1\HUD.exe [2008-06-26 1940992]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\I:^Documents and Settings^Mogon^Start Menu^Programs^Startup^SolidWorks Task Scheduler Engine.lnk]
I:\PROGRA~1\SOLIDW~1\SWSCHE~1\SWBOEN~1.EXE [2007-09-09 488728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
I:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2007-02-27 282624]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
I:\WINDOWS\system32\WgaLogon.dll [2008-10-18 200064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - I:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=I:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=I:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=I:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"vidc.xvid"=xvidvfw.dll

======File associations======

.scr - open - I:\WINDOWS\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2012-06-19 21:08:49 ----D---- I:\Documents and Settings\Mogon\Application Data\ICQ Search
2012-06-19 21:08:45 ----D---- I:\Program Files\ICQ6Toolbar
2012-06-19 21:08:43 ----D---- I:\Program Files\Guard-ICQ
2012-06-19 21:08:40 ----D---- I:\Documents and Settings\All Users\Application Data\ICQ
2012-06-19 21:07:59 ----D---- I:\Program Files\ICQ7M
2012-06-15 00:42:07 ----HDC---- I:\WINDOWS\$NtUninstallKB2707511$
2012-06-15 00:32:36 ----HDC---- I:\WINDOWS\$NtUninstallKB2685939$
2012-06-15 00:29:59 ----HDC---- I:\WINDOWS\$NtUninstallKB2709162$

======List of files/folders modified in the last 1 month======

2012-07-09 18:47:05 ----D---- I:\Program Files\Trend Micro
2012-07-09 18:47:05 ----D---- I:\Program Files\PeerGuardian2
2012-07-09 18:45:53 ----D---- I:\WINDOWS
2012-07-09 18:45:32 ----D---- I:\WINDOWS\Temp
2012-07-09 18:44:44 ----D---- I:\Program Files\ESET
2012-07-09 18:42:40 ----D---- I:\WINDOWS\system32\drivers
2012-07-09 18:41:55 ----N---- I:\WINDOWS\SchedLgU.Txt
2012-07-09 18:41:40 ----D---- I:\Config.Msi
2012-07-09 18:41:37 ----HD---- I:\WINDOWS\inf
2012-07-09 18:41:34 ----D---- I:\WINDOWS\system32\CatRoot2
2012-07-09 18:41:32 ----SHD---- I:\WINDOWS\Installer
2012-07-08 22:13:17 ----A---- I:\WINDOWS\NeroDigital.ini
2012-07-08 21:29:43 ----A---- I:\WINDOWS\wincmd.ini
2012-07-08 20:50:22 ----D---- I:\WINDOWS\Prefetch
2012-07-08 20:17:10 ----D---- I:\Program Files\SUPERAntiSpyware
2012-07-08 09:28:44 ----D---- I:\Documents and Settings\Mogon\Application Data\ICQ
2012-07-06 22:29:21 ----D---- I:\Documents and Settings\All Users\Application Data\YouTube Downloader
2012-07-04 16:39:05 ----A---- I:\WINDOWS\system32\FlashPlayerApp.exe
2012-07-02 20:10:48 ----D---- I:\Documents and Settings\Mogon\Application Data\SolidWorks
2012-06-29 13:36:53 ----D---- I:\WINDOWS\system32
2012-06-25 23:23:32 ----HD---- I:\BJPrinter
2012-06-24 11:47:15 ----D---- I:\Documents and Settings\Mogon\Application Data\Skype
2012-06-24 11:05:04 ----D---- I:\Documents and Settings\Mogon\Application Data\skypePM
2012-06-22 18:35:20 ----D---- I:\WINDOWS\Debug
2012-06-20 18:34:09 ----RSHDC---- I:\WINDOWS\system32\dllcache
2012-06-19 21:08:45 ----HD---- I:\Program Files\InstallShield Installation Information
2012-06-19 21:08:45 ----D---- I:\Program Files
2012-06-19 18:14:33 ----D---- I:\WINDOWS\Help
2012-06-17 08:54:58 ----D---- I:\Program Files\Mozilla Maintenance Service
2012-06-16 20:53:06 ----D---- I:\Program Files\Mozilla Firefox
2012-06-15 15:14:24 ----RSD---- I:\WINDOWS\assembly
2012-06-15 15:14:24 ----D---- I:\WINDOWS\Microsoft.NET
2012-06-15 00:42:33 ----D---- I:\Documents and Settings\All Users\Application Data\Microsoft Help
2012-06-15 00:41:59 ----A---- I:\WINDOWS\system32\PerfStringBackup.INI
2012-06-15 00:41:55 ----D---- I:\WINDOWS\WinSxS
2012-06-15 00:35:55 ----A---- I:\WINDOWS\system32\MRT.exe
2012-06-15 00:33:04 ----D---- I:\Program Files\Internet Explorer
2012-06-15 00:32:45 ----HD---- I:\WINDOWS\$hf_mig$
2012-06-12 18:36:13 ----D---- I:\Program Files\JDownloader

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 imagedrv;imagedrv; I:\WINDOWS\System32\Drivers\imagedrv.sys [2005-08-15 5888]
R0 imagesrv;imagesrv; I:\WINDOWS\system32\DRIVERS\imagesrv.sys [2005-08-15 127488]
R0 JRAID;JRAID; I:\WINDOWS\system32\DRIVERS\jraid.sys [2008-11-04 83296]
R0 ohci1394;Texas Instruments OHCI Compliant IEEE 1394 Host Controller; I:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; I:\WINDOWS\system32\DRIVERS\PxHelp20.sys [2009-04-28 44944]
R0 sptd;sptd; I:\WINDOWS\System32\Drivers\sptd.sys [2010-12-24 685816]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; I:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 intelppm;Intel Processor Driver; I:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 SASDIFSV;SASDIFSV; \??\I:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\I:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R2 Aspi32;Aspi32; I:\WINDOWS\system32\drivers\Aspi32.sys [1999-09-10 25244]
R2 Sentinel;Sentinel; I:\WINDOWS\System32\Drivers\SENTINEL.SYS [2006-03-14 90176]
R3 Arp1394;1394 ARP Client Protocol; I:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 gdrv;gdrv; \??\I:\WINDOWS\gdrv.sys []
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; I:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); I:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-07-24 4749824]
R3 NIC1394;1394 Net Driver; I:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; I:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-04-03 10232128]
R3 PdiPorts;Portrait Displays low level device driver; I:\WINDOWS\System32\Drivers\PdiPorts.sys [2010-04-16 17136]
R3 pgfilter;pgfilter; \??\I:\Program Files\PeerGuardian2\pgfilter.sys []
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; I:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-10-16 115840]
R3 SNP325;USB PC Camera (SNPSTD325); I:\WINDOWS\system32\DRIVERS\snp325.sys [2007-07-24 10394624]
R3 usbstor;USB Mass Storage Driver; I:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; I:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 Pivot;Pivot; I:\WINDOWS\System32\drivers\pivot.sys [2010-05-13 17465]
S2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B}; \??\I:\Program Files\CyberLink\PowerDVD\000.fcl []
S3 ah7h6nz8;ah7h6nz8; I:\WINDOWS\system32\drivers\ah7h6nz8.sys []
S3 CCDECODE;Closed Caption Decoder; I:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 C-Dilla;C-Dilla; \??\I:\WINDOWS\system32\drivers\CDANT.SYS []
S3 HidUsb;Microsoft HID Class Driver; I:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 mouhid;Mouse HID Driver; I:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; I:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; I:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; I:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 pivotmou;Pivot Mouse/Pointers Filter Driver; \??\I:\WINDOWS\System32\drivers\pivotmou.sys []
S3 SASENUM;SASENUM; \??\I:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 SLIP;BDA Slip De-Framer; I:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; I:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; I:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; I:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; I:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;Sony Ericsson USB Serial Port; I:\WINDOWS\system32\DRIVERS\usbser.sys [2008-04-13 26112]
S3 WpdUsb;WpdUsb; I:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; I:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; I:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 C-DillaSrv;C-DillaSrv; I:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE [2009-08-18 32256]
R2 DTSRVC;Portrait Displays Display Tune Service; I:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe [2010-05-17 121456]
R2 Guard.Mail.ru;Guard.Mail.ru; I:\Program Files\Guard-ICQ\GuardICQ.exe [2012-06-19 1564368]
R2 JavaQuickStarterService;Java Quick Starter; I:\Program Files\Java\jre6\bin\jqs.exe [2012-05-06 153376]
R2 NVSvc;NVIDIA Display Driver Service; I:\WINDOWS\system32\nvsvc32.exe [2010-04-03 154216]
R2 PdiService;Portrait Displays SDK Service; I:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2010-04-16 109168]
R2 Tekla Structures Licensing Service;Tekla Structures Licensing Service; I:\TeklaStructures\License\Server\lmgrd.exe [2010-07-12 1377104]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; I:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 FLEXnet Licensing Service;FLEXnet Licensing Service; I:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-02-01 1044816]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; I:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 GEST Service;GEST Service for program management.; I:\Program Files\GIGABYTE\EnergySaver\GSvr.exe [2008-12-08 68136]
S2 gupdate;Služba Google Update (gupdate); I:\Program Files\Google\Update\GoogleUpdate.exe [2010-10-15 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; I:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-04 250056]
S3 aspnet_state;ASP.NET State Service; I:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 Autodesk Licensing Service;Autodesk Licensing Service; I:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2010-04-02 77944]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; I:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service; I:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; I:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); I:\Program Files\Google\Update\GoogleUpdate.exe [2010-10-15 136176]
S3 IDriverT;InstallDriver Table Manager; I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; I:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; I:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-16 113120]
S3 odserv;Microsoft Office Diagnostics Service; I:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; I:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; I:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2012-02-26 79360]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; I:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; I:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 msvsmon80;Visual Studio 2005 Remote Debugger; I:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
S4 NBService;NBService; I:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-10-09 724992]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; I:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Prajem pekný deň

Napsal: 09 črc 2012 18:28
od vyosek
:arrow: Free antivir doporucuji Avast :)

Zdravim a pekny den preji :)

:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pockejte na dokonceni PreScanu
  • Zvolte moznost Prohledat (scan)
  • Po dokonceni skenu kliknete na Zpráva (Report)- otevre se log, ten sem vlozte
:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Kliknete na volbu Change parametrs
  • V obou oknech (Objects to scan i Additional Option) zakliknete vsechny moznosti - ve vsech ctvereccich musi mit fajecka
  • Kliknete na OK
  • Utilite prikazte, at skenuje - klik na Start Scan
  • Po dokonceni skenu se objevi okno, zkontrolujte, zda-li je vsude moznost Skip
  • Pokud moznost Skip nebude primarne nastavena, prekliknete ji na Skip
  • Pokud mate vsude Skip, kliknete na Continue
  • Na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt bude log - jeho obsah sem vlozte

Re: Prajem pekný deň

Napsal: 09 črc 2012 19:02
od mogon
Prikladám report z RogueKiller a po dokončení skenu mi na ploche pribudol súbor: RK_Quarantine

Log: RogueKiller V7.6.3 [07/08/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Mogon [Admin rights]
Mode: Scan -- Date: 07/09/2012 19:49:31

¤¤¤ Bad processes: 2 ¤¤¤
[SUSP PATH] tsnp325.exe -- I:\WINDOWS\tsnp325.exe -> KILLED [TermProc]
[SUSP PATH] vsnp325.exe -- I:\WINDOWS\vsnp325.exe -> KILLED [TermProc]

¤¤¤ Registry Entries: 4 ¤¤¤
[SUSP PATH] HKLM\[...]\Run : tsnp325 (I:\WINDOWS\tsnp325.exe) -> FOUND
[SUSP PATH] HKLM\[...]\Run : snp325 (I:\WINDOWS\vsnp325.exe) -> FOUND
[HJ] HKLM\[...]\SystemRestore : DisableSR (1) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤
[Faked.Drv][FAKED] netbt.sys : i:\windows\system32\drivers\netbt.sys --> CANNOT FIX

¤¤¤ Driver: [LOADED] ¤¤¤
IRP[IRP_MJ_CREATE] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xB7DF2B40)
IRP[IRP_MJ_CLOSE] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xB7DF2B40)
IRP[IRP_MJ_DEVICE_CONTROL] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xB7DF2B40)
IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xB7DF2B40)
IRP[IRP_MJ_SYSTEM_CONTROL] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xB7DF2B40)
IRP[IRP_MJ_DEVICE_CHANGE] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xB7DF2B40)

¤¤¤ Infection : ZeroAccess ¤¤¤
[ZeroAccess] (LOCKED) windir\NtUpdateKBxxxx present!

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: SATA SAMSUNG HD753LJ SCSI Disk Device +++++
--- User ---
[MBR] 9bb7c59a6cbba041fb3a6ba45a100697
[BSP] 214de69f6e57b6c57c521cd4c3dcc9e7 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 80395 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 164650185 | Size: 634998 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Finished : << RKreport[1].txt >>
RKreport[1].txt



Prikladám tiež report z TDSSKiller:

19:54:39.0968 2400 TDSS rootkit removing tool 2.7.45.0 Jul 9 2012 12:46:35
19:54:40.0093 2400 ============================================================
19:54:40.0093 2400 Current date / time: 2012/07/09 19:54:40.0093
19:54:40.0093 2400 SystemInfo:
19:54:40.0093 2400
19:54:40.0093 2400 OS Version: 5.1.2600 ServicePack: 3.0
19:54:40.0093 2400 Product type: Workstation
19:54:40.0093 2400 ComputerName: MOGON-1CA4C1668
19:54:40.0093 2400 UserName: Mogon
19:54:40.0093 2400 Windows directory: I:\WINDOWS
19:54:40.0093 2400 System windows directory: I:\WINDOWS
19:54:40.0093 2400 Processor architecture: Intel x86
19:54:40.0093 2400 Number of processors: 8
19:54:40.0093 2400 Page size: 0x1000
19:54:40.0093 2400 Boot type: Normal boot
19:54:40.0093 2400 ============================================================
19:54:40.0968 2400 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8BD5E00 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000058
19:54:40.0984 2400 ============================================================
19:54:40.0984 2400 \Device\Harddisk0\DR0:
19:54:40.0984 2400 MBR partitions:
19:54:40.0984 2400 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x9D05C8A
19:54:41.0000 2400 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x9D05D08, BlocksNum 0x1CAFAD47
19:54:41.0015 2400 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x26800A8E, BlocksNum 0x30D409B2
19:54:41.0015 2400 ============================================================
19:54:41.0046 2400 I: <-> \Device\Harddisk0\DR0\Partition0
19:54:41.0140 2400 J: <-> \Device\Harddisk0\DR0\Partition1
19:54:41.0390 2400 K: <-> \Device\Harddisk0\DR0\Partition2
19:54:41.0390 2400 ============================================================
19:54:41.0390 2400 Initialize success
19:54:41.0390 2400 ============================================================
19:55:36.0921 3280 ============================================================
19:55:36.0921 3280 Scan started
19:55:36.0921 3280 Mode: Manual; SigCheck; TDLFS;
19:55:36.0921 3280 ============================================================
19:55:37.0078 3280 Abiosdsk - ok
19:55:37.0078 3280 abp480n5 - ok
19:55:37.0125 3280 ACPI (8fd99680a539792a30e97944fdaecf17) I:\WINDOWS\system32\DRIVERS\ACPI.sys
19:55:38.0375 3280 ACPI - ok
19:55:38.0453 3280 ACPIEC (9859c0f6936e723e4892d7141b1327d5) I:\WINDOWS\system32\drivers\ACPIEC.sys
19:55:38.0640 3280 ACPIEC - ok
19:55:38.0750 3280 AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) I:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
19:55:38.0765 3280 AdobeFlashPlayerUpdateSvc - ok
19:55:38.0765 3280 adpu160m - ok
19:55:38.0796 3280 aec (8bed39e3c35d6a489438b8141717a557) I:\WINDOWS\system32\drivers\aec.sys
19:55:38.0937 3280 aec - ok
19:55:38.0984 3280 AFD (1e44bc1e83d8fd2305f8d452db109cf9) I:\WINDOWS\System32\drivers\afd.sys
19:55:39.0046 3280 AFD - ok
19:55:39.0046 3280 Aha154x - ok
19:55:39.0062 3280 aic78u2 - ok
19:55:39.0062 3280 aic78xx - ok
19:55:39.0093 3280 Alerter (a9a3daa780ca6c9671a19d52456705b4) I:\WINDOWS\system32\alrsvc.dll
19:55:39.0234 3280 Alerter - ok
19:55:39.0265 3280 ALG (8c515081584a38aa007909cd02020b3d) I:\WINDOWS\System32\alg.exe
19:55:39.0343 3280 ALG - ok
19:55:39.0359 3280 AliIde - ok
19:55:39.0359 3280 amsint - ok
19:55:39.0421 3280 AppMgmt (d8849f77c0b66226335a59d26cb4edc6) I:\WINDOWS\System32\appmgmts.dll
19:55:39.0484 3280 AppMgmt - ok
19:55:39.0500 3280 Arp1394 (b5b8a80875c1dededa8b02765642c32f) I:\WINDOWS\system32\DRIVERS\arp1394.sys
19:55:39.0640 3280 Arp1394 - ok
19:55:39.0640 3280 asc - ok
19:55:39.0640 3280 asc3350p - ok
19:55:39.0656 3280 asc3550 - ok
19:55:39.0703 3280 Aspi32 (b979979ab8027f7f53fb16ec4229b7db) I:\WINDOWS\system32\drivers\Aspi32.sys
19:55:39.0718 3280 Aspi32 ( UnsignedFile.Multi.Generic ) - warning
19:55:39.0718 3280 Aspi32 - detected UnsignedFile.Multi.Generic (1)
19:55:39.0843 3280 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) I:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
19:55:39.0937 3280 aspnet_state - ok
19:55:39.0953 3280 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) I:\WINDOWS\system32\DRIVERS\asyncmac.sys
19:55:40.0078 3280 AsyncMac - ok
19:55:40.0093 3280 atapi (9f3a2f5aa6875c72bf062c712cfa2674) I:\WINDOWS\system32\DRIVERS\atapi.sys
19:55:40.0250 3280 atapi - ok
19:55:40.0250 3280 Atdisk - ok
19:55:40.0281 3280 Atmarpc (9916c1225104ba14794209cfa8012159) I:\WINDOWS\system32\DRIVERS\atmarpc.sys
19:55:40.0406 3280 Atmarpc - ok
19:55:40.0437 3280 AudioSrv (def7a7882bec100fe0b2ce2549188f9d) I:\WINDOWS\System32\audiosrv.dll
19:55:40.0562 3280 AudioSrv - ok
19:55:40.0609 3280 audstub (d9f724aa26c010a217c97606b160ed68) I:\WINDOWS\system32\DRIVERS\audstub.sys
19:55:40.0734 3280 audstub - ok
19:55:40.0796 3280 Autodesk Licensing Service (32a5defddc3562bf89d73586f5915b34) I:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
19:55:40.0812 3280 Autodesk Licensing Service - ok
19:55:40.0828 3280 Beep (da1f27d85e0d1525f6621372e7b685e9) I:\WINDOWS\system32\drivers\Beep.sys
19:55:40.0968 3280 Beep - ok
19:55:41.0000 3280 BITS (574738f61fca2935f5265dc4e5691314) I:\WINDOWS\system32\qmgr.dll
19:55:41.0140 3280 BITS - ok
19:55:41.0171 3280 Browser (a06ce3399d16db864f55faeb1f1927a9) I:\WINDOWS\System32\browser.dll
19:55:41.0296 3280 Browser - ok
19:55:41.0343 3280 C-Dilla (894ffbfc41be336443bee9c33010419a) I:\WINDOWS\system32\drivers\CDANT.SYS
19:55:41.0343 3280 C-Dilla ( UnsignedFile.Multi.Generic ) - warning
19:55:41.0343 3280 C-Dilla - detected UnsignedFile.Multi.Generic (1)
19:55:41.0390 3280 C-DillaSrv (42c77c40b230e51be2952f943b1513e7) I:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
19:55:41.0390 3280 C-DillaSrv ( UnsignedFile.Multi.Generic ) - warning
19:55:41.0390 3280 C-DillaSrv - detected UnsignedFile.Multi.Generic (1)
19:55:41.0406 3280 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) I:\WINDOWS\system32\drivers\cbidf2k.sys
19:55:41.0546 3280 cbidf2k - ok
19:55:41.0562 3280 CCDECODE (0be5aef125be881c4f854c554f2b025c) I:\WINDOWS\system32\DRIVERS\CCDECODE.sys
19:55:41.0687 3280 CCDECODE - ok
19:55:41.0703 3280 cd20xrnt - ok
19:55:41.0703 3280 Cdaudio (c1b486a7658353d33a10cc15211a873b) I:\WINDOWS\system32\drivers\Cdaudio.sys
19:55:41.0843 3280 Cdaudio - ok
19:55:41.0859 3280 Cdfs (c885b02847f5d2fd45a24e219ed93b32) I:\WINDOWS\system32\drivers\Cdfs.sys
19:55:42.0000 3280 Cdfs - ok
19:55:42.0031 3280 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) I:\WINDOWS\system32\DRIVERS\cdrom.sys
19:55:42.0171 3280 Cdrom - ok
19:55:42.0171 3280 Changer - ok
19:55:42.0187 3280 CiSvc (1cfe720eb8d93a7158a4ebc3ab178bde) I:\WINDOWS\system32\cisvc.exe
19:55:42.0312 3280 CiSvc - ok
19:55:42.0328 3280 ClipSrv (34cbe729f38138217f9c80212a2a0c82) I:\WINDOWS\system32\clipsrv.exe
19:55:42.0468 3280 ClipSrv - ok
19:55:42.0562 3280 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) I:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:55:42.0671 3280 clr_optimization_v2.0.50727_32 - ok
19:55:42.0750 3280 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) I:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:55:42.0765 3280 clr_optimization_v4.0.30319_32 - ok
19:55:42.0765 3280 CmdIde - ok
19:55:42.0765 3280 COMSysApp - ok
19:55:42.0875 3280 CoordinatorServiceHost (ab82a8885ab9687d82aa51a4b4f62e2d) I:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
19:55:42.0890 3280 CoordinatorServiceHost - ok
19:55:42.0906 3280 Cpqarray - ok
19:55:42.0921 3280 CryptSvc (3d4e199942e29207970e04315d02ad3b) I:\WINDOWS\System32\cryptsvc.dll
19:55:43.0062 3280 CryptSvc - ok
19:55:43.0062 3280 dac2w2k - ok
19:55:43.0062 3280 dac960nt - ok
19:55:43.0125 3280 DcomLaunch (6b27a5c03dfb94b4245739065431322c) I:\WINDOWS\system32\rpcss.dll
19:55:43.0171 3280 DcomLaunch - ok
19:55:43.0234 3280 Dhcp (5e38d7684a49cacfb752b046357e0589) I:\WINDOWS\System32\dhcpcsvc.dll
19:55:43.0375 3280 Dhcp - ok
19:55:43.0390 3280 Disk (044452051f3e02e7963599fc8f4f3e25) I:\WINDOWS\system32\DRIVERS\disk.sys
19:55:43.0531 3280 Disk - ok
19:55:43.0531 3280 dmadmin - ok
19:55:43.0578 3280 dmboot (d992fe1274bde0f84ad826acae022a41) I:\WINDOWS\system32\drivers\dmboot.sys
19:55:43.0734 3280 dmboot - ok
19:55:43.0750 3280 dmio (7c824cf7bbde77d95c08005717a95f6f) I:\WINDOWS\system32\drivers\dmio.sys
19:55:43.0890 3280 dmio - ok
19:55:43.0921 3280 dmload (e9317282a63ca4d188c0df5e09c6ac5f) I:\WINDOWS\system32\drivers\dmload.sys
19:55:44.0046 3280 dmload - ok
19:55:44.0062 3280 dmserver (57edec2e5f59f0335e92f35184bc8631) I:\WINDOWS\System32\dmserver.dll
19:55:44.0203 3280 dmserver - ok
19:55:44.0234 3280 DMusic (8a208dfcf89792a484e76c40e5f50b45) I:\WINDOWS\system32\drivers\DMusic.sys
19:55:44.0375 3280 DMusic - ok
19:55:44.0406 3280 Dnscache (5f7e24fa9eab896051ffb87f840730d2) I:\WINDOWS\System32\dnsrslvr.dll
19:55:44.0437 3280 Dnscache - ok
19:55:44.0453 3280 Dot3svc (0f0f6e687e5e15579ef4da8dd6945814) I:\WINDOWS\System32\dot3svc.dll
19:55:44.0593 3280 Dot3svc - ok
19:55:44.0609 3280 dpti2o - ok
19:55:44.0609 3280 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) I:\WINDOWS\system32\drivers\drmkaud.sys
19:55:44.0734 3280 drmkaud - ok
19:55:44.0859 3280 DTSRVC (805dc72532529080df97891dbdd61f38) I:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
19:55:44.0906 3280 DTSRVC - ok
19:55:44.0953 3280 EapHost (2187855a7703adef0cef9ee4285182cc) I:\WINDOWS\System32\eapsvc.dll
19:55:45.0078 3280 EapHost - ok
19:55:45.0140 3280 ERSvc (bc93b4a066477954555966d77fec9ecb) I:\WINDOWS\System32\ersvc.dll
19:55:45.0265 3280 ERSvc - ok
19:55:45.0296 3280 Eventlog (65df52f5b8b6e9bbd183505225c37315) I:\WINDOWS\system32\services.exe
19:55:45.0328 3280 Eventlog - ok
19:55:45.0375 3280 EventSystem (d4991d98f2db73c60d042f1aef79efae) I:\WINDOWS\system32\es.dll
19:55:45.0437 3280 EventSystem - ok
19:55:45.0453 3280 Fastfat (38d332a6d56af32635675f132548343e) I:\WINDOWS\system32\drivers\Fastfat.sys
19:55:45.0578 3280 Fastfat - ok
19:55:45.0593 3280 FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) I:\WINDOWS\System32\shsvcs.dll
19:55:45.0625 3280 FastUserSwitchingCompatibility - ok
19:55:45.0656 3280 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) I:\WINDOWS\system32\drivers\Fdc.sys
19:55:45.0796 3280 Fdc - ok
19:55:45.0812 3280 Fips (d45926117eb9fa946a6af572fbe1caa3) I:\WINDOWS\system32\drivers\Fips.sys
19:55:45.0937 3280 Fips - ok
19:55:46.0031 3280 FLEXnet Licensing Service (73081cf28f0ae20a52ca4f67cee6e6b0) I:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
19:55:46.0078 3280 FLEXnet Licensing Service - ok
19:55:46.0078 3280 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) I:\WINDOWS\system32\drivers\Flpydisk.sys
19:55:46.0218 3280 Flpydisk - ok
19:55:46.0234 3280 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) I:\WINDOWS\system32\drivers\fltmgr.sys
19:55:46.0375 3280 FltMgr - ok
19:55:46.0546 3280 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) I:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
19:55:46.0562 3280 FontCache3.0.0.0 - ok
19:55:46.0609 3280 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) I:\WINDOWS\system32\drivers\Fs_Rec.sys
19:55:46.0750 3280 Fs_Rec - ok
19:55:46.0750 3280 Ftdisk (6ac26732762483366c3969c9e4d2259d) I:\WINDOWS\system32\DRIVERS\ftdisk.sys
19:55:46.0890 3280 Ftdisk - ok
19:55:46.0953 3280 gdrv (c6e3105b8c68c35cc1eb26a00fd1a8c6) I:\WINDOWS\gdrv.sys
19:55:47.0296 3280 gdrv - ok
19:55:47.0343 3280 GEST Service (20438b962021f0ea729020ed5a148d4c) I:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
19:55:47.0359 3280 GEST Service - ok
19:55:47.0390 3280 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) I:\WINDOWS\system32\DRIVERS\msgpc.sys
19:55:47.0531 3280 Gpc - ok
19:55:47.0640 3280 Guard.Mail.ru (e859ca020ed61899f3c74a8d0032d05c) I:\Program Files\Guard-ICQ\GuardICQ.exe
19:55:47.0703 3280 Guard.Mail.ru - ok
19:55:47.0750 3280 gupdate (f02a533f517eb38333cb12a9e8963773) I:\Program Files\Google\Update\GoogleUpdate.exe
19:55:47.0765 3280 gupdate - ok
19:55:47.0765 3280 gupdatem (f02a533f517eb38333cb12a9e8963773) I:\Program Files\Google\Update\GoogleUpdate.exe
19:55:47.0781 3280 gupdatem - ok
19:55:47.0875 3280 HDAudBus (573c7d0a32852b48f3058cfd8026f511) I:\WINDOWS\system32\DRIVERS\HDAudBus.sys
19:55:48.0015 3280 HDAudBus - ok
19:55:48.0109 3280 helpsvc (4fcca060dfe0c51a09dd5c3843888bcd) I:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
19:55:48.0234 3280 helpsvc - ok
19:55:48.0250 3280 HidServ - ok
19:55:48.0281 3280 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) I:\WINDOWS\system32\DRIVERS\hidusb.sys
19:55:48.0421 3280 HidUsb - ok
19:55:48.0453 3280 hkmsvc (8878bd685e490239777bfe51320b88e9) I:\WINDOWS\System32\kmsvc.dll
19:55:48.0593 3280 hkmsvc - ok
19:55:48.0609 3280 hpn - ok
19:55:48.0671 3280 HTTP (f80a415ef82cd06ffaf0d971528ead38) I:\WINDOWS\system32\Drivers\HTTP.sys
19:55:48.0718 3280 HTTP - ok
19:55:48.0750 3280 HTTPFilter (6100a808600f44d999cebdef8841c7a3) I:\WINDOWS\System32\w3ssl.dll
19:55:48.0890 3280 HTTPFilter - ok
19:55:48.0890 3280 i2omgmt - ok
19:55:48.0890 3280 i2omp - ok
19:55:48.0906 3280 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) I:\WINDOWS\system32\DRIVERS\i8042prt.sys
19:55:49.0046 3280 i8042prt - ok
19:55:49.0109 3280 IDriverT (1cf03c69b49acb70c722df92755c0c8c) I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
19:55:49.0109 3280 IDriverT ( UnsignedFile.Multi.Generic ) - warning
19:55:49.0109 3280 IDriverT - detected UnsignedFile.Multi.Generic (1)
19:55:49.0234 3280 idsvc (c01ac32dc5c03076cfb852cb5da5229c) I:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
19:55:49.0281 3280 idsvc - ok
19:55:49.0312 3280 imagedrv (25edd75e23c5ef6b33d0fbcce125a601) I:\WINDOWS\system32\Drivers\imagedrv.sys
19:55:49.0328 3280 imagedrv ( UnsignedFile.Multi.Generic ) - warning
19:55:49.0328 3280 imagedrv - detected UnsignedFile.Multi.Generic (1)
19:55:49.0343 3280 imagesrv (9c4bbacf4e9b9543c3ce23f1fe556941) I:\WINDOWS\system32\DRIVERS\imagesrv.sys
19:55:49.0359 3280 imagesrv ( UnsignedFile.Multi.Generic ) - warning
19:55:49.0359 3280 imagesrv - detected UnsignedFile.Multi.Generic (1)
19:55:49.0359 3280 Imapi (083a052659f5310dd8b6a6cb05edcf8e) I:\WINDOWS\system32\DRIVERS\imapi.sys
19:55:49.0484 3280 Imapi - ok
19:55:49.0515 3280 ImapiService (30deaf54a9755bb8546168cfe8a6b5e1) I:\WINDOWS\system32\imapi.exe
19:55:49.0640 3280 ImapiService - ok
19:55:49.0656 3280 ini910u - ok
19:55:49.0937 3280 IntcAzAudAddService (4aaa8312732655f93a254d1fa695eb79) I:\WINDOWS\system32\drivers\RtkHDAud.sys
19:55:50.0125 3280 IntcAzAudAddService - ok
19:55:50.0187 3280 IntelIde - ok
19:55:50.0218 3280 intelppm (8c953733d8f36eb2133f5bb58808b66b) I:\WINDOWS\system32\DRIVERS\intelppm.sys
19:55:50.0343 3280 intelppm - ok
19:55:50.0359 3280 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) I:\WINDOWS\system32\drivers\ip6fw.sys
19:55:50.0500 3280 Ip6Fw - ok
19:55:50.0546 3280 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) I:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
19:55:50.0671 3280 IpFilterDriver - ok
19:55:50.0687 3280 IpInIp (b87ab476dcf76e72010632b5550955f5) I:\WINDOWS\system32\DRIVERS\ipinip.sys
19:55:50.0828 3280 IpInIp - ok
19:55:50.0843 3280 IpNat (cc748ea12c6effde940ee98098bf96bb) I:\WINDOWS\system32\DRIVERS\ipnat.sys
19:55:50.0968 3280 IpNat - ok
19:55:50.0984 3280 IPSec (23c74d75e36e7158768dd63d92789a91) I:\WINDOWS\system32\DRIVERS\ipsec.sys
19:55:51.0125 3280 IPSec - ok
19:55:51.0140 3280 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) I:\WINDOWS\system32\DRIVERS\irenum.sys
19:55:51.0203 3280 IRENUM - ok
19:55:51.0218 3280 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) I:\WINDOWS\system32\DRIVERS\isapnp.sys
19:55:51.0359 3280 isapnp - ok
19:55:51.0500 3280 JavaQuickStarterService (a38441ed570f190cc041a7be49488fa7) I:\Program Files\Java\jre6\bin\jqs.exe
19:55:51.0515 3280 JavaQuickStarterService - ok
19:55:51.0515 3280 JRAID (a324485106f133e751f4b7f47c4be3ea) I:\WINDOWS\system32\DRIVERS\jraid.sys
19:55:51.0562 3280 JRAID - ok
19:55:51.0578 3280 Kbdclass (463c1ec80cd17420a542b7f36a36f128) I:\WINDOWS\system32\DRIVERS\kbdclass.sys
19:55:51.0703 3280 Kbdclass - ok
19:55:51.0718 3280 kmixer (692bcf44383d056aed41b045a323d378) I:\WINDOWS\system32\drivers\kmixer.sys
19:55:51.0843 3280 kmixer - ok
19:55:51.0875 3280 KSecDD (b467646c54cc746128904e1654c750c1) I:\WINDOWS\system32\drivers\KSecDD.sys
19:55:51.0968 3280 KSecDD - ok
19:55:52.0000 3280 lanmanserver (3a7c3cbe5d96b8ae96ce81f0b22fb527) I:\WINDOWS\System32\srvsvc.dll
19:55:52.0015 3280 lanmanserver - ok
19:55:52.0078 3280 lanmanworkstation (a8888a5327621856c0cec4e385f69309) I:\WINDOWS\System32\wkssvc.dll
19:55:52.0093 3280 lanmanworkstation - ok
19:55:52.0093 3280 lbrtfdc - ok
19:55:52.0109 3280 LmHosts (a7db739ae99a796d91580147e919cc59) I:\WINDOWS\System32\lmhsvc.dll
19:55:52.0234 3280 LmHosts - ok
19:55:52.0250 3280 Messenger (986b1ff5814366d71e0ac5755c88f2d3) I:\WINDOWS\System32\msgsvc.dll
19:55:52.0406 3280 Messenger - ok
19:55:52.0421 3280 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) I:\WINDOWS\system32\drivers\mnmdd.sys
19:55:52.0562 3280 mnmdd - ok
19:55:52.0578 3280 mnmsrvc (d18f1f0c101d06a1c1adf26eed16fcdd) I:\WINDOWS\system32\mnmsrvc.exe
19:55:52.0718 3280 mnmsrvc - ok
19:55:52.0734 3280 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) I:\WINDOWS\system32\drivers\Modem.sys
19:55:52.0859 3280 Modem - ok
19:55:52.0875 3280 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) I:\WINDOWS\system32\DRIVERS\mouclass.sys
19:55:53.0015 3280 Mouclass - ok
19:55:53.0015 3280 mouhid (b1c303e17fb9d46e87a98e4ba6769685) I:\WINDOWS\system32\DRIVERS\mouhid.sys
19:55:53.0140 3280 mouhid - ok
19:55:53.0156 3280 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) I:\WINDOWS\system32\drivers\MountMgr.sys
19:55:53.0281 3280 MountMgr - ok
19:55:53.0343 3280 MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) I:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
19:55:53.0359 3280 MozillaMaintenance - ok
19:55:53.0359 3280 mraid35x - ok
19:55:53.0375 3280 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) I:\WINDOWS\system32\DRIVERS\mrxdav.sys
19:55:53.0515 3280 MRxDAV - ok
19:55:53.0562 3280 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) I:\WINDOWS\system32\DRIVERS\mrxsmb.sys
19:55:53.0609 3280 MRxSmb - ok
19:55:53.0625 3280 MSDTC (a137f1470499a205abbb9aafb3b6f2b1) I:\WINDOWS\system32\msdtc.exe
19:55:53.0765 3280 MSDTC - ok
19:55:53.0765 3280 Msfs (c941ea2454ba8350021d774daf0f1027) I:\WINDOWS\system32\drivers\Msfs.sys
19:55:53.0906 3280 Msfs - ok
19:55:53.0906 3280 MSIServer - ok
19:55:53.0921 3280 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) I:\WINDOWS\system32\drivers\MSKSSRV.sys
19:55:54.0046 3280 MSKSSRV - ok
19:55:54.0062 3280 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) I:\WINDOWS\system32\drivers\MSPCLOCK.sys
19:55:54.0187 3280 MSPCLOCK - ok
19:55:54.0203 3280 MSPQM (bad59648ba099da4a17680b39730cb3d) I:\WINDOWS\system32\drivers\MSPQM.sys
19:55:54.0328 3280 MSPQM - ok
19:55:54.0343 3280 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) I:\WINDOWS\system32\DRIVERS\mssmbios.sys
19:55:54.0484 3280 mssmbios - ok
19:55:54.0546 3280 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) I:\WINDOWS\system32\drivers\MSTEE.sys
19:55:54.0687 3280 MSTEE - ok
19:55:54.0875 3280 msvsmon80 (73fa09b84b23a1897809a84f976d5d99) I:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe
19:55:55.0015 3280 msvsmon80 - ok
19:55:55.0109 3280 Mup (de6a75f5c270e756c5508d94b6cf68f5) I:\WINDOWS\system32\drivers\Mup.sys
19:55:55.0125 3280 Mup - ok
19:55:55.0140 3280 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) I:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
19:55:55.0281 3280 NABTSFEC - ok
19:55:55.0312 3280 napagent (0102140028fad045756796e1c685d695) I:\WINDOWS\System32\qagentrt.dll
19:55:55.0437 3280 napagent - ok
19:55:55.0578 3280 NBService (2637f26312ecceeb6f110e95f1ece243) I:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
19:55:55.0625 3280 NBService ( UnsignedFile.Multi.Generic ) - warning
19:55:55.0625 3280 NBService - detected UnsignedFile.Multi.Generic (1)
19:55:55.0703 3280 NDIS (1df7f42665c94b825322fae71721130d) I:\WINDOWS\system32\drivers\NDIS.sys
19:55:55.0828 3280 NDIS - ok
19:55:55.0843 3280 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) I:\WINDOWS\system32\DRIVERS\NdisIP.sys
19:55:55.0984 3280 NdisIP - ok
19:55:56.0031 3280 NdisTapi (0109c4f3850dfbab279542515386ae22) I:\WINDOWS\system32\DRIVERS\ndistapi.sys
19:55:56.0031 3280 NdisTapi - ok
19:55:56.0046 3280 Ndisuio (f927a4434c5028758a842943ef1a3849) I:\WINDOWS\system32\DRIVERS\ndisuio.sys
19:55:56.0171 3280 Ndisuio - ok
19:55:56.0187 3280 NdisWan (edc1531a49c80614b2cfda43ca8659ab) I:\WINDOWS\system32\DRIVERS\ndiswan.sys
19:55:56.0312 3280 NdisWan - ok
19:55:56.0328 3280 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) I:\WINDOWS\system32\drivers\NDProxy.sys
19:55:56.0359 3280 NDProxy - ok
19:55:56.0375 3280 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) I:\WINDOWS\system32\DRIVERS\netbios.sys
19:55:56.0515 3280 NetBIOS - ok
19:55:56.0531 3280 NetBT (c9f5150f13862d5b3c470a966c1f5687) I:\WINDOWS\system32\DRIVERS\netbt.sys
19:55:56.0531 3280 Suspicious file (Forged): I:\WINDOWS\system32\DRIVERS\netbt.sys. Real md5: c9f5150f13862d5b3c470a966c1f5687, Fake md5: 74b2b2f5bea5e9a3dc021d685551bd3d
19:55:56.0531 3280 NetBT ( Virus.Win32.ZAccess.k ) - infected
19:55:56.0531 3280 NetBT - detected Virus.Win32.ZAccess.k (0)
19:55:56.0562 3280 NetDDE (b857ba82860d7ff85ae29b095645563b) I:\WINDOWS\system32\netdde.exe
19:55:56.0703 3280 NetDDE - ok
19:55:56.0718 3280 NetDDEdsdm (b857ba82860d7ff85ae29b095645563b) I:\WINDOWS\system32\netdde.exe
19:55:56.0843 3280 NetDDEdsdm - ok
19:55:56.0859 3280 Netlogon (bf2466b3e18e970d8a976fb95fc1ca85) I:\WINDOWS\system32\lsass.exe
19:55:57.0000 3280 Netlogon - ok
19:55:57.0031 3280 Netman (13e67b55b3abd7bf3fe7aae5a0f9a9de) I:\WINDOWS\System32\netman.dll
19:55:57.0156 3280 Netman - ok
19:55:57.0250 3280 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) I:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
19:55:57.0265 3280 NetTcpPortSharing - ok
19:55:57.0281 3280 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) I:\WINDOWS\system32\DRIVERS\nic1394.sys
19:55:57.0421 3280 NIC1394 - ok
19:55:57.0484 3280 Nla (943337d786a56729263071623bbb9de5) I:\WINDOWS\System32\mswsock.dll
19:55:57.0500 3280 Nla - ok
19:55:57.0515 3280 Npfs (3182d64ae053d6fb034f44b6def8034a) I:\WINDOWS\system32\drivers\Npfs.sys
19:55:57.0640 3280 Npfs - ok
19:55:57.0671 3280 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) I:\WINDOWS\system32\drivers\Ntfs.sys
19:55:57.0812 3280 Ntfs - ok
19:55:57.0828 3280 NtLmSsp (bf2466b3e18e970d8a976fb95fc1ca85) I:\WINDOWS\system32\lsass.exe
19:55:57.0953 3280 NtLmSsp - ok
19:55:57.0984 3280 NtmsSvc (156f64a3345bd23c600655fb4d10bc08) I:\WINDOWS\system32\ntmssvc.dll
19:55:58.0125 3280 NtmsSvc - ok
19:55:58.0156 3280 Null (73c1e1f395918bc2c6dd67af7591a3ad) I:\WINDOWS\system32\drivers\Null.sys
19:55:58.0296 3280 Null - ok
19:55:58.0812 3280 nv (30913cbf518396912e54c2c9f1dd0f09) I:\WINDOWS\system32\DRIVERS\nv4_mini.sys
19:55:59.0093 3280 nv - ok
19:55:59.0187 3280 NVSvc (c0204c1a7a2d2433d48f49e4ecc09ab6) I:\WINDOWS\system32\nvsvc32.exe
19:55:59.0203 3280 NVSvc - ok
19:55:59.0234 3280 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) I:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
19:55:59.0375 3280 NwlnkFlt - ok
19:55:59.0390 3280 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) I:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
19:55:59.0515 3280 NwlnkFwd - ok
19:55:59.0656 3280 odserv (785f487a64950f3cb8e9f16253ba3b7b) I:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
19:55:59.0687 3280 odserv - ok
19:55:59.0734 3280 ohci1394 (ca33832df41afb202ee7aeb05145922f) I:\WINDOWS\system32\DRIVERS\ohci1394.sys
19:55:59.0890 3280 ohci1394 - ok
19:55:59.0937 3280 ose (5a432a042dae460abe7199b758e8606c) I:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
19:55:59.0953 3280 ose - ok
19:55:59.0968 3280 Parport (5575faf8f97ce5e713d108c2a58d7c7c) I:\WINDOWS\system32\drivers\Parport.sys
19:56:00.0109 3280 Parport - ok
19:56:00.0125 3280 PartMgr (beb3ba25197665d82ec7065b724171c6) I:\WINDOWS\system32\drivers\PartMgr.sys
19:56:00.0250 3280 PartMgr - ok
19:56:00.0296 3280 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) I:\WINDOWS\system32\drivers\ParVdm.sys
19:56:00.0437 3280 ParVdm - ok
19:56:00.0437 3280 PCI (a219903ccf74233761d92bef471a07b1) I:\WINDOWS\system32\DRIVERS\pci.sys
19:56:00.0578 3280 PCI - ok
19:56:00.0578 3280 PCIDump - ok
19:56:00.0625 3280 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) I:\WINDOWS\system32\DRIVERS\pciide.sys
19:56:00.0750 3280 PCIIde - ok
19:56:00.0765 3280 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) I:\WINDOWS\system32\drivers\Pcmcia.sys
19:56:00.0890 3280 Pcmcia - ok
19:56:00.0906 3280 PDCOMP - ok
19:56:00.0906 3280 PDFRAME - ok
19:56:00.0937 3280 PdiPorts (089ca80ce0766b031164714b51df99bb) I:\WINDOWS\system32\Drivers\PdiPorts.sys
19:56:00.0953 3280 PdiPorts - ok
19:56:01.0000 3280 PdiService (0a098df98ec8facaa30bd7db4c7aea06) I:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
19:56:01.0015 3280 PdiService - ok
19:56:01.0015 3280 PDRELI - ok
19:56:01.0015 3280 PDRFRAME - ok
19:56:01.0031 3280 perc2 - ok
19:56:01.0031 3280 perc2hib - ok
19:56:01.0109 3280 pgfilter (79bad6756154335d5304f0fe39961f5b) I:\Program Files\PeerGuardian2\pgfilter.sys
19:56:01.0109 3280 pgfilter ( UnsignedFile.Multi.Generic ) - warning
19:56:01.0109 3280 pgfilter - detected UnsignedFile.Multi.Generic (1)
19:56:01.0140 3280 Pivot (ec4f52692b5cf116ca6b0428d84a9aba) I:\WINDOWS\system32\drivers\pivot.sys
19:56:01.0156 3280 Pivot ( UnsignedFile.Multi.Generic ) - warning
19:56:01.0156 3280 Pivot - detected UnsignedFile.Multi.Generic (1)
19:56:01.0187 3280 pivotmou (7d72ac1abda06ff42fd57345d0d75523) I:\WINDOWS\System32\drivers\pivotmou.sys
19:56:01.0187 3280 pivotmou ( UnsignedFile.Multi.Generic ) - warning
19:56:01.0187 3280 pivotmou - detected UnsignedFile.Multi.Generic (1)
19:56:01.0218 3280 PlugPlay (65df52f5b8b6e9bbd183505225c37315) I:\WINDOWS\system32\services.exe
19:56:01.0234 3280 PlugPlay - ok
19:56:01.0265 3280 PolicyAgent (bf2466b3e18e970d8a976fb95fc1ca85) I:\WINDOWS\system32\lsass.exe
19:56:01.0390 3280 PolicyAgent - ok
19:56:01.0406 3280 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) I:\WINDOWS\system32\DRIVERS\raspptp.sys
19:56:01.0546 3280 PptpMiniport - ok
19:56:01.0546 3280 ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) I:\WINDOWS\system32\lsass.exe
19:56:01.0671 3280 ProtectedStorage - ok
19:56:01.0687 3280 PSched (09298ec810b07e5d582cb3a3f9255424) I:\WINDOWS\system32\DRIVERS\psched.sys
19:56:01.0812 3280 PSched - ok
19:56:01.0859 3280 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) I:\WINDOWS\system32\DRIVERS\ptilink.sys
19:56:01.0984 3280 Ptilink - ok
19:56:02.0015 3280 PxHelp20 (153d02480a0a2f45785522e814c634b6) I:\WINDOWS\system32\DRIVERS\PxHelp20.sys
19:56:02.0031 3280 PxHelp20 - ok
19:56:02.0031 3280 ql1080 - ok
19:56:02.0031 3280 Ql10wnt - ok
19:56:02.0046 3280 ql12160 - ok
19:56:02.0046 3280 ql1240 - ok
19:56:02.0046 3280 ql1280 - ok
19:56:02.0062 3280 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) I:\WINDOWS\system32\DRIVERS\rasacd.sys
19:56:02.0187 3280 RasAcd - ok
19:56:02.0187 3280 RasAuto (ad188be7bdf94e8df4ca0a55c00a5073) I:\WINDOWS\System32\rasauto.dll
19:56:02.0328 3280 RasAuto - ok
19:56:02.0328 3280 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) I:\WINDOWS\system32\DRIVERS\rasl2tp.sys
19:56:02.0468 3280 Rasl2tp - ok
19:56:02.0484 3280 RasMan (76a9a3cbeadd68cc57cda5e1d7448235) I:\WINDOWS\System32\rasmans.dll
19:56:02.0609 3280 RasMan - ok
19:56:02.0625 3280 RasPppoe (5bc962f2654137c9909c3d4603587dee) I:\WINDOWS\system32\DRIVERS\raspppoe.sys
19:56:02.0765 3280 RasPppoe - ok
19:56:02.0765 3280 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) I:\WINDOWS\system32\DRIVERS\raspti.sys
19:56:02.0890 3280 Raspti - ok
19:56:02.0921 3280 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) I:\WINDOWS\system32\DRIVERS\rdbss.sys
19:56:03.0062 3280 Rdbss - ok
19:56:03.0062 3280 RDPCDD (4912d5b403614ce99c28420f75353332) I:\WINDOWS\system32\DRIVERS\RDPCDD.sys
19:56:03.0203 3280 RDPCDD - ok
19:56:03.0218 3280 rdpdr (15cabd0f7c00c47c70124907916af3f1) I:\WINDOWS\system32\DRIVERS\rdpdr.sys
19:56:03.0343 3280 rdpdr - ok
19:56:03.0406 3280 RDPWD (6589db6e5969f8eee594cf71171c5028) I:\WINDOWS\system32\drivers\RDPWD.sys
19:56:03.0437 3280 RDPWD - ok
19:56:03.0453 3280 RDSessMgr (3c37bf86641bda977c3bf8a840f3b7fa) I:\WINDOWS\system32\sessmgr.exe
19:56:03.0578 3280 RDSessMgr - ok
19:56:03.0593 3280 redbook (f828dd7e1419b6653894a8f97a0094c5) I:\WINDOWS\system32\DRIVERS\redbook.sys
19:56:03.0718 3280 redbook - ok
19:56:03.0734 3280 RemoteAccess (7e699ff5f59b5d9de5390e3c34c67cf5) I:\WINDOWS\System32\mprdim.dll
19:56:03.0875 3280 RemoteAccess - ok
19:56:03.0890 3280 RemoteRegistry (5b19b557b0c188210a56a6b699d90b8f) I:\WINDOWS\system32\regsvc.dll
19:56:04.0031 3280 RemoteRegistry - ok
19:56:04.0031 3280 RpcLocator (aaed593f84afa419bbae8572af87cf6a) I:\WINDOWS\system32\locator.exe
19:56:04.0171 3280 RpcLocator - ok
19:56:04.0234 3280 RpcSs (6b27a5c03dfb94b4245739065431322c) I:\WINDOWS\System32\rpcss.dll
19:56:04.0265 3280 RpcSs - ok
19:56:04.0312 3280 RSVP (471b3f9741d762abe75e9deea4787e47) I:\WINDOWS\system32\rsvp.exe
19:56:04.0453 3280 RSVP - ok
19:56:04.0484 3280 RTLE8023xp (0c57c0f776361b155b00d245c99b41f6) I:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
19:56:04.0562 3280 RTLE8023xp - ok
19:56:04.0578 3280 SamSs (bf2466b3e18e970d8a976fb95fc1ca85) I:\WINDOWS\system32\lsass.exe
19:56:04.0703 3280 SamSs - ok
19:56:04.0796 3280 SASDIFSV (d96686fca1f9f6b06f7490553cbda6de) I:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
19:56:04.0812 3280 SASDIFSV ( UnsignedFile.Multi.Generic ) - warning
19:56:04.0812 3280 SASDIFSV - detected UnsignedFile.Multi.Generic (1)
19:56:04.0843 3280 SASENUM (7f1085895e499907f68df7731924122b) I:\Program Files\SUPERAntiSpyware\SASENUM.SYS
19:56:04.0843 3280 SASENUM ( UnsignedFile.Multi.Generic ) - warning
19:56:04.0843 3280 SASENUM - detected UnsignedFile.Multi.Generic (1)
19:56:04.0859 3280 SASKUTIL (2e0e10b8b547a39cdcc1b105239a43a4) I:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
19:56:04.0859 3280 SASKUTIL ( UnsignedFile.Multi.Generic ) - warning
19:56:04.0859 3280 SASKUTIL - detected UnsignedFile.Multi.Generic (1)
19:56:04.0875 3280 SCardSvr (86d007e7a654b9a71d1d7d856b104353) I:\WINDOWS\System32\SCardSvr.exe
19:56:05.0015 3280 SCardSvr - ok
19:56:05.0031 3280 Schedule (0a9a7365a1ca4319aa7c1d6cd8e4eafa) I:\WINDOWS\system32\schedsvc.dll
19:56:05.0171 3280 Schedule - ok
19:56:05.0203 3280 Secdrv (90a3935d05b494a5a39d37e71f09a677) I:\WINDOWS\system32\DRIVERS\secdrv.sys
19:56:05.0281 3280 Secdrv - ok
19:56:05.0281 3280 seclogon (cbe612e2bb6a10e3563336191eda1250) I:\WINDOWS\System32\seclogon.dll
19:56:05.0406 3280 seclogon - ok
19:56:05.0421 3280 SENS (7fdd5d0684eca8c1f68b4d99d124dcd0) I:\WINDOWS\system32\sens.dll
19:56:05.0546 3280 SENS - ok
19:56:05.0593 3280 Sentinel (b3c1b187fefc941f63ce0df93d02eb9f) I:\WINDOWS\System32\Drivers\SENTINEL.SYS
19:56:05.0593 3280 Sentinel - ok
19:56:05.0609 3280 serenum (0f29512ccd6bead730039fb4bd2c85ce) I:\WINDOWS\system32\DRIVERS\serenum.sys
19:56:05.0734 3280 serenum - ok
19:56:05.0750 3280 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) I:\WINDOWS\system32\DRIVERS\serial.sys
19:56:05.0875 3280 Serial - ok
19:56:05.0890 3280 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) I:\WINDOWS\system32\drivers\Sfloppy.sys
19:56:06.0031 3280 Sfloppy - ok
19:56:06.0062 3280 ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) I:\WINDOWS\System32\shsvcs.dll
19:56:06.0078 3280 ShellHWDetection - ok
19:56:06.0078 3280 Simbad - ok
19:56:06.0125 3280 SLIP (866d538ebe33709a5c9f5c62b73b7d14) I:\WINDOWS\system32\DRIVERS\SLIP.sys
19:56:06.0250 3280 SLIP - ok
19:56:06.0781 3280 SNP325 (ff2f9204e0542f1bf09b161822fb7556) I:\WINDOWS\system32\DRIVERS\snp325.sys
19:56:07.0062 3280 SNP325 ( UnsignedFile.Multi.Generic ) - warning
19:56:07.0062 3280 SNP325 - detected UnsignedFile.Multi.Generic (1)
19:56:07.0218 3280 SolidWorks Licensing Service (4945020bc094c322571184a6e8056b3a) I:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
19:56:07.0234 3280 SolidWorks Licensing Service ( UnsignedFile.Multi.Generic ) - warning
19:56:07.0234 3280 SolidWorks Licensing Service - detected UnsignedFile.Multi.Generic (1)
19:56:07.0312 3280 Sony Ericsson PCCompanion (1a623f2b69e1f182f995f963c55db935) I:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
19:56:07.0328 3280 Sony Ericsson PCCompanion - ok
19:56:07.0406 3280 Sparrow - ok
19:56:07.0453 3280 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) I:\WINDOWS\system32\drivers\splitter.sys
19:56:07.0593 3280 splitter - ok
19:56:07.0625 3280 Spooler (60784f891563fb1b767f70117fc2428f) I:\WINDOWS\system32\spoolsv.exe
19:56:07.0671 3280 Spooler - ok
19:56:07.0750 3280 sptd (d390675b8ce45e5fb359338e5e649329) I:\WINDOWS\system32\Drivers\sptd.sys
19:56:07.0750 3280 Suspicious file (NoAccess): I:\WINDOWS\system32\Drivers\sptd.sys. md5: d390675b8ce45e5fb359338e5e649329
19:56:07.0750 3280 sptd ( LockedFile.Multi.Generic ) - warning
19:56:07.0750 3280 sptd - detected LockedFile.Multi.Generic (1)
19:56:07.0765 3280 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) I:\WINDOWS\system32\DRIVERS\sr.sys
19:56:07.0843 3280 sr - ok
19:56:07.0906 3280 srservice (3805df0ac4296a34ba4bf93b346cc378) I:\WINDOWS\system32\srsvc.dll
19:56:07.0968 3280 srservice - ok
19:56:08.0015 3280 Srv (47ddfc2f003f7f9f0592c6874962a2e7) I:\WINDOWS\system32\DRIVERS\srv.sys
19:56:08.0062 3280 Srv - ok
19:56:08.0109 3280 SSDPSRV (0a5679b3714edab99e357057ee88fca6) I:\WINDOWS\System32\ssdpsrv.dll
19:56:08.0187 3280 SSDPSRV - ok
19:56:08.0234 3280 stisvc (8bad69cbac032d4bbacfce0306174c30) I:\WINDOWS\system32\wiaservc.dll
19:56:08.0375 3280 stisvc - ok
19:56:08.0406 3280 streamip (77813007ba6265c4b6098187e6ed79d2) I:\WINDOWS\system32\DRIVERS\StreamIP.sys
19:56:08.0531 3280 streamip - ok
19:56:08.0546 3280 swenum (3941d127aef12e93addf6fe6ee027e0f) I:\WINDOWS\system32\DRIVERS\swenum.sys
19:56:08.0671 3280 swenum - ok
19:56:08.0687 3280 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) I:\WINDOWS\system32\drivers\swmidi.sys
19:56:08.0812 3280 swmidi - ok
19:56:08.0828 3280 SwPrv - ok
19:56:08.0828 3280 symc810 - ok
19:56:08.0828 3280 symc8xx - ok
19:56:08.0843 3280 sym_hi - ok
19:56:08.0843 3280 sym_u3 - ok
19:56:08.0859 3280 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) I:\WINDOWS\system32\drivers\sysaudio.sys
19:56:08.0984 3280 sysaudio - ok
19:56:09.0000 3280 SysmonLog (c7abbc59b43274b1109df6b24d617051) I:\WINDOWS\system32\smlogsvc.exe
19:56:09.0125 3280 SysmonLog - ok
19:56:09.0140 3280 TapiSrv (3cb78c17bb664637787c9a1c98f79c38) I:\WINDOWS\System32\tapisrv.dll
19:56:09.0281 3280 TapiSrv - ok
19:56:09.0359 3280 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) I:\WINDOWS\system32\DRIVERS\tcpip.sys
19:56:09.0375 3280 Tcpip - ok
19:56:09.0421 3280 TDPIPE (6471a66807f5e104e4885f5b67349397) I:\WINDOWS\system32\drivers\TDPIPE.sys
19:56:09.0546 3280 TDPIPE - ok
19:56:09.0578 3280 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) I:\WINDOWS\system32\drivers\TDTCP.sys
19:56:09.0703 3280 TDTCP - ok
19:56:09.0859 3280 Tekla Structures Licensing Service (6fac4e9e361383c8b8d93da0c3722619) I:\TeklaStructures\License\Server\lmgrd.exe
19:56:09.0921 3280 Tekla Structures Licensing Service - ok
19:56:09.0953 3280 TermDD (88155247177638048422893737429d9e) I:\WINDOWS\system32\DRIVERS\termdd.sys
19:56:10.0078 3280 TermDD - ok
19:56:10.0109 3280 TermService (ff3477c03be7201c294c35f684b3479f) I:\WINDOWS\System32\termsrv.dll
19:56:10.0250 3280 TermService - ok
19:56:10.0265 3280 Themes (99bc0b50f511924348be19c7c7313bbf) I:\WINDOWS\System32\shsvcs.dll
19:56:10.0281 3280 Themes - ok
19:56:10.0312 3280 TlntSvr (db7205804759ff62c34e3efd8a4cc76a) I:\WINDOWS\system32\tlntsvr.exe
19:56:10.0390 3280 TlntSvr - ok
19:56:10.0390 3280 TosIde - ok
19:56:10.0406 3280 TrkWks (55bca12f7f523d35ca3cb833c725f54e) I:\WINDOWS\system32\trkwks.dll
19:56:10.0546 3280 TrkWks - ok
19:56:10.0578 3280 TrueSight (b3c9c35dc93563b8d19ad414edf2fc82) i:\windows\system32\drivers\TrueSight.sys
19:56:10.0578 3280 TrueSight ( UnsignedFile.Multi.Generic ) - warning
19:56:10.0578 3280 TrueSight - detected UnsignedFile.Multi.Generic (1)
19:56:10.0593 3280 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) I:\WINDOWS\system32\drivers\Udfs.sys
19:56:10.0718 3280 Udfs - ok
19:56:10.0734 3280 ultra - ok
19:56:10.0750 3280 Update (402ddc88356b1bac0ee3dd1580c76a31) I:\WINDOWS\system32\DRIVERS\update.sys
19:56:10.0906 3280 Update - ok
19:56:10.0921 3280 upnphost (1ebafeb9a3fbdc41b8d9c7f0f687ad91) I:\WINDOWS\System32\upnphost.dll
19:56:11.0000 3280 upnphost - ok
19:56:11.0015 3280 UPS (05365fb38fca1e98f7a566aaaf5d1815) I:\WINDOWS\System32\ups.exe
19:56:11.0140 3280 UPS - ok
19:56:11.0203 3280 usbccgp (173f317ce0db8e21322e71b7e60a27e8) I:\WINDOWS\system32\DRIVERS\usbccgp.sys
19:56:11.0328 3280 usbccgp - ok
19:56:11.0343 3280 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) I:\WINDOWS\system32\DRIVERS\usbehci.sys
19:56:11.0484 3280 usbehci - ok
19:56:11.0515 3280 usbhub (1ab3cdde553b6e064d2e754efe20285c) I:\WINDOWS\system32\DRIVERS\usbhub.sys
19:56:11.0656 3280 usbhub - ok
19:56:11.0671 3280 usbprint (a717c8721046828520c9edf31288fc00) I:\WINDOWS\system32\DRIVERS\usbprint.sys
19:56:11.0796 3280 usbprint - ok
19:56:11.0828 3280 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) I:\WINDOWS\system32\DRIVERS\usbscan.sys
19:56:11.0953 3280 usbscan - ok
19:56:11.0968 3280 usbser (1c888b000c2f9492f4b15b5b6b84873e) I:\WINDOWS\system32\DRIVERS\usbser.sys
19:56:12.0093 3280 usbser - ok
19:56:12.0125 3280 usbstor (a32426d9b14a089eaa1d922e0c5801a9) I:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
19:56:12.0265 3280 usbstor - ok
19:56:12.0281 3280 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) I:\WINDOWS\system32\DRIVERS\usbuhci.sys
19:56:12.0406 3280 usbuhci - ok
19:56:12.0421 3280 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) I:\WINDOWS\System32\drivers\vga.sys
19:56:12.0562 3280 VgaSave - ok
19:56:12.0562 3280 ViaIde - ok
19:56:12.0578 3280 VolSnap (4c8fcb5cc53aab716d810740fe59d025) I:\WINDOWS\system32\drivers\VolSnap.sys
19:56:12.0703 3280 VolSnap - ok
19:56:12.0718 3280 VSS (7a9db3a67c333bf0bd42e42b8596854b) I:\WINDOWS\System32\vssvc.exe
19:56:12.0796 3280 VSS - ok
19:56:12.0812 3280 W32Time (54af4b1d5459500ef0937f6d33b1914f) I:\WINDOWS\system32\w32time.dll
19:56:12.0953 3280 W32Time - ok
19:56:12.0968 3280 Wanarp (e20b95baedb550f32dd489265c1da1f6) I:\WINDOWS\system32\DRIVERS\wanarp.sys
19:56:13.0093 3280 Wanarp - ok
19:56:13.0093 3280 WDICA - ok
19:56:13.0109 3280 wdmaud (6768acf64b18196494413695f0c3a00f) I:\WINDOWS\system32\drivers\wdmaud.sys
19:56:13.0250 3280 wdmaud - ok
19:56:13.0265 3280 WebClient (77a354e28153ad2d5e120a5a8687bc06) I:\WINDOWS\System32\webclnt.dll
19:56:13.0406 3280 WebClient - ok
19:56:13.0515 3280 winmgmt (2d0e4ed081963804ccc196a0929275b5) I:\WINDOWS\system32\wbem\WMIsvc.dll
19:56:13.0640 3280 winmgmt - ok
19:56:13.0703 3280 WmdmPmSN (c51b4a5c05a5475708e3c81c7765b71d) I:\WINDOWS\system32\MsPMSNSv.dll
19:56:13.0718 3280 WmdmPmSN - ok
19:56:13.0812 3280 Wmi (e76f8807070ed04e7408a86d6d3a6137) I:\WINDOWS\System32\advapi32.dll
19:56:13.0875 3280 Wmi - ok
19:56:13.0890 3280 WmiApSrv (e0673f1106e62a68d2257e376079f821) I:\WINDOWS\system32\wbem\wmiapsrv.exe
19:56:14.0015 3280 WmiApSrv - ok
19:56:14.0031 3280 WpdUsb (cf4def1bf66f06964dc0d91844239104) I:\WINDOWS\system32\DRIVERS\wpdusb.sys
19:56:14.0046 3280 WpdUsb - ok
19:56:14.0187 3280 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) I:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
19:56:14.0234 3280 WPFFontCache_v0400 - ok
19:56:14.0265 3280 WSTCODEC (c98b39829c2bbd34e454150633c62c78) I:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
19:56:14.0406 3280 WSTCODEC - ok
19:56:14.0437 3280 wuauserv (35321fb577cdc98ce3eb3a3eb9e4610a) I:\WINDOWS\system32\wuauserv.dll
19:56:14.0562 3280 wuauserv - ok
19:56:14.0609 3280 WudfPf (f15feafffbb3644ccc80c5da584e6311) I:\WINDOWS\system32\DRIVERS\WudfPf.sys
19:56:14.0640 3280 WudfPf - ok
19:56:14.0656 3280 WudfRd (28b524262bce6de1f7ef9f510ba3985b) I:\WINDOWS\system32\DRIVERS\wudfrd.sys
19:56:14.0671 3280 WudfRd - ok
19:56:14.0718 3280 WudfSvc (05231c04253c5bc30b26cbaae680ed89) I:\WINDOWS\System32\WUDFSvc.dll
19:56:14.0734 3280 WudfSvc - ok
19:56:14.0812 3280 WZCSVC (81dc3f549f44b1c1fff022dec9ecf30b) I:\WINDOWS\System32\wzcsvc.dll
19:56:14.0953 3280 WZCSVC - ok
19:56:14.0968 3280 xmlprov (295d21f14c335b53cb8154e5b1f892b9) I:\WINDOWS\System32\xmlprov.dll
19:56:15.0109 3280 xmlprov - ok
19:56:15.0171 3280 {95808DC4-FA4A-4c74-92FE-5B863F82066B} - ok
19:56:15.0187 3280 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
19:56:15.0828 3280 \Device\Harddisk0\DR0 - ok
19:56:15.0828 3280 Boot (0x1200) (cd223fc117c418012ed2692796cd2eae) \Device\Harddisk0\DR0\Partition0
19:56:15.0843 3280 \Device\Harddisk0\DR0\Partition0 - ok
19:56:15.0843 3280 Boot (0x1200) (f02d3a63d0b86e984860163adc512203) \Device\Harddisk0\DR0\Partition1
19:56:15.0843 3280 \Device\Harddisk0\DR0\Partition1 - ok
19:56:15.0859 3280 Boot (0x1200) (c4aac9a7ec8c05e07eeb3c8c123ce0b8) \Device\Harddisk0\DR0\Partition2
19:56:15.0859 3280 \Device\Harddisk0\DR0\Partition2 - ok
19:56:15.0859 3280 ============================================================
19:56:15.0859 3280 Scan finished
19:56:15.0859 3280 ============================================================
19:56:15.0968 3276 Detected object count: 18
19:56:15.0968 3276 Actual detected object count: 18
19:56:52.0328 3276 Aspi32 ( UnsignedFile.Multi.Generic ) - skipped by user
19:56:52.0328 3276 Aspi32 ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:56:52.0328 3276 C-Dilla ( UnsignedFile.Multi.Generic ) - skipped by user
19:56:52.0328 3276 C-Dilla ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:56:52.0328 3276 C-DillaSrv ( UnsignedFile.Multi.Generic ) - skipped by user
19:56:52.0328 3276 C-DillaSrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:56:52.0328 3276 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
19:56:52.0328 3276 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:56:52.0328 3276 imagedrv ( UnsignedFile.Multi.Generic ) - skipped by user
19:56:52.0328 3276 imagedrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:56:52.0328 3276 imagesrv ( UnsignedFile.Multi.Generic ) - skipped by user
19:56:52.0328 3276 imagesrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:56:52.0328 3276 NBService ( UnsignedFile.Multi.Generic ) - skipped by user
19:56:52.0328 3276 NBService ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:56:52.0359 3276 I:\WINDOWS\system32\DRIVERS\netbt.sys - copied to quarantine
19:56:52.0437 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\@ - copied to quarantine
19:56:52.0437 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\Desktop.ini - copied to quarantine
19:56:52.0437 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\L\00000004.@ - copied to quarantine
19:56:52.0437 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\L\00000008.@ - copied to quarantine
19:56:52.0468 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\L\umixxwkm - copied to quarantine
19:56:52.0500 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\U\00000004.@ - copied to quarantine
19:56:52.0515 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\U\00000008.@ - copied to quarantine
19:56:52.0546 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\U\000000cb.@ - copied to quarantine
19:56:52.0546 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\U\80000000.@ - copied to quarantine
19:56:52.0562 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\U\80000032.@ - copied to quarantine
19:56:52.0796 3276 Backup copy found, using it..
19:56:52.0843 3276 I:\WINDOWS\system32\DRIVERS\netbt.sys - will be cured on reboot
19:56:53.0859 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\@ - will be deleted on reboot
19:56:53.0859 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\Desktop.ini - will be deleted on reboot
19:56:53.0875 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\U\00000004.@ - will be deleted on reboot
19:56:53.0875 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\U\00000008.@ - will be deleted on reboot
19:56:53.0875 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\U\000000cb.@ - will be deleted on reboot
19:56:53.0875 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\U\80000000.@ - will be deleted on reboot
19:56:53.0875 3276 I:\WINDOWS\$NtUninstallKB41124$\1205135216\U\80000032.@ - will be deleted on reboot
19:56:53.0875 3276 I:\WINDOWS\$NtUninstallKB41124$\791209367 - will be deleted on reboot
19:56:53.0875 3276 NetBT ( Virus.Win32.ZAccess.k ) - User select action: Cure
19:56:53.0875 3276 pgfilter ( UnsignedFile.Multi.Generic ) - skipped by user
19:56:53.0875 3276 pgfilter ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:56:53.0875 3276 Pivot ( UnsignedFile.Multi.Generic ) - skipped by user
19:56:53.0875 3276 Pivot ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:56:53.0875 3276 pivotmou ( UnsignedFile.Multi.Generic ) - skipped by user
19:56:53.0875 3276 pivotmou ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:56:53.0875 3276 SASDIFSV ( UnsignedFile.Multi.Generic ) - skipped by user
19:56:53.0875 3276 SASDIFSV ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:56:53.0875 3276 SASENUM ( UnsignedFile.Multi.Generic ) - skipped by user
19:56:53.0875 3276 SASENUM ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:56:53.0875 3276 SASKUTIL ( UnsignedFile.Multi.Generic ) - skipped by user
19:56:53.0875 3276 SASKUTIL ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:56:53.0875 3276 SNP325 ( UnsignedFile.Multi.Generic ) - skipped by user
19:56:53.0875 3276 SNP325 ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:56:53.0875 3276 SolidWorks Licensing Service ( UnsignedFile.Multi.Generic ) - skipped by user
19:56:53.0875 3276 SolidWorks Licensing Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:56:53.0875 3276 sptd ( LockedFile.Multi.Generic ) - skipped by user
19:56:53.0875 3276 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
19:56:53.0875 3276 TrueSight ( UnsignedFile.Multi.Generic ) - skipped by user
19:56:53.0875 3276 TrueSight ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:57:01.0031 2396 Deinitialize success

Re: Prajem pekný deň

Napsal: 09 črc 2012 19:38
od vyosek
:arrow: Slozku RK_Quarantine zatim nechte, tak jako ostatni nove slozky - jsou to zalohy programu - na konci leceni je smazeme

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: Prajem pekný deň

Napsal: 09 črc 2012 20:13
od mogon
Prikladam log z CF:

ComboFix 12-07-08.02 - Mogon 09.07.2012 21:04:44.3.8 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.420.1033.18.3326.2925 [GMT 2:00]
Running from: i:\documents and settings\Mogon\Desktop\liecenie\ComboFix.exe
FW: ZoneAlarm Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
i:\documents and settings\All Users\Application Data\TEMP
i:\documents and settings\All Users\Application Data\TEMP\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\PostBuild.exe
i:\documents and settings\Mogon\WINDOWS
i:\windows\iun6002.exe
i:\windows\pkunzip.pif
i:\windows\pkzip.pif
i:\windows\system32\_000011_.tmp.dll
i:\windows\system32\_000012_.tmp.dll
i:\windows\system32\_000014_.tmp.dll
i:\windows\system32\CCXPButton.ocx
i:\windows\system32\dllcache\dlimport.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-06-09 to 2012-07-09 )))))))))))))))))))))))))))))))
.
.
2012-07-09 17:56 . 2012-07-09 17:56 -------- d-----w- I:\TDSSKiller_Quarantine
2012-07-09 17:35 . 2012-07-09 17:49 14080 ----a-w- i:\windows\system32\drivers\TrueSight.sys
2012-06-19 19:08 . 2012-06-19 19:08 -------- d-----w- i:\documents and settings\Mogon\Application Data\ICQ Search
2012-06-19 19:08 . 2012-06-19 19:08 -------- d-----w- i:\program files\ICQ6Toolbar
2012-06-19 19:08 . 2012-06-19 19:08 -------- d-----w- i:\program files\Guard-ICQ
2012-06-19 19:08 . 2012-06-19 19:08 -------- d-----w- i:\documents and settings\All Users\Application Data\ICQ
2012-06-19 19:07 . 2012-06-19 19:09 -------- d-----w- i:\program files\ICQ7M
2012-06-14 17:04 . 2012-05-11 14:42 521728 -c----w- i:\windows\system32\dllcache\jsdbgui.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-09 19:03 . 2009-05-29 19:30 16608 ----a-w- i:\windows\gdrv.sys
2012-07-09 17:57 . 2004-08-03 21:14 162816 ----a-w- i:\windows\system32\drivers\netbt.sys
2012-07-09 16:53 . 2012-04-03 15:12 419488 ----a-w- i:\windows\system32\FlashPlayerApp.exe
2012-07-09 16:53 . 2011-09-13 14:34 70304 ----a-w- i:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-02 13:19 . 2008-10-16 12:09 22040 ----a-w- i:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2009-05-29 16:41 329240 ----a-w- i:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2009-05-29 16:41 219160 ----a-w- i:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2009-05-29 16:41 210968 ----a-w- i:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2008-10-16 12:07 15384 ----a-w- i:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2009-05-29 16:41 35864 ----a-w- i:\windows\system32\wups.dll
2012-06-02 13:19 . 2009-05-29 16:41 53784 ----a-w- i:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2008-10-16 12:09 45080 ----a-w- i:\windows\system32\wups2.dll
2012-06-02 13:19 . 2008-10-16 12:07 15384 ----a-w- i:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2004-08-03 22:56 97304 ----a-w- i:\windows\system32\cdm.dll
2012-06-02 13:19 . 2008-10-16 12:07 17944 ----a-w- i:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2009-05-29 16:41 577048 ----a-w- i:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2009-05-29 16:41 1933848 ----a-w- i:\windows\system32\wuaueng.dll
2012-06-02 13:18 . 2012-04-01 06:49 275696 ----a-w- i:\windows\system32\mucltui.dll
2012-06-02 13:18 . 2012-04-01 06:49 214256 ----a-w- i:\windows\system32\muweb.dll
2012-06-02 13:18 . 2012-04-01 06:49 17136 ----a-w- i:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2004-08-03 22:56 599040 ----a-w- i:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2004-08-03 22:56 916992 ----a-w- i:\windows\system32\wininet.dll
2012-05-15 13:20 . 2004-08-03 21:17 1863168 ----a-w- i:\windows\system32\win32k.sys
2012-05-11 14:42 . 2004-08-03 22:56 1469440 ------w- i:\windows\system32\inetcpl.cpl
2012-05-11 14:42 . 2004-08-03 22:56 43520 ----a-w- i:\windows\system32\licmgr10.dll
2012-05-11 11:38 . 2004-08-03 20:59 385024 ----a-w- i:\windows\system32\html.iec
2012-05-06 06:06 . 2012-05-06 06:06 73728 ----a-w- i:\windows\system32\javacpl.cpl
2012-05-06 06:06 . 2012-05-06 06:06 476960 ----a-w- i:\windows\system32\npdeployJava1.dll
2012-05-06 06:06 . 2012-05-06 06:06 472864 ----a-w- i:\windows\system32\deployJava1.dll
2012-05-04 13:16 . 2004-08-03 21:18 2148352 ----a-w- i:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2004-08-03 22:59 2026496 ----a-w- i:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2009-05-29 16:39 139656 ----a-w- i:\windows\system32\drivers\rdpwd.sys
2012-06-16 18:52 . 2011-04-30 21:15 85472 ----a-w- i:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="i:\program files\PeerGuardian2\pg2.exe" [2005-09-18 1421824]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-23 16804864]
"SoundMan"="SOUNDMAN.EXE" [2008-06-18 77824]
"AlcWzrd"="ALCWZRD.EXE" [2008-06-19 2808832]
"JMB36X IDE Setup"="i:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"tsnp325"="i:\windows\tsnp325.exe" [2007-04-21 270336]
"snp325"="i:\windows\vsnp325.exe" [2007-05-10 835584]
"NvMediaCenter"="i:\windows\system32\NvMcTray.dll" [2010-04-03 110696]
"NvCplDaemon"="i:\windows\system32\NvCpl.dll" [2010-04-03 13670504]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="i:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "i:\program files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-02-27 09:39 282624 ----a-w- i:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKLM\~\startupfolder\I:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=i:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=i:\windows\pss\Windows Desktop Search.lnkCommon Startup
.
[HKLM\~\startupfolder\I:^Documents and Settings^Mogon^Start Menu^Programs^Startup^GIGABYTE Gamer HUD.lnk]
path=i:\documents and settings\Mogon\Start Menu\Programs\Startup\GIGABYTE Gamer HUD.lnk
backup=i:\windows\pss\GIGABYTE Gamer HUD.lnkStartup
.
[HKLM\~\startupfolder\I:^Documents and Settings^Mogon^Start Menu^Programs^Startup^SolidWorks Task Scheduler Engine.lnk]
path=i:\documents and settings\Mogon\Start Menu\Programs\Startup\SolidWorks Task Scheduler Engine.lnk
backup=i:\windows\pss\SolidWorks Task Scheduler Engine.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-02 09:07 843712 ----a-r- i:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-03-27 12:41 37296 ----a-w- i:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DT PLP]
2010-05-17 11:03 121456 ----a-w- i:\program files\Common Files\Portrait Displays\Shared\DT_Startup.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Guard.Mail.ru.gui]
2012-06-19 19:08 1564368 ----a-w- i:\program files\Guard-ICQ\GuardICQ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2012-06-19 19:08 127040 ----a-w- i:\program files\ICQ7M\ICQ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PivotSoftware]
2010-05-13 15:34 110192 ----a-w- i:\program files\Portrait Displays\Pivot Pro Plugin\pivot_Startup.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Companion]
2011-07-25 09:41 433360 ----a-w- i:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-18 12:02 254696 ----a-w- i:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2003-12-13 00:50 33792 ----a-w- i:\program files\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
R0 sptd;sptd;i:\windows\system32\drivers\sptd.sys [24.12.2010 14:20 685816]
R1 SASDIFSV;SASDIFSV;i:\program files\SUPERAntiSpyware\sasdifsv.sys [10.10.2006 12:53 5632]
R1 SASKUTIL;SASKUTIL;i:\program files\SUPERAntiSpyware\SASKUTIL.SYS [27.2.2007 11:39 32256]
R2 Guard.Mail.ru;Guard.Mail.ru;i:\program files\Guard-ICQ\GuardICQ.exe [19.6.2012 21:08 1564368]
R2 PdiService;Portrait Displays SDK Service;i:\program files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [24.1.2012 18:35 109168]
R2 Tekla Structures Licensing Service;Tekla Structures Licensing Service;i:\teklastructures\License\Server\lmgrd.exe [12.7.2010 10:11 1377104]
R3 SNP325;USB PC Camera (SNPSTD325);i:\windows\system32\drivers\snp325.sys [3.8.2009 10:16 10394624]
S2 GEST Service;GEST Service for program management.;i:\program files\GIGABYTE\EnergySaver\GSvr.exe [29.5.2009 21:31 68136]
S2 gupdate;Služba Google Update (gupdate);i:\program files\Google\Update\GoogleUpdate.exe [10.9.2011 15:55 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;i:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [3.4.2012 17:12 257696]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;i:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [15.10.2009 7:51 87336]
S3 gupdatem;Služba Google Update (gupdatem);i:\program files\Google\Update\GoogleUpdate.exe [10.9.2011 15:55 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;i:\program files\Mozilla Maintenance Service\maintenanceservice.exe [25.4.2012 9:28 113120]
S3 SASENUM;SASENUM;i:\program files\SUPERAntiSpyware\SASENUM.SYS [16.2.2006 16:51 4096]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;i:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2.9.2011 9:51 155344]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;i:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23.9.2005 8:01 2799808]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-09 i:\windows\Tasks\Adobe Flash Player Updater.job
- i:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 16:53]
.
2012-07-09 i:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- i:\program files\Google\Update\GoogleUpdate.exe [2011-09-10 13:41]
.
2012-07-09 i:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- i:\program files\Google\Update\GoogleUpdate.exe [2011-09-10 13:41]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.mail.ru/cnt/9514
IE: E&xportovať do programu Microsoft Excel - i:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - i:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - i:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - i:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - i:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - i:\program files\ICQ7M\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} - file:///I:/Program%20Files/AutoCAD%202002%20Cz/InstFred.ocx
DPF: {640373B0-6978-4FA5-A9FC-420ECBBC61C7} - file:///C:/_Schodiská,%20Balkóny,%20Zábradlia/Zábr.%20točeného%20bet.%20schodiska/PublicWeb/dll/zkitlib.dll
DPF: {AE563723-B4F5-11D4-A415-00108302FDFD} - file:///I:/Program%20Files/AutoCAD%202002%20Cz/InstBanr.ocx
FF - ProfilePath - i:\documents and settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.5.1&q=
pref('extensions.shownSelectionUI',true);
pref('extensions.autoDisableScopes',0);
.
.
------- File Associations -------
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-27434111.sys
AddRemove-Cool's_Codec_pack_4.12 - i:\windows\iun6002.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-09 21:10
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\i:\program files\CyberLink\PowerDVD\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,6f,41,ab,60,78,17,bc,4e,af,d6,95,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,6f,41,ab,60,78,17,bc,4e,af,d6,95,\
.
[HKEY_USERS\S-1-5-21-746137067-1390067357-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:c0,c2,0e,38,5e,0d,26,7a,5c,61,42,83,71,b9,b9,72,b5,6b,fe,24,8a,
f5,d3,2a,67,cc,9d,25,bc,3b,54,f2,f4,16,fb,d2,0e,03,28,b7,f4,cd,8d,8e,20,e3,\
"rkeysecu"=hex:a5,bc,40,ce,86,26,1c,2d,cf,5b,94,c2,5a,17,81,ce
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(908)
i:\program files\SUPERAntiSpyware\SASWINLO.dll
i:\windows\system32\WININET.dll
.
Completion time: 2012-07-09 21:11:49
ComboFix-quarantined-files.txt 2012-07-09 19:11
.
Pre-Run: 23 209 791 488 bytes free
Post-Run: 23 418 593 280 bytes free
.
- - End Of File - - 2F9D1FE4E30EAE363A5761CA7283C617

Re: Prajem pekný deň

Napsal: 09 črc 2012 20:34
od vyosek
:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    File::
    I:\WINDOWS\tasks\Adobe Flash Player Updater.job
    I:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
    I:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    I:\Documents and Settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\searchplugins\icqplugin.gif
    I:\Documents and Settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\searchplugins\icqplugin.src
    I:\Documents and Settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\searchplugins\icqplugin.xml
    
    Folder::
    I:\Program Files\ICQ6Toolbar
    I:\Program Files\ESET
    I:\Documents and Settings\Mogon\Application Data\ICQ Search
    I:\Program Files\Guard-ICQ
    
    Driver::
    ICQ Service
    Guard.Mail.ru
    gupdate
    gupdatem
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{855F3B16-6D32-4FE6-8A56-BBB695989046}"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DT PLP]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Guard.Mail.ru.gui]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Companion]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\I:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000000
    
    DDS::
    uStart Page = hxxp://www.mail.ru/cnt/9514
    
    Firefox::
    FF - ProfilePath - i:\documents and settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\
    FF - prefs.js: browser.search.selectedEngine - ICQ Search
    FF - prefs.js: browser.startup.homepage - about:home
    FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_result ... r=1.5.1&q=
    pref('extensions.shownSelectionUI',true);
    pref('extensions.autoDisableScopes',0);
    
    RegLock::
    [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
    
    RegNull::
    [HKEY_USERS\S-1-5-21-746137067-1390067357-839522115-1003\Software\SecuROM\License information*]
    
    ClearJavaCache::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

:arrow: Pokud vyskoci hlaska "Pokus pouzit neplatnou operaci na klic registru, ktery je oznacen pro odstraneni", tak jen restartujte PC - registr se da do kupy - jedna se o vnitrni chybu, kterou zpusobuje CF a autor ji zatim neumi bohuzel opravit

Re: Prajem pekný deň

Napsal: 10 črc 2012 16:19
od mogon
Zdravím,

vykonané...prikladám log:

ComboFix 12-07-08.02 - Mogon 10.07.2012 17:07:37.4.8 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.420.1033.18.3326.2929 [GMT 2:00]
Running from: i:\documents and settings\Mogon\Desktop\ComboFix.exe
Command switches used :: i:\documents and settings\Mogon\Desktop\CFScript.txt
FW: ZoneAlarm Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
FILE ::
"i:\documents and settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\searchplugins\icqplugin.gif"
"i:\documents and settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\searchplugins\icqplugin.src"
"i:\documents and settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\searchplugins\icqplugin.xml"
"i:\windows\tasks\Adobe Flash Player Updater.job"
"i:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"i:\windows\tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
i:\documents and settings\Mogon\Application Data\ICQ Search
i:\documents and settings\Mogon\Application Data\ICQ Search\icq_search_shortcut.ico
i:\documents and settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\searchplugins\icqplugin.gif
i:\documents and settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\searchplugins\icqplugin.src
i:\documents and settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\searchplugins\icqplugin.xml
i:\program files\ESET
i:\program files\ESET\ESET NOD32 Antivirus\nod32krn.exe
i:\program files\ESET\ESET Smart Security\em023_32.dat
i:\program files\Guard-ICQ
i:\program files\Guard-ICQ\GuardICQ.exe
i:\program files\ICQ6Toolbar
i:\program files\ICQ6Toolbar\config.xml
i:\program files\ICQ6Toolbar\Icons.bmp
i:\program files\ICQ6Toolbar\ICQ Service.exe
i:\program files\ICQ6Toolbar\icq6Toolbar.ico
i:\program files\ICQ6Toolbar\ICQToolBar.dll
i:\program files\ICQ6Toolbar\ICQUnToolbar.exe
i:\program files\ICQ6Toolbar\logo_small.gif
i:\program files\ICQ6Toolbar\ServiceStarter.exe
i:\program files\ICQ6Toolbar\short.wav
i:\program files\ICQ6Toolbar\Version.txt
i:\program files\ICQ6Toolbar\voucher.bmp
i:\program files\ICQ6Toolbar\voucher2.bmp
i:\windows\tasks\Adobe Flash Player Updater.job
i:\windows\tasks\GoogleUpdateTaskMachineCore.job
i:\windows\tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_GUARD.MAIL.RU
-------\Legacy_GUPDATE
-------\Service_Guard.Mail.ru
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Files Created from 2012-06-10 to 2012-07-10 )))))))))))))))))))))))))))))))
.
.
2012-07-09 17:56 . 2012-07-09 17:56 -------- d-----w- I:\TDSSKiller_Quarantine
2012-07-09 17:35 . 2012-07-09 17:49 14080 ----a-w- i:\windows\system32\drivers\TrueSight.sys
2012-06-19 19:08 . 2012-06-19 19:08 -------- d-----w- i:\documents and settings\All Users\Application Data\ICQ
2012-06-19 19:07 . 2012-06-19 19:09 -------- d-----w- i:\program files\ICQ7M
2012-06-14 17:04 . 2012-05-11 14:42 521728 -c----w- i:\windows\system32\dllcache\jsdbgui.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-10 15:14 . 2009-05-29 19:30 16608 ----a-w- i:\windows\gdrv.sys
2012-07-09 17:57 . 2004-08-03 21:14 162816 ----a-w- i:\windows\system32\drivers\netbt.sys
2012-07-09 16:53 . 2012-04-03 15:12 419488 ----a-w- i:\windows\system32\FlashPlayerApp.exe
2012-07-09 16:53 . 2011-09-13 14:34 70304 ----a-w- i:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-02 13:19 . 2008-10-16 12:09 22040 ----a-w- i:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2009-05-29 16:41 329240 ----a-w- i:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2009-05-29 16:41 219160 ----a-w- i:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2009-05-29 16:41 210968 ----a-w- i:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2008-10-16 12:07 15384 ----a-w- i:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2009-05-29 16:41 35864 ----a-w- i:\windows\system32\wups.dll
2012-06-02 13:19 . 2009-05-29 16:41 53784 ----a-w- i:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2008-10-16 12:09 45080 ----a-w- i:\windows\system32\wups2.dll
2012-06-02 13:19 . 2008-10-16 12:07 15384 ----a-w- i:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2004-08-03 22:56 97304 ----a-w- i:\windows\system32\cdm.dll
2012-06-02 13:19 . 2008-10-16 12:07 17944 ----a-w- i:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2009-05-29 16:41 577048 ----a-w- i:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2009-05-29 16:41 1933848 ----a-w- i:\windows\system32\wuaueng.dll
2012-06-02 13:18 . 2012-04-01 06:49 275696 ----a-w- i:\windows\system32\mucltui.dll
2012-06-02 13:18 . 2012-04-01 06:49 214256 ----a-w- i:\windows\system32\muweb.dll
2012-06-02 13:18 . 2012-04-01 06:49 17136 ----a-w- i:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2004-08-03 22:56 599040 ----a-w- i:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2004-08-03 22:56 916992 ----a-w- i:\windows\system32\wininet.dll
2012-05-15 13:20 . 2004-08-03 21:17 1863168 ----a-w- i:\windows\system32\win32k.sys
2012-05-11 14:42 . 2004-08-03 22:56 1469440 ------w- i:\windows\system32\inetcpl.cpl
2012-05-11 14:42 . 2004-08-03 22:56 43520 ----a-w- i:\windows\system32\licmgr10.dll
2012-05-11 11:38 . 2004-08-03 20:59 385024 ----a-w- i:\windows\system32\html.iec
2012-05-06 06:06 . 2012-05-06 06:06 73728 ----a-w- i:\windows\system32\javacpl.cpl
2012-05-06 06:06 . 2012-05-06 06:06 476960 ----a-w- i:\windows\system32\npdeployJava1.dll
2012-05-06 06:06 . 2012-05-06 06:06 472864 ----a-w- i:\windows\system32\deployJava1.dll
2012-05-04 13:16 . 2004-08-03 21:18 2148352 ----a-w- i:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2004-08-03 22:59 2026496 ----a-w- i:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2009-05-29 16:39 139656 ----a-w- i:\windows\system32\drivers\rdpwd.sys
2012-06-16 18:52 . 2011-04-30 21:15 85472 ----a-w- i:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-07-09_19.10.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-10 15:14 . 2012-07-10 15:14 16384 i:\windows\temp\Perflib_Perfdata_778.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="i:\program files\PeerGuardian2\pg2.exe" [2005-09-18 1421824]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-23 16804864]
"SoundMan"="SOUNDMAN.EXE" [2008-06-18 77824]
"AlcWzrd"="ALCWZRD.EXE" [2008-06-19 2808832]
"JMB36X IDE Setup"="i:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"tsnp325"="i:\windows\tsnp325.exe" [2007-04-21 270336]
"snp325"="i:\windows\vsnp325.exe" [2007-05-10 835584]
"NvMediaCenter"="i:\windows\system32\NvMcTray.dll" [2010-04-03 110696]
"NvCplDaemon"="i:\windows\system32\NvCpl.dll" [2010-04-03 13670504]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="i:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "i:\program files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-02-27 09:39 282624 ----a-w- i:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKLM\~\startupfolder\I:^Documents and Settings^Mogon^Start Menu^Programs^Startup^GIGABYTE Gamer HUD.lnk]
path=i:\documents and settings\Mogon\Start Menu\Programs\Startup\GIGABYTE Gamer HUD.lnk
backup=i:\windows\pss\GIGABYTE Gamer HUD.lnkStartup
.
[HKLM\~\startupfolder\I:^Documents and Settings^Mogon^Start Menu^Programs^Startup^SolidWorks Task Scheduler Engine.lnk]
path=i:\documents and settings\Mogon\Start Menu\Programs\Startup\SolidWorks Task Scheduler Engine.lnk
backup=i:\windows\pss\SolidWorks Task Scheduler Engine.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PivotSoftware]
2010-05-13 15:34 110192 ----a-w- i:\program files\Portrait Displays\Pivot Pro Plugin\pivot_Startup.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 sptd;sptd;i:\windows\system32\drivers\sptd.sys [24.12.2010 14:20 685816]
R1 SASDIFSV;SASDIFSV;i:\program files\SUPERAntiSpyware\sasdifsv.sys [10.10.2006 12:53 5632]
R1 SASKUTIL;SASKUTIL;i:\program files\SUPERAntiSpyware\SASKUTIL.SYS [27.2.2007 11:39 32256]
R2 PdiService;Portrait Displays SDK Service;i:\program files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [24.1.2012 18:35 109168]
R2 Tekla Structures Licensing Service;Tekla Structures Licensing Service;i:\teklastructures\License\Server\lmgrd.exe [12.7.2010 10:11 1377104]
R3 SNP325;USB PC Camera (SNPSTD325);i:\windows\system32\drivers\snp325.sys [3.8.2009 10:16 10394624]
S2 GEST Service;GEST Service for program management.;i:\program files\GIGABYTE\EnergySaver\GSvr.exe [29.5.2009 21:31 68136]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;i:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [3.4.2012 17:12 257696]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;i:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [15.10.2009 7:51 87336]
S3 MozillaMaintenance;Mozilla Maintenance Service;i:\program files\Mozilla Maintenance Service\maintenanceservice.exe [25.4.2012 9:28 113120]
S3 SASENUM;SASENUM;i:\program files\SUPERAntiSpyware\SASENUM.SYS [16.2.2006 16:51 4096]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;i:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2.9.2011 9:51 155344]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;i:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23.9.2005 8:01 2799808]
.
.
------- Supplementary Scan -------
.
IE: E&xportovať do programu Microsoft Excel - i:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - i:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - i:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - i:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - i:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - i:\program files\ICQ7M\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} - file:///I:/Program%20Files/AutoCAD%202002%20Cz/InstFred.ocx
DPF: {640373B0-6978-4FA5-A9FC-420ECBBC61C7} - file:///C:/_Schodiská,%20Balkóny,%20Zábradlia/Zábr.%20točeného%20bet.%20schodiska/PublicWeb/dll/zkitlib.dll
DPF: {AE563723-B4F5-11D4-A415-00108302FDFD} - file:///I:/Program%20Files/AutoCAD%202002%20Cz/InstBanr.ocx
FF - ProfilePath - i:\documents and settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\
pref('extensions.shownSelectionUI',true);
pref('extensions.autoDisableScopes',0);
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Guard.Mail.ru - i:\program files\Guard-ICQ\GuardICQ.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-10 17:15
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\i:\program files\CyberLink\PowerDVD\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(912)
i:\program files\SUPERAntiSpyware\SASWINLO.dll
i:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(3460)
i:\windows\system32\WININET.dll
i:\windows\system32\AcSignIcon.dll
i:\program files\Common Files\Autodesk Shared\AcSignCore16.dll
i:\windows\system32\msi.dll
i:\windows\system32\ieframe.dll
i:\windows\system32\webcheck.dll
i:\windows\system32\WPDShServiceObj.dll
i:\windows\system32\PortableDeviceTypes.dll
i:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
i:\windows\system32\nvsvc32.exe
i:\windows\system32\DRIVERS\CDANTSRV.EXE
i:\program files\Common Files\Portrait Displays\Shared\DTSRVC.exe
i:\program files\Java\jre6\bin\jqs.exe
i:\teklastructures\License\Server\tekla.exe
i:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
i:\windows\system32\wscntfy.exe
i:\windows\RTHDCPL.EXE
i:\windows\SOUNDMAN.EXE
i:\windows\system32\RUNDLL32.EXE
.
**************************************************************************
.
Completion time: 2012-07-10 17:18:22 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-10 15:18
ComboFix2.txt 2012-07-09 19:11
.
Pre-Run: 23 335 260 160 bytes free
Post-Run: 23 268 327 424 bytes free
.
- - End Of File - - B81D31F955ED39650C30BF38534C7F20

Re: Prajem pekný deň

Napsal: 10 črc 2012 18:34
od vyosek
:arrow: Nainstalujte bezp. SW (Avast)

:arrow: Napiste co PC

Re: Prajem pekný deň

Napsal: 10 črc 2012 20:52
od mogon
Zdravím,

vyzerá to byť v pohode. Keby sa nieco vyskytlo tak by som sa ešte ozval, ale myslím že už to bude v poriadku. Nainštalujem Avast, ale asi len dočasne a zvážim kúpu NOD-u, príde mi že to je celkom dobry antivir.

A ak môžem vedieť, čo som to tam mal za prevíta?

A moc ďakujem za váš čas a pomoc. M.

Re: Prajem pekný deň

Napsal: 10 črc 2012 22:04
od vyosek
Tak jeste uklidime :James008:

:arrow: Odinstalujte Combofix
  • Prejmenujte ComboFix na Uninstall
  • Spustte jej
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Byla tam havet jmenem ZeroAccess - hodne aktualni a hodne silna - obcas jeji leceni konci formatem, nam se zadarilo :wink:

:arrow: Poprosim o novy log z RSIT (i s nainstalovanym Avastem)

Re: Prajem pekný deň

Napsal: 15 črc 2012 20:59
od mogon
Zdravím,

sorry že píšem tak neskoro, ale bol som mimo.

Tak to by ma zaujmalo ako sa také svinstvo dostalo do môjho PC..a zároveň moc ďakujem za pomoc.

Takže spravil som všetko čo som mal.
Dal som si spraviť aj kontrolu Avastom a Superantispywarom a nič nenašlo. Len ešte jedna vec, keď dám vypnúť PC, tak kým sa vypne tak to trva hrozne dlho 5-7 min. Predtým sa vypol do minuty max. dvoch.

Prikladám log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Mogon at 2012-07-15 21:53:25
Microsoft Windows XP Professional Service Pack 3
System drive I: has 22 GB (28%) free of 80 GB
Total RAM: 3326 MB (80% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:53:28, on 15.7.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\nvsvc32.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
I:\Program Files\Alwil Software\Avast4\ashServ.exe
I:\WINDOWS\Explorer.EXE
I:\WINDOWS\RTHDCPL.EXE
I:\WINDOWS\SOUNDMAN.EXE
I:\WINDOWS\tsnp325.exe
I:\WINDOWS\vsnp325.exe
I:\WINDOWS\system32\RUNDLL32.EXE
I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
I:\Program Files\PeerGuardian2\pg2.exe
I:\WINDOWS\system32\spoolsv.exe
I:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
I:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
I:\Program Files\Java\jre6\bin\jqs.exe
I:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
I:\WINDOWS\system32\svchost.exe
I:\TeklaStructures\License\Server\lmgrd.exe
I:\TeklaStructures\License\Server\lmgrd.exe
I:\TeklaStructures\License\Server\tekla.exe
I:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
I:\Program Files\Alwil Software\Avast4\ashWebSv.exe
I:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
I:\WINDOWS\system32\wscntfy.exe
I:\Program Files\Mozilla Firefox\firefox.exe
I:\Program Files\Mozilla Firefox\plugin-container.exe
I:\Documents and Settings\Mogon\Desktop\RSIT.exe
I:\Program Files\Trend Micro\Mogon.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - I:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - I:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - I:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - I:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] I:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [tsnp325] I:\WINDOWS\tsnp325.exe
O4 - HKLM\..\Run: [snp325] I:\WINDOWS\vsnp325.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE I:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE I:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [PeerGuardian] I:\Program Files\PeerGuardian2\pg2.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://I:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://I:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://I:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://I:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://I:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - I:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - I:\Program Files\ICQ7M\ICQ.exe
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file:///I:/Program%20Files/AutoCAD%202002%20Cz/InstFred.ocx
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://195.28.70.134/kapor2/lib/mgaxctrl.cab
O16 - DPF: {640373B0-6978-4FA5-A9FC-420ECBBC61C7} (Web Viewer Class) - file:///C:/_Schodiská,%20Balkóny,%20Zábradlia/Zábr.%20točeného%20bet.%20schodiska/PublicWeb/dll/zkitlib.dll
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Ovládací prvek AcDcToday) - file:///I:/Program%20Files/AutoCAD%202002%20Cz/AcDcToday.ocx
O16 - DPF: {AE563723-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file:///I:/Program%20Files/AutoCAD%202002%20Cz/InstBanr.ocx
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Prvek AcPreview) - file:///I:/Program%20Files/AutoCAD%202002%20Cz/AcPreview.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - I:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - I:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - I:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - I:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - I:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - I:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - I:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - I:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - I:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - I:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corp. - I:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - I:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - I:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - I:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - I:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - I:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - I:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - I:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - I:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - I:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: Tekla Structures Licensing Service - Flexera Software, Inc. - I:\TeklaStructures\License\Server\lmgrd.exe

--
End of file - 9332 bytes

=========Mozilla firefox=========

ProfilePath - I:\Documents and Settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default

prefs.js - "extensions.enabledItems" - "{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.4.2b, jqs@sun.com:1.0, {20a82645-c095-46ed-80e3-08825760534b}:1.2.1, {64161300-e22b-11db-8314-0800200c9a66}:0.9.5.8, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"

"{20a82645-c095-46ed-80e3-08825760534b}"=I:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=I:\Program Files\Java\jre6\lib\deploy\jqs\ff


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.262 Plugin
"Path"=I:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=I:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32]
"Description"=
"Path"=I:\WINDOWS\system32\npdeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=I:\Program Files\Java\jre6\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=I:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=I:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=I:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=I:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=I:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

I:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

I:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt

I:\Program Files\Mozilla Firefox\plugins\
npEModelPlugin.dll
NPOFFICE.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nsEModelPlugin.xpt
QuickTimePlugin.class

I:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

I:\Documents and Settings\Mogon\Application Data\Mozilla\Firefox\Profiles\d2uacjvf.default\extensions\
{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
{20a82645-c095-46ed-80e3-08825760534b}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-03-26 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - I:\Program Files\Java\jre6\bin\ssv.dll [2012-05-06 329504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - I:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-05-06 59168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - I:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2012-05-06 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - I:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26 405504]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=I:\WINDOWS\RTHDCPL.EXE [2008-07-23 16804864]
"SoundMan"=I:\WINDOWS\SOUNDMAN.EXE [2008-06-18 77824]
"AlcWzrd"=I:\WINDOWS\ALCWZRD.EXE [2008-06-19 2808832]
"JMB36X IDE Setup"=I:\WINDOWS\RaidTool\xInsIDE.exe [2007-03-20 36864]
"tsnp325"=I:\WINDOWS\tsnp325.exe [2007-04-21 270336]
"snp325"=I:\WINDOWS\vsnp325.exe [2007-05-10 835584]
"NvMediaCenter"=I:\WINDOWS\system32\NvMcTray.dll [2010-04-03 110696]
"NvCplDaemon"=I:\WINDOWS\system32\NvCpl.dll [2010-04-03 13670504]
"avast!"=I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"=I:\Program Files\PeerGuardian2\pg2.exe [2005-09-18 1421824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PivotSoftware]
I:\Program Files\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe [2010-05-13 110192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\I:^Documents and Settings^Mogon^Start Menu^Programs^Startup^GIGABYTE Gamer HUD.lnk]
I:\PROGRA~1\GIGABYTE\GAMERH~1\HUD.exe [2008-06-26 1940992]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\I:^Documents and Settings^Mogon^Start Menu^Programs^Startup^SolidWorks Task Scheduler Engine.lnk]
I:\PROGRA~1\SOLIDW~1\SWSCHE~1\SWBOEN~1.EXE [2007-09-09 488728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
I:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2007-02-27 282624]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
I:\WINDOWS\system32\WgaLogon.dll [2008-10-18 200064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - I:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=I:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=I:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=I:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"vidc.xvid"=xvidvfw.dll

======File associations======

.scr - open - I:\WINDOWS\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2012-07-15 21:53:25 ----D---- I:\rsit
2012-07-15 20:35:50 ----A---- I:\WINDOWS\system32\drivers\aswSP.sys
2012-07-15 20:35:50 ----A---- I:\WINDOWS\system32\drivers\aswFsBlk.sys
2012-07-15 20:24:57 ----A---- I:\WINDOWS\system32\drivers\aswTdi.sys
2012-07-15 20:24:57 ----A---- I:\WINDOWS\system32\drivers\aswRdr.sys
2012-07-15 20:24:57 ----A---- I:\WINDOWS\system32\drivers\aswmon2.sys
2012-07-15 20:24:57 ----A---- I:\WINDOWS\system32\drivers\aswmon.sys
2012-07-15 20:24:57 ----A---- I:\WINDOWS\system32\drivers\aavmker4.sys
2012-07-15 20:24:57 ----A---- I:\WINDOWS\system32\AvastSS.scr
2012-07-15 20:24:54 ----A---- I:\WINDOWS\system32\aswBoot.exe
2012-07-15 20:24:51 ----D---- I:\Program Files\Alwil Software
2012-07-10 21:00:05 ----D---- I:\Program Files\ESET
2012-07-10 17:46:41 ----SHD---- I:\RECYCLER
2012-07-10 17:13:27 ----D---- I:\WINDOWS\temp
2012-06-19 21:08:40 ----D---- I:\Documents and Settings\All Users\Application Data\ICQ
2012-06-19 21:07:59 ----D---- I:\Program Files\ICQ7M

======List of files/folders modified in the last 1 month======

2012-07-15 21:53:28 ----D---- I:\Program Files\Trend Micro
2012-07-15 21:53:13 ----D---- I:\Program Files\PeerGuardian2
2012-07-15 21:49:53 ----D---- I:\WINDOWS\Prefetch
2012-07-15 21:43:14 ----D---- I:\WINDOWS
2012-07-15 21:39:59 ----N---- I:\WINDOWS\SchedLgU.Txt
2012-07-15 21:34:13 ----D---- I:\WINDOWS\Internet Logs
2012-07-15 21:33:52 ----SHD---- I:\System Volume Information
2012-07-15 21:33:52 ----D---- I:\WINDOWS\system32\Restore
2012-07-15 21:33:51 ----D---- I:\WINDOWS\system32\drivers
2012-07-15 20:37:00 ----D---- I:\WINDOWS\system32\config
2012-07-15 20:35:34 ----D---- I:\WINDOWS\system32
2012-07-15 20:24:51 ----D---- I:\Program Files
2012-07-15 11:54:09 ----D---- I:\Documents and Settings\Mogon\Application Data\ICQ
2012-07-15 09:07:35 ----D---- I:\Documents and Settings\Mogon\Application Data\SolidWorks
2012-07-12 22:46:52 ----SHD---- I:\WINDOWS\Installer
2012-07-12 22:46:47 ----D---- I:\Config.Msi
2012-07-12 22:46:45 ----HD---- I:\WINDOWS\inf
2012-07-12 22:46:42 ----D---- I:\WINDOWS\system32\CatRoot2
2012-07-12 21:07:57 ----D---- I:\Program Files\JDownloader
2012-07-12 00:18:36 ----A---- I:\WINDOWS\NeroDigital.ini
2012-07-10 17:15:37 ----A---- I:\WINDOWS\system.ini
2012-07-10 17:15:17 ----D---- I:\WINDOWS\system32\drivers\etc
2012-07-10 17:13:11 ----SD---- I:\WINDOWS\Tasks
2012-07-10 17:12:15 ----D---- I:\WINDOWS\AppPatch
2012-07-10 17:12:14 ----D---- I:\Program Files\Common Files
2012-07-09 21:10:23 ----RSHDC---- I:\WINDOWS\system32\dllcache
2012-07-09 19:57:40 ----DC---- I:\WINDOWS\$NtUninstallKB41124$
2012-07-09 18:53:07 ----A---- I:\WINDOWS\system32\FlashPlayerApp.exe
2012-07-08 21:29:43 ----A---- I:\WINDOWS\wincmd.ini
2012-07-08 20:17:10 ----D---- I:\Program Files\SUPERAntiSpyware
2012-07-06 22:29:21 ----D---- I:\Documents and Settings\All Users\Application Data\YouTube Downloader
2012-06-25 23:23:32 ----HD---- I:\BJPrinter
2012-06-24 11:47:15 ----D---- I:\Documents and Settings\Mogon\Application Data\Skype
2012-06-24 11:05:04 ----D---- I:\Documents and Settings\Mogon\Application Data\skypePM
2012-06-22 18:35:20 ----D---- I:\WINDOWS\Debug
2012-06-19 21:08:45 ----HD---- I:\Program Files\InstallShield Installation Information
2012-06-19 18:14:33 ----D---- I:\WINDOWS\Help
2012-06-17 08:54:58 ----D---- I:\Program Files\Mozilla Maintenance Service
2012-06-16 20:53:06 ----D---- I:\Program Files\Mozilla Firefox

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 imagedrv;imagedrv; I:\WINDOWS\System32\Drivers\imagedrv.sys [2005-08-15 5888]
R0 imagesrv;imagesrv; I:\WINDOWS\system32\DRIVERS\imagesrv.sys [2005-08-15 127488]
R0 JRAID;JRAID; I:\WINDOWS\system32\DRIVERS\jraid.sys [2008-11-04 83296]
R0 ohci1394;Texas Instruments OHCI Compliant IEEE 1394 Host Controller; I:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; I:\WINDOWS\system32\DRIVERS\PxHelp20.sys [2009-04-28 44944]
R0 sptd;sptd; I:\WINDOWS\System32\Drivers\sptd.sys [2010-12-24 685816]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; I:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 Aavmker4;avast! Asynchronous Virus Monitor; I:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 aswSP;avast! Self Protection; I:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; I:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 intelppm;Intel Processor Driver; I:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 SASDIFSV;SASDIFSV; \??\I:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\I:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; I:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-23 12032]
R2 Aspi32;Aspi32; I:\WINDOWS\system32\drivers\Aspi32.sys [1999-09-10 25244]
R2 aswFsBlk;aswFsBlk; I:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; I:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R2 Sentinel;Sentinel; I:\WINDOWS\System32\Drivers\SENTINEL.SYS [2006-03-14 90176]
R3 Arp1394;1394 ARP Client Protocol; I:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 aswRdr;aswRdr; I:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 gdrv;gdrv; \??\I:\WINDOWS\gdrv.sys []
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; I:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); I:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-07-24 4749824]
R3 NIC1394;1394 Net Driver; I:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; I:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-04-03 10232128]
R3 PdiPorts;Portrait Displays low level device driver; I:\WINDOWS\System32\Drivers\PdiPorts.sys [2010-04-16 17136]
R3 pgfilter;pgfilter; \??\I:\Program Files\PeerGuardian2\pgfilter.sys []
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; I:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-10-16 115840]
R3 SNP325;USB PC Camera (SNPSTD325); I:\WINDOWS\system32\DRIVERS\snp325.sys [2007-07-24 10394624]
R3 usbstor;USB Mass Storage Driver; I:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; I:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 Pivot;Pivot; I:\WINDOWS\System32\drivers\pivot.sys [2010-05-13 17465]
S2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B}; \??\I:\Program Files\CyberLink\PowerDVD\000.fcl []
S3 a1hjpmvo;a1hjpmvo; I:\WINDOWS\system32\drivers\a1hjpmvo.sys []
S3 CCDECODE;Closed Caption Decoder; I:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 C-Dilla;C-Dilla; \??\I:\WINDOWS\system32\drivers\CDANT.SYS []
S3 HidUsb;Microsoft HID Class Driver; I:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 mouhid;Mouse HID Driver; I:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; I:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; I:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; I:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 pivotmou;Pivot Mouse/Pointers Filter Driver; \??\I:\WINDOWS\System32\drivers\pivotmou.sys []
S3 SASENUM;SASENUM; \??\I:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 SLIP;BDA Slip De-Framer; I:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; I:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 TrueSight;TrueSight; \??\i:\windows\system32\drivers\TrueSight.sys []
S3 usbccgp;Microsoft USB Generic Parent Driver; I:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; I:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; I:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;Sony Ericsson USB Serial Port; I:\WINDOWS\system32\DRIVERS\usbser.sys [2008-04-13 26112]
S3 WpdUsb;WpdUsb; I:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; I:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; I:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; I:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 C-DillaSrv;C-DillaSrv; I:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE [2009-08-18 32256]
R2 DTSRVC;Portrait Displays Display Tune Service; I:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe [2010-05-17 121456]
R2 JavaQuickStarterService;Java Quick Starter; I:\Program Files\Java\jre6\bin\jqs.exe [2012-05-06 153376]
R2 NVSvc;NVIDIA Display Driver Service; I:\WINDOWS\system32\nvsvc32.exe [2010-04-03 154216]
R2 PdiService;Portrait Displays SDK Service; I:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2010-04-16 109168]
R2 Tekla Structures Licensing Service;Tekla Structures Licensing Service; I:\TeklaStructures\License\Server\lmgrd.exe [2010-07-12 1377104]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; I:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; I:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; I:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
R3 FLEXnet Licensing Service;FLEXnet Licensing Service; I:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-02-01 1044816]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; I:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 GEST Service;GEST Service for program management.; I:\Program Files\GIGABYTE\EnergySaver\GSvr.exe [2008-12-08 68136]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; I:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-09 257696]
S3 aspnet_state;ASP.NET State Service; I:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 Autodesk Licensing Service;Autodesk Licensing Service; I:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2010-04-02 77944]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; I:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service; I:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; I:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; I:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; I:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-16 113120]
S3 odserv;Microsoft Office Diagnostics Service; I:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; I:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; I:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2012-02-26 79360]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; I:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; I:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 msvsmon80;Visual Studio 2005 Remote Debugger; I:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
S4 NBService;NBService; I:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-10-09 724992]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; I:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Prajem pekný deň

Napsal: 18 črc 2012 16:43
od vyosek
:arrow: Log se zda OK :)

:arrow: Zkuste dle navodu kolegy
[quote="pitimir"]

1. Start -> Spustit
2. Napis "regedit" (bez uvodzoviek)
3. Vyhladaj: HKEY_LOCAL_MACHINE -> System -> CurrentControlSet -> Control
4. Klikni na priecinok "Control" a na pravej strane okna vyhladaj "WaitToKillServiceTimeout"
5. 2x klikni a zmen cislo na 1000 (default je 20000)

1. Start->Spustit->"regedit"
2. Vyhladaj: HKEY_CURRENT_USER -> Control Panel -> Desktop
3. Klik na priecinok "Desktop" a na pravej strane vyhladaj "WaitToKillAppTimeout" a "HungAppTimeout"
4. 2x klik na obe zmienovane polozky a zmenit ich hodnoty na 1000 (default 20000)
/quote]