Sekající se pc
Napsal: 03 pro 2014 19:07
Dobrý den,
vím, že počítač je zastaralý a pomalý, ale jsem stále dotazován, jestli tam není havěť či vir.
Log:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Spravce at 2014-12-03 19:04:30
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 53 GB (69%) free of 76 GB
Total RAM: 1023 MB (29% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:04:54, on 3.12.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe
C:\Program Files\Java\jre7\bin\jqs.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\WandouLabs\wandoujia_helper.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Documents and Settings\Spravce\Plocha\RSIT.exe
C:\Program Files\trend micro\Spravce.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?o=APN10645A& ... 91-539&t=4
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Movies Search App (Dist. by Bandoo Media, Inc.) - {c0caa5fe-7c9c-4dca-a265-63cf55379d1a} - C:\PROGRA~1\MOVIES~1\Datamngr\SRTOOL~1\IE\searchresultsDx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Movies Search App (Dist. by Bandoo Media, Inc.) - {c0caa5fe-7c9c-4dca-a265-63cf55379d1a} - C:\PROGRA~1\MOVIES~1\Datamngr\SRTOOL~1\IE\searchresultsDx.dll
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CCleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: wandoujia_helper.lnk = C:\Program Files\WandouLabs\wandoujia_helper.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Datamngr Coordinator (DatamngrCoordinator) - Bandoo Media Inc. - C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
--
End of file - 5563 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job - c:\Program Files\Microsoft Security Client\MpCmdRun.exe Scan -ScheduleJob -RestrictPrivileges
C:\WINDOWS\tasks\MpIdleTask.job - c:\Program Files\Microsoft Security Client\MpCmdRun.exe -IdleTask -TaskName MpIdleTask
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Spravce\Data aplikací\Mozilla\Firefox\Profiles\i0cjxqex.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.search.ask.com/?o=APN10645A& ... 91-539&t=4"
prefs.js - "keyword.URL" - "http://dts.search.ask.com/sr?src=ffb&gc ... PN10645&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
C:\Documents and Settings\Spravce\Data aplikací\Mozilla\Firefox\Profiles\i0cjxqex.default\extensions\
{c0caa5fe-7c9c-4dca-a265-63cf55379d1a}
C:\Documents and Settings\Spravce\Data aplikací\Mozilla\Firefox\Profiles\i0cjxqex.default\searchplugins\
Ask.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-10-07 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c0caa5fe-7c9c-4dca-a265-63cf55379d1a}]
Movies Search App (Dist. by Bandoo Media, Inc.) - C:\PROGRA~1\MOVIES~1\Datamngr\SRTOOL~1\IE\searchresultsDx.dll [2014-07-03 115584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-10-07 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{c0caa5fe-7c9c-4dca-a265-63cf55379d1a} - Movies Search App (Dist. by Bandoo Media, Inc.) - C:\PROGRA~1\MOVIES~1\Datamngr\SRTOOL~1\IE\searchresultsDx.dll [2014-07-03 115584]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-08-19 110696]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-08-19 13925480]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2013-01-27 947152]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-07-25 256896]
"iTunesHelper"=C:\Program Files\iTunesHelper.exe [2014-10-15 157480]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"CCleaner"=C:\Program Files\CCleaner\CCleaner.exe [2014-08-21 4796696]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2014-10-01 22065760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-08-18 1753192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2005-07-12 81920]
C:\Documents and Settings\Spravce\Nabídka Start\Programy\Po spuštění
wandoujia_helper.lnk - C:\Program Files\WandouLabs\wandoujia_helper.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"E:\_Data\Hry\Counter-Strike 1.6 Non-Steam\hl.exe"="E:\_Data\Hry\Counter-Strike 1.6 Non-Steam\hl.exe:*:Disabled:Half-Life Launcher"
"E:\_Data\Hry\EA GAMES\Need for Speed Underground 2\speed2.exe"="E:\_Data\Hry\EA GAMES\Need for Speed Underground 2\speed2.exe:*:Enabled:speed2"
"C:\Program Files\WandouLabs\wandoujia2.exe"="C:\Program Files\WandouLabs\wandoujia2.exe:*:Enabled:SnapPea"
"C:\Program Files\iTunes.exe"="C:\Program Files\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Movies App\Datamngr\SRTOOL~1\IE\dtuser.exe"="C:\Program Files\Movies App\Datamngr\SRTOOL~1\IE\dtuser.exe:*:Enabled:Movies Search App (Dist. by Bandoo Media, Inc.) DTX Broker"
"C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"midi1"=wdmaud.drv
======List of files/folders created in the last 1 month======
2014-12-03 19:04:30 ----D---- C:\rsit
2014-12-03 19:04:30 ----D---- C:\Program Files\trend micro
2014-11-30 20:27:36 ----SHD---- C:\Config.Msi
2014-11-23 14:13:57 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2014-11-23 14:13:57 ----A---- C:\WINDOWS\system32\x3daudio1_2.dll
2014-11-23 14:13:56 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2014-11-23 14:13:56 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2014-11-23 14:13:55 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2014-11-23 14:13:54 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2014-11-23 14:13:52 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2014-11-23 14:13:50 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2014-11-23 14:13:50 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2014-11-23 14:13:48 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2014-11-23 14:13:47 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2014-11-23 14:13:46 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2014-11-23 14:13:46 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2014-11-23 14:13:45 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2014-11-23 14:13:45 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2014-11-23 14:13:45 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2014-11-23 14:13:44 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2014-11-23 14:13:44 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2014-11-23 14:13:43 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2014-11-23 14:13:42 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2014-11-23 14:13:41 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2014-11-23 14:13:31 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2014-11-23 14:13:31 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2014-11-23 14:13:31 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2014-11-23 14:13:29 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2014-11-23 14:13:29 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2014-11-23 14:13:28 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2014-11-23 14:13:28 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2014-11-23 14:13:27 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2014-11-23 14:13:26 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2014-11-23 14:12:47 ----A---- C:\WINDOWS\game.ini
2014-11-23 13:58:19 ----D---- C:\Program Files\Activision
2014-11-23 13:53:53 ----SHD---- C:\WINDOWS\ftpcache
2014-11-23 13:52:52 ----D---- C:\Documents and Settings\Spravce\Data aplikací\searchresultstb
2014-11-22 18:26:57 ----D---- C:\Program Files\MyPC Backup
2014-11-22 18:24:16 ----D---- C:\Documents and Settings\Spravce\Data aplikací\ilividbandoomoviestoolbar
2014-11-22 18:23:33 ----D---- C:\Program Files\Movies App
2014-11-22 18:23:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\Datamngr
2014-11-22 18:14:20 ----D---- C:\Program Files\Plug-Ins
2014-11-21 20:22:19 ----D---- C:\Documents and Settings\Spravce\Data aplikací\Apple Computer
2014-11-21 20:21:43 ----A---- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2014-11-21 20:21:22 ----D---- C:\Program Files\Mozilla Plugins
2014-11-21 20:21:18 ----D---- C:\Program Files\iTunesMiniPlayer.Resources
2014-11-21 20:21:13 ----D---- C:\Program Files\iTunesHelper.Resources
2014-11-21 20:19:52 ----D---- C:\Program Files\iTunes.Resources
2014-11-21 20:19:45 ----D---- C:\Program Files\iPod
2014-11-21 20:19:30 ----D---- C:\Program Files\CD Configuration
2014-11-21 20:19:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2014-11-21 20:19:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2014-11-21 20:18:34 ----DC---- C:\WINDOWS\system32\DRVSTORE
2014-11-21 20:15:41 ----D---- C:\Program Files\Common Files\Apple
2014-11-21 20:15:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple
2014-11-09 18:29:19 ----N---- C:\WINDOWS\system32\spmsgXP_2k3.dll
2014-11-09 18:29:04 ----HDC---- C:\WINDOWS\$NtUninstallWdf01007$
2014-11-09 18:28:36 ----A---- C:\WINDOWS\system32\drivers\ANDROIDUSB.sys
2014-11-09 18:28:35 ----A---- C:\WINDOWS\system32\WdfCoInstaller01007.dll
2014-11-09 18:26:47 ----D---- C:\SnapPea
2014-11-09 18:26:44 ----D---- C:\Documents and Settings\Spravce\Data aplikací\WandoujiaUsbDriver
2014-11-09 18:26:16 ----D---- C:\Documents and Settings\Spravce\Data aplikací\Wandoujia2
2014-11-09 18:25:46 ----D---- C:\Program Files\WandouLabs
======List of files/folders modified in the last 1 month======
2014-12-03 19:04:37 ----D---- C:\WINDOWS\Prefetch
2014-12-03 19:04:30 ----RD---- C:\Program Files
2014-12-03 19:01:49 ----D---- C:\WINDOWS\system32\CatRoot2
2014-12-03 18:59:48 ----D---- C:\WINDOWS\Temp
2014-12-03 18:59:32 ----D---- C:\Documents and Settings\Spravce\Data aplikací\Skype
2014-12-03 18:59:11 ----D---- C:\WINDOWS\SoftwareDistribution
2014-12-03 18:57:51 ----D---- C:\WINDOWS
2014-12-02 21:17:42 ----N---- C:\WINDOWS\SchedLgU.Txt
2014-12-02 14:42:45 ----SD---- C:\WINDOWS\Tasks
2014-12-01 17:37:43 ----HD---- C:\WINDOWS\inf
2014-12-01 17:36:13 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-12-01 17:36:13 ----D---- C:\WINDOWS\system32\cs-cz
2014-12-01 17:36:13 ----D---- C:\WINDOWS\system32
2014-12-01 17:36:13 ----D---- C:\WINDOWS\Help
2014-12-01 17:36:13 ----D---- C:\Program Files\Internet Explorer
2014-11-30 20:33:50 ----D---- C:\Program Files\Google
2014-11-30 20:33:49 ----SHD---- C:\WINDOWS\Installer
2014-11-23 14:13:58 ----D---- C:\WINDOWS\system32\DirectX
2014-11-23 14:13:41 ----RSD---- C:\WINDOWS\assembly
2014-11-23 14:13:33 ----D---- C:\WINDOWS\Microsoft.NET
2014-11-23 14:12:41 ----HD---- C:\Program Files\InstallShield Installation Information
2014-11-22 18:28:29 ----D---- C:\WINDOWS\WinSxS
2014-11-21 20:21:44 ----D---- C:\WINDOWS\system32\drivers
2014-11-21 20:15:41 ----D---- C:\Program Files\Common Files
2014-11-09 18:26:19 ----RSD---- C:\WINDOWS\Fonts
2014-11-04 21:12:40 ----SD---- C:\Documents and Settings\Spravce\Data aplikací\Microsoft
2014-11-04 19:51:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2013-01-20 195296]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R1 AmdK8;Ovladač procesoru AMD Athlon64; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2004-05-08 38400]
R1 F06DEFF2-5B9C-490D-910F-35D3A9119622;F06DEFF2-5B9C-490D-910F-35D3A9119622; \??\C:\Program Files\Movies App\Datamngr\setmgrc2.cfg []
R2 regi;regi; \??\C:\WINDOWS\system32\drivers\regi.sys []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-07-15 3640000]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 26840]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-03-02 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-08-19 9902112]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-08-11 33536]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-08-11 12928]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 HTCAND32;HTC Device Driver; C:\WINDOWS\System32\Drivers\ANDROIDUSB.sys [2014-11-09 24576]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-01-19 503144]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 DatamngrCoordinator;Datamngr Coordinator; C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe [2014-11-11 3573448]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2014-10-07 182696]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-01-27 20456]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-08-19 155752]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2014-10-15 540968]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-10-11 114288]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
-----------------EOF-----------------
vím, že počítač je zastaralý a pomalý, ale jsem stále dotazován, jestli tam není havěť či vir.
Log:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Spravce at 2014-12-03 19:04:30
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 53 GB (69%) free of 76 GB
Total RAM: 1023 MB (29% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:04:54, on 3.12.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe
C:\Program Files\Java\jre7\bin\jqs.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\WandouLabs\wandoujia_helper.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Documents and Settings\Spravce\Plocha\RSIT.exe
C:\Program Files\trend micro\Spravce.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?o=APN10645A& ... 91-539&t=4
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Movies Search App (Dist. by Bandoo Media, Inc.) - {c0caa5fe-7c9c-4dca-a265-63cf55379d1a} - C:\PROGRA~1\MOVIES~1\Datamngr\SRTOOL~1\IE\searchresultsDx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Movies Search App (Dist. by Bandoo Media, Inc.) - {c0caa5fe-7c9c-4dca-a265-63cf55379d1a} - C:\PROGRA~1\MOVIES~1\Datamngr\SRTOOL~1\IE\searchresultsDx.dll
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CCleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: wandoujia_helper.lnk = C:\Program Files\WandouLabs\wandoujia_helper.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Datamngr Coordinator (DatamngrCoordinator) - Bandoo Media Inc. - C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
--
End of file - 5563 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job - c:\Program Files\Microsoft Security Client\MpCmdRun.exe Scan -ScheduleJob -RestrictPrivileges
C:\WINDOWS\tasks\MpIdleTask.job - c:\Program Files\Microsoft Security Client\MpCmdRun.exe -IdleTask -TaskName MpIdleTask
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Spravce\Data aplikací\Mozilla\Firefox\Profiles\i0cjxqex.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.search.ask.com/?o=APN10645A& ... 91-539&t=4"
prefs.js - "keyword.URL" - "http://dts.search.ask.com/sr?src=ffb&gc ... PN10645&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
C:\Documents and Settings\Spravce\Data aplikací\Mozilla\Firefox\Profiles\i0cjxqex.default\extensions\
{c0caa5fe-7c9c-4dca-a265-63cf55379d1a}
C:\Documents and Settings\Spravce\Data aplikací\Mozilla\Firefox\Profiles\i0cjxqex.default\searchplugins\
Ask.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-10-07 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c0caa5fe-7c9c-4dca-a265-63cf55379d1a}]
Movies Search App (Dist. by Bandoo Media, Inc.) - C:\PROGRA~1\MOVIES~1\Datamngr\SRTOOL~1\IE\searchresultsDx.dll [2014-07-03 115584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-10-07 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{c0caa5fe-7c9c-4dca-a265-63cf55379d1a} - Movies Search App (Dist. by Bandoo Media, Inc.) - C:\PROGRA~1\MOVIES~1\Datamngr\SRTOOL~1\IE\searchresultsDx.dll [2014-07-03 115584]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-08-19 110696]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-08-19 13925480]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2013-01-27 947152]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-07-25 256896]
"iTunesHelper"=C:\Program Files\iTunesHelper.exe [2014-10-15 157480]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"CCleaner"=C:\Program Files\CCleaner\CCleaner.exe [2014-08-21 4796696]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2014-10-01 22065760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-08-18 1753192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2005-07-12 81920]
C:\Documents and Settings\Spravce\Nabídka Start\Programy\Po spuštění
wandoujia_helper.lnk - C:\Program Files\WandouLabs\wandoujia_helper.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"E:\_Data\Hry\Counter-Strike 1.6 Non-Steam\hl.exe"="E:\_Data\Hry\Counter-Strike 1.6 Non-Steam\hl.exe:*:Disabled:Half-Life Launcher"
"E:\_Data\Hry\EA GAMES\Need for Speed Underground 2\speed2.exe"="E:\_Data\Hry\EA GAMES\Need for Speed Underground 2\speed2.exe:*:Enabled:speed2"
"C:\Program Files\WandouLabs\wandoujia2.exe"="C:\Program Files\WandouLabs\wandoujia2.exe:*:Enabled:SnapPea"
"C:\Program Files\iTunes.exe"="C:\Program Files\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Movies App\Datamngr\SRTOOL~1\IE\dtuser.exe"="C:\Program Files\Movies App\Datamngr\SRTOOL~1\IE\dtuser.exe:*:Enabled:Movies Search App (Dist. by Bandoo Media, Inc.) DTX Broker"
"C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"midi1"=wdmaud.drv
======List of files/folders created in the last 1 month======
2014-12-03 19:04:30 ----D---- C:\rsit
2014-12-03 19:04:30 ----D---- C:\Program Files\trend micro
2014-11-30 20:27:36 ----SHD---- C:\Config.Msi
2014-11-23 14:13:57 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2014-11-23 14:13:57 ----A---- C:\WINDOWS\system32\x3daudio1_2.dll
2014-11-23 14:13:56 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2014-11-23 14:13:56 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2014-11-23 14:13:55 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2014-11-23 14:13:54 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2014-11-23 14:13:52 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2014-11-23 14:13:50 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2014-11-23 14:13:50 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2014-11-23 14:13:48 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2014-11-23 14:13:47 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2014-11-23 14:13:46 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2014-11-23 14:13:46 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2014-11-23 14:13:45 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2014-11-23 14:13:45 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2014-11-23 14:13:45 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2014-11-23 14:13:44 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2014-11-23 14:13:44 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2014-11-23 14:13:43 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2014-11-23 14:13:42 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2014-11-23 14:13:41 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2014-11-23 14:13:31 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2014-11-23 14:13:31 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2014-11-23 14:13:31 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2014-11-23 14:13:29 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2014-11-23 14:13:29 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2014-11-23 14:13:28 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2014-11-23 14:13:28 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2014-11-23 14:13:27 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2014-11-23 14:13:26 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2014-11-23 14:12:47 ----A---- C:\WINDOWS\game.ini
2014-11-23 13:58:19 ----D---- C:\Program Files\Activision
2014-11-23 13:53:53 ----SHD---- C:\WINDOWS\ftpcache
2014-11-23 13:52:52 ----D---- C:\Documents and Settings\Spravce\Data aplikací\searchresultstb
2014-11-22 18:26:57 ----D---- C:\Program Files\MyPC Backup
2014-11-22 18:24:16 ----D---- C:\Documents and Settings\Spravce\Data aplikací\ilividbandoomoviestoolbar
2014-11-22 18:23:33 ----D---- C:\Program Files\Movies App
2014-11-22 18:23:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\Datamngr
2014-11-22 18:14:20 ----D---- C:\Program Files\Plug-Ins
2014-11-21 20:22:19 ----D---- C:\Documents and Settings\Spravce\Data aplikací\Apple Computer
2014-11-21 20:21:43 ----A---- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2014-11-21 20:21:22 ----D---- C:\Program Files\Mozilla Plugins
2014-11-21 20:21:18 ----D---- C:\Program Files\iTunesMiniPlayer.Resources
2014-11-21 20:21:13 ----D---- C:\Program Files\iTunesHelper.Resources
2014-11-21 20:19:52 ----D---- C:\Program Files\iTunes.Resources
2014-11-21 20:19:45 ----D---- C:\Program Files\iPod
2014-11-21 20:19:30 ----D---- C:\Program Files\CD Configuration
2014-11-21 20:19:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2014-11-21 20:19:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2014-11-21 20:18:34 ----DC---- C:\WINDOWS\system32\DRVSTORE
2014-11-21 20:15:41 ----D---- C:\Program Files\Common Files\Apple
2014-11-21 20:15:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple
2014-11-09 18:29:19 ----N---- C:\WINDOWS\system32\spmsgXP_2k3.dll
2014-11-09 18:29:04 ----HDC---- C:\WINDOWS\$NtUninstallWdf01007$
2014-11-09 18:28:36 ----A---- C:\WINDOWS\system32\drivers\ANDROIDUSB.sys
2014-11-09 18:28:35 ----A---- C:\WINDOWS\system32\WdfCoInstaller01007.dll
2014-11-09 18:26:47 ----D---- C:\SnapPea
2014-11-09 18:26:44 ----D---- C:\Documents and Settings\Spravce\Data aplikací\WandoujiaUsbDriver
2014-11-09 18:26:16 ----D---- C:\Documents and Settings\Spravce\Data aplikací\Wandoujia2
2014-11-09 18:25:46 ----D---- C:\Program Files\WandouLabs
======List of files/folders modified in the last 1 month======
2014-12-03 19:04:37 ----D---- C:\WINDOWS\Prefetch
2014-12-03 19:04:30 ----RD---- C:\Program Files
2014-12-03 19:01:49 ----D---- C:\WINDOWS\system32\CatRoot2
2014-12-03 18:59:48 ----D---- C:\WINDOWS\Temp
2014-12-03 18:59:32 ----D---- C:\Documents and Settings\Spravce\Data aplikací\Skype
2014-12-03 18:59:11 ----D---- C:\WINDOWS\SoftwareDistribution
2014-12-03 18:57:51 ----D---- C:\WINDOWS
2014-12-02 21:17:42 ----N---- C:\WINDOWS\SchedLgU.Txt
2014-12-02 14:42:45 ----SD---- C:\WINDOWS\Tasks
2014-12-01 17:37:43 ----HD---- C:\WINDOWS\inf
2014-12-01 17:36:13 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-12-01 17:36:13 ----D---- C:\WINDOWS\system32\cs-cz
2014-12-01 17:36:13 ----D---- C:\WINDOWS\system32
2014-12-01 17:36:13 ----D---- C:\WINDOWS\Help
2014-12-01 17:36:13 ----D---- C:\Program Files\Internet Explorer
2014-11-30 20:33:50 ----D---- C:\Program Files\Google
2014-11-30 20:33:49 ----SHD---- C:\WINDOWS\Installer
2014-11-23 14:13:58 ----D---- C:\WINDOWS\system32\DirectX
2014-11-23 14:13:41 ----RSD---- C:\WINDOWS\assembly
2014-11-23 14:13:33 ----D---- C:\WINDOWS\Microsoft.NET
2014-11-23 14:12:41 ----HD---- C:\Program Files\InstallShield Installation Information
2014-11-22 18:28:29 ----D---- C:\WINDOWS\WinSxS
2014-11-21 20:21:44 ----D---- C:\WINDOWS\system32\drivers
2014-11-21 20:15:41 ----D---- C:\Program Files\Common Files
2014-11-09 18:26:19 ----RSD---- C:\WINDOWS\Fonts
2014-11-04 21:12:40 ----SD---- C:\Documents and Settings\Spravce\Data aplikací\Microsoft
2014-11-04 19:51:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2013-01-20 195296]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R1 AmdK8;Ovladač procesoru AMD Athlon64; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2004-05-08 38400]
R1 F06DEFF2-5B9C-490D-910F-35D3A9119622;F06DEFF2-5B9C-490D-910F-35D3A9119622; \??\C:\Program Files\Movies App\Datamngr\setmgrc2.cfg []
R2 regi;regi; \??\C:\WINDOWS\system32\drivers\regi.sys []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-07-15 3640000]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 26840]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-03-02 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-08-19 9902112]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-08-11 33536]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-08-11 12928]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 HTCAND32;HTC Device Driver; C:\WINDOWS\System32\Drivers\ANDROIDUSB.sys [2014-11-09 24576]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-01-19 503144]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 DatamngrCoordinator;Datamngr Coordinator; C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe [2014-11-11 3573448]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2014-10-07 182696]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-01-27 20456]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-08-19 155752]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2014-10-15 540968]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-10-11 114288]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
-----------------EOF-----------------