PC se zpomaluje až do následného restartu
Napsal: 11 led 2010 09:33
Dobrý den, prosím o pomoc. Začal se mi zpomalovat počítač, nejdříve je to poznat na pohybu myši, později přestane fungovat internet, počítač je čím dál pomalejší až následuje restart. O využití procesoru se perou Nečinné procesy systému a antivir NOD32.
Pro napravení jsem harddisk v jiném PC zkontroloval antiviry NOD32, AVPTool, Kaspersky a Avirou. Vše detekováno jsem zlikvidoval. Potom jsem v PC ještě použil Combofix, nic nepomohlo. Nastavil jsem úplnou kontrolu disku při bootování, bohužel to napíše "Svazek nelze otevřít pro přímý vstup". Nefunguje ani volba "chkdsk" v naběhnutém systému. Prosím poraďte.
Logfile of random's system information tool 1.06 (written by random/random)
Run by hubsch at 2010-01-11 08:32:08
WIN_XP Service Pack 3
System drive C: has 7 GB (3%) free of 238 GB
Total RAM: 1791 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:32:29, on 11.1.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Elektro\Plocha\RSIT.exe
C:\hubsch.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.warforum.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-3086271954-1183994661-564440380-1125\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-21-3086271954-1183994661-564440380-1125\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: VistaAccess.lnk = C:\VstaScan\VsAccess.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = elektro.local
O17 - HKLM\Software\..\Telephony: DomainName = elektro.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = elektro.local
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
--
End of file - 4741 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Schedule Task Weekly.job
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
StartCCC=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-03-17 61440]
iTunesHelper=C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]
egui=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-11-16 2054360]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
MSMSGS=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Po spuštění
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
VistaAccess.lnk - C:\VstaScan\VsAccess.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-03-16 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
dontdisplaylastusername=0
legalnoticecaption=
legalnoticetext=
shutdownwithoutlogon=1
undockwithoutlogon=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoDriveTypeAutoRun=323
NoResolveTrack=1
NoDriveAutoRun=67108863
NoDrives=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoResolveTrack=
NoResolveSearch=
NoPopUpsOnBoot=
HonorAutoRunSetting=
NoDriveAutoRun=
NoDriveTypeAutoRun=
NoDrives=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
C:\Program Files\ICQLite\ICQLite.exe="C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite"
C:\Program Files\uTorrent\utorrent.exe="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe="C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"
C:\Program Files\Canon\Color Network ScanGear\SgTool.exe="C:\Program Files\Canon\Color Network ScanGear\SgTool.exe:*:Enabled:SGTOOL"
%windir%\Network Diagnostic\xpnetdiag.exe="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
C:\Program Files\Bonjour\mDNSResponder.exe="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
C:\Program Files\iTunes\iTunes.exe="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe="C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"
%windir%\Network Diagnostic\xpnetdiag.exe="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
C:\Program Files\ICQLite\ICQLite.exe="C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite"
C:\Program Files\uTorrent\utorrent.exe="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
C:\Program Files\Java\jre6\bin\javaw.exe="C:\Program Files\Java\jre6\bin\javaw.exe:*:Disabled:Java(TM) Platform SE binary"
C:\Program Files\Java\jre6\bin\java.exe="C:\Program Files\Java\jre6\bin\java.exe:*:Disabled:Java(TM) Platform SE binary"
C:\games\Buccaneer\T3D.exe="C:\games\Buccaneer\T3D.exe:*:Enabled:Buccaneer: The Pursuit of Infamy"
C:\Program Files\Common Files\XpressUpdate\XPressUpdate.exe="C:\Program Files\Common Files\XpressUpdate\XPressUpdate.exe:*:Enabled:XPressUpdate"
C:\Program Files\Brother\Brmfl08h\FAXRX.exe="C:\Program Files\Brother\Brmfl08h\FAXRX.exe:*:Enabled:FAXRX.EXE"
C:\Program Files\iTunes\iTunes.exe="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
======List of files/folders created in the last 1 months======
2010-01-11 08:32:08 ----A---- C:\hubsch.exe
2010-01-08 15:30:45 ----D---- C:\backups
2010-01-08 15:03:59 ----D---- C:\Program Files\SubtitleCreator
2010-01-06 14:37:54 ----SHD---- C:\RECYCLER
2010-01-06 12:54:16 ----D---- C:\WINDOWS\temp
2010-01-06 12:44:53 ----D---- C:\ComboFix
2010-01-05 09:29:37 ----A---- C:\Pokus.bat
2010-01-05 09:03:22 ----A---- C:\Zpráva o Analýze Hijack.txt
2010-01-05 08:04:33 ----A---- C:\ComboFix log.txt
2010-01-05 07:49:19 ----A---- C:\Boot.bak
2010-01-05 07:49:11 ----RASHD---- C:\cmdcons
2010-01-05 07:47:30 ----A---- C:\WINDOWS\MBR.exe
2010-01-05 07:47:29 ----A---- C:\WINDOWS\NIRCMD.exe
2010-01-05 07:47:27 ----A---- C:\WINDOWS\PEV.exe
2010-01-05 07:47:26 ----A---- C:\WINDOWS\zip.exe
2010-01-05 07:47:26 ----A---- C:\WINDOWS\SWSC.exe
2010-01-05 07:47:26 ----A---- C:\WINDOWS\SWREG.exe
2010-01-05 07:47:26 ----A---- C:\WINDOWS\sed.exe
2010-01-05 07:47:26 ----A---- C:\WINDOWS\grep.exe
2010-01-05 07:47:25 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-01-05 07:37:33 ----A---- C:\hijackthis.exe
2010-01-04 07:14:44 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Avira
2009-12-18 14:24:27 ----D---- C:\Documents and Settings\Elektro\Data aplikací\Virtual City
2009-12-17 09:04:07 ----D---- C:\divx
2009-12-17 08:43:29 ----D---- C:\Program Files\Common Files\DivX Shared
2009-12-17 08:35:44 ----A---- C:\DivXInstaller.exe
2009-12-15 13:13:38 ----A---- C:\se-setup.exe
2009-12-15 12:48:09 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-12-15 12:47:39 ----A---- C:\mbam-setup.exe
2009-12-15 11:59:50 ----AD---- C:\WINDOWS\rundll16.exe
2009-12-15 11:59:50 ----AD---- C:\WINDOWS\logo1_.exe
2009-12-15 10:26:43 ----D---- C:\Documents and Settings\Elektro\Data aplikací\DAEMON Tools Lite
2009-12-15 10:26:41 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\DAEMON Tools Lite
2009-12-15 09:05:59 ----D---- C:\Documents and Settings\Elektro\Data aplikací\EurekaLog
2009-12-15 07:46:59 ----D---- C:\Program Files\CCleaner
2009-12-15 07:43:09 ----AD---- C:\WINDOWS\VDLL.DLL
2009-12-15 07:43:09 ----AD---- C:\WINDOWS\system32\runouce.exe
2009-12-15 07:43:09 ----AD---- C:\WINDOWS\RUNDL132.EXE
2009-12-15 07:43:09 ----AD---- C:\WINDOWS\logo_1.exe
2009-12-15 07:42:05 ----A---- C:\WINDOWS\system32\eEmpty.exe
2009-12-15 07:42:02 ----A---- C:\WINDOWS\system32\T.COM
2009-12-15 07:42:01 ----A---- C:\WINDOWS\R.COM
2009-12-15 07:41:58 ----D---- C:\Program Files\Common Files\MicroWorld
2009-12-15 07:41:55 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\MicroWorld
2009-12-15 07:30:03 ----D---- C:\rsit
2009-12-15 07:30:03 ----D---- C:\Program Files\trend micro
2009-12-14 08:35:22 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2009-12-14 08:35:01 ----HDC---- C:\WINDOWS\$NtUninstallKB976098-v2$
2009-12-14 08:34:38 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2009-12-14 08:34:12 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2009-12-14 08:33:22 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2009-12-14 08:32:46 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2009-12-14 08:32:02 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2009-12-14 08:31:25 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2009-12-14 08:31:02 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2009-12-14 08:30:34 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2009-12-14 08:30:03 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2009-12-14 08:28:28 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2009-12-14 08:28:01 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2009-12-14 08:27:31 ----HDC---- C:\WINDOWS\$NtUninstallKB973525$
2009-12-14 08:23:02 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2009-12-14 08:22:35 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2009-12-14 08:22:06 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2009-12-14 07:55:43 ----A---- C:\SeaToolsforWindowsSetup-1201.exe
2009-12-14 07:48:27 ----D---- C:\Documents and Settings\Elektro\Data aplikací\ESET
2009-12-14 07:47:52 ----D---- C:\Program Files\ESET
2009-12-14 07:47:52 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\ESET
======List of files/folders modified in the last 1 months======
2010-01-11 08:31:15 ----A---- C:\WINDOWS\VISTA32.INI
2010-01-11 08:28:36 ----D---- C:\W
2010-01-11 08:16:09 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-11 07:43:58 ----D---- C:\WINDOWS\Prefetch
2010-01-08 15:21:59 ----SHD---- C:\WINDOWS\CSC
2010-01-08 15:03:59 ----RD---- C:\Program Files
2010-01-08 13:52:45 ----A---- C:\WINDOWS\win.ini
2010-01-08 13:37:41 ----SHD---- C:\WINDOWS\Installer
2010-01-08 13:37:40 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-01-08 13:37:40 ----D---- C:\Config.Msi
2010-01-08 11:03:54 ----D---- C:\Program Files\Sony
2010-01-08 10:58:57 ----D---- C:\Documents and Settings\Elektro\Data aplikací\Sony
2010-01-08 10:57:59 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Sony
2010-01-08 10:57:43 ----D---- C:\WINDOWS\system32
2010-01-08 10:57:08 ----D---- C:\WINDOWS\WinSxS
2010-01-08 10:39:34 ----D---- C:\WINDOWS\system32\drivers
2010-01-08 10:36:53 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-08 07:21:29 ----D---- C:\WINDOWS
2010-01-08 07:12:28 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Kaspersky Lab
2010-01-08 07:10:24 ----HD---- C:\WINDOWS\inf
2010-01-07 14:56:27 ----A---- C:\WINDOWS\NeroDigital.ini
2010-01-07 14:36:10 ----D---- C:\WINDOWS\system32\config
2010-01-07 12:58:54 ----D---- C:\WINDOWS\system32\Restore
2010-01-07 12:53:08 ----SHD---- C:\System Volume Information
2010-01-07 11:52:14 ----D---- C:\DVD
2010-01-07 11:01:34 ----A---- C:\WINDOWS\umaxuapi.ini
2010-01-06 12:54:28 ----A---- C:\WINDOWS\system.ini
2010-01-06 12:51:41 ----D---- C:\WINDOWS\AppPatch
2010-01-06 12:51:37 ----D---- C:\Program Files\Common Files
2010-01-06 12:45:16 ----D---- C:\Qoobox
2010-01-06 09:35:27 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-01-06 09:34:36 ----D---- C:\Program Files\Ranch Rush
2010-01-06 09:34:36 ----D---- C:\Program Files\Farm Frenzy 2
2010-01-06 09:34:36 ----D---- C:\Program Files\Ancient Quest of Saqqarah
2010-01-05 09:30:35 ----D---- C:\WINDOWS\SoftwareDistribution
2010-01-05 08:02:49 ----SD---- C:\WINDOWS\Tasks
2010-01-05 08:02:27 ----D---- C:\WINDOWS\ERDNT
2010-01-05 08:00:13 ----D---- C:\WINDOWS\system
2010-01-05 07:49:20 ----RASH---- C:\boot.ini
2010-01-04 18:50:11 ----D---- C:\Program Files\DVD-RB PRO
2010-01-04 14:15:23 ----D---- C:\Documents and Settings\Elektro\Data aplikací\vlc
2010-01-04 13:11:50 ----D---- C:\CENÍKY
2010-01-04 09:40:30 ----SD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Microsoft
2010-01-04 07:40:00 ----D---- C:\Program Files\Easy CD-DA Extractor 12
2009-12-18 14:48:34 ----AD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP
2009-12-18 08:46:50 ----D---- C:\Program Files\DivX
2009-12-17 09:34:22 ----D---- C:\Documents and Settings\Elektro\Data aplikací\dvdcss
2009-12-17 09:33:57 ----D---- C:\Documents and Settings\Elektro\Data aplikací\DivX
2009-12-15 08:35:59 ----RSD---- C:\WINDOWS\assembly
2009-12-15 08:31:54 ----D---- C:\WINDOWS\Microsoft.NET
2009-12-15 07:50:54 ----D---- C:\WINDOWS\Debug
2009-12-15 07:50:53 ----D---- C:\WINDOWS\Minidump
2009-12-15 07:42:07 ----A---- C:\WINDOWS\system32\msvcr80.dll
2009-12-15 07:42:05 ----A---- C:\WINDOWS\system32\msvcp80.dll
2009-12-14 15:20:27 ----D---- C:\Program Files\Canon
2009-12-14 08:38:57 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-12-14 08:35:28 ----D---- C:\WINDOWS\system32\CatRoot
2009-12-14 08:34:42 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-12-14 08:30:33 ----HD---- C:\WINDOWS\$hf_mig$
2009-12-14 08:29:23 ----D---- C:\WINDOWS\system32\cs-cz
2009-12-14 08:29:22 ----D---- C:\Program Files\Internet Explorer
2009-12-14 08:28:59 ----D---- C:\WINDOWS\ie7updates
2009-12-14 07:58:46 ----D---- C:\Program Files\Seagate
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 cdrbsdrv;cdrbsdrv; C:\WINDOWS\system32\drivers\cdrbsdrv.sys [2008-11-04 33408]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-11-16 55768]
R1 HMFAxCore46691b2fe72383a3b643d95081ef1d95;HMFAxCore46691b2fe72383a3b643d95081ef1d95; \??\C:\WINDOWS\system32\drivers\HMFAxCore46691b2fe72383a3b643d95081ef1d95.sys []
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}; \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl []
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2008-10-03 278984]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-11-16 135048]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2008-10-03 25416]
R2 PARCLASS1;PARCLASS1; \??\C:\WINDOWS\system32\drivers\PARCLASS1.sys []
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-03-16 3597312]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-06-19 33096]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-01-30 4725760]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [2004-08-15 5810]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtenicxp.sys [2007-12-05 104064]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-10-24 6784]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-13 17152]
S2 DeviceScanner;UMAX Astra 4400 Scanner; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S2 Parclass;Parclass; C:\WINDOWS\System32\Drivers\Parclass.sys [2006-12-08 20272]
S3 afepmrjq;afepmrjq; C:\WINDOWS\system32\drivers\afepmrjq.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\Elektro\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 cpuz132;cpuz132; \??\C:\WINDOWS\system32\drivers\cpuz132_x32.sys []
S3 CXFALCON;AVerMedia AVerTV Video Capture (Falcon); C:\WINDOWS\system32\drivers\AF2VCap.sys [2006-06-23 345344]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys []
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2008-09-09 47360]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys []
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2005-10-21 12800]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-08-28 40448]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\system32\DRIVERS\sr.sys [2008-04-14 73344]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2003-04-16 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-03-16 602112]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-11-16 735960]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2008-04-08 241734]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-11-16 20680]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2008-11-21 79360]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-03-17 593920]
S4 Canon Driver Information Assist Service;Canon Driver Information Assist Service; C:\Program Files\Canon\DIAS\CnxDIAS.exe []
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Pro napravení jsem harddisk v jiném PC zkontroloval antiviry NOD32, AVPTool, Kaspersky a Avirou. Vše detekováno jsem zlikvidoval. Potom jsem v PC ještě použil Combofix, nic nepomohlo. Nastavil jsem úplnou kontrolu disku při bootování, bohužel to napíše "Svazek nelze otevřít pro přímý vstup". Nefunguje ani volba "chkdsk" v naběhnutém systému. Prosím poraďte.
Logfile of random's system information tool 1.06 (written by random/random)
Run by hubsch at 2010-01-11 08:32:08
WIN_XP Service Pack 3
System drive C: has 7 GB (3%) free of 238 GB
Total RAM: 1791 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:32:29, on 11.1.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Elektro\Plocha\RSIT.exe
C:\hubsch.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.warforum.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-3086271954-1183994661-564440380-1125\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-21-3086271954-1183994661-564440380-1125\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: VistaAccess.lnk = C:\VstaScan\VsAccess.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = elektro.local
O17 - HKLM\Software\..\Telephony: DomainName = elektro.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = elektro.local
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
--
End of file - 4741 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Schedule Task Weekly.job
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
StartCCC=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-03-17 61440]
iTunesHelper=C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]
egui=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-11-16 2054360]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
MSMSGS=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Po spuštění
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
VistaAccess.lnk - C:\VstaScan\VsAccess.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-03-16 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
dontdisplaylastusername=0
legalnoticecaption=
legalnoticetext=
shutdownwithoutlogon=1
undockwithoutlogon=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoDriveTypeAutoRun=323
NoResolveTrack=1
NoDriveAutoRun=67108863
NoDrives=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoResolveTrack=
NoResolveSearch=
NoPopUpsOnBoot=
HonorAutoRunSetting=
NoDriveAutoRun=
NoDriveTypeAutoRun=
NoDrives=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
C:\Program Files\ICQLite\ICQLite.exe="C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite"
C:\Program Files\uTorrent\utorrent.exe="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe="C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"
C:\Program Files\Canon\Color Network ScanGear\SgTool.exe="C:\Program Files\Canon\Color Network ScanGear\SgTool.exe:*:Enabled:SGTOOL"
%windir%\Network Diagnostic\xpnetdiag.exe="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
C:\Program Files\Bonjour\mDNSResponder.exe="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
C:\Program Files\iTunes\iTunes.exe="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe="C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"
%windir%\Network Diagnostic\xpnetdiag.exe="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
C:\Program Files\ICQLite\ICQLite.exe="C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite"
C:\Program Files\uTorrent\utorrent.exe="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
C:\Program Files\Java\jre6\bin\javaw.exe="C:\Program Files\Java\jre6\bin\javaw.exe:*:Disabled:Java(TM) Platform SE binary"
C:\Program Files\Java\jre6\bin\java.exe="C:\Program Files\Java\jre6\bin\java.exe:*:Disabled:Java(TM) Platform SE binary"
C:\games\Buccaneer\T3D.exe="C:\games\Buccaneer\T3D.exe:*:Enabled:Buccaneer: The Pursuit of Infamy"
C:\Program Files\Common Files\XpressUpdate\XPressUpdate.exe="C:\Program Files\Common Files\XpressUpdate\XPressUpdate.exe:*:Enabled:XPressUpdate"
C:\Program Files\Brother\Brmfl08h\FAXRX.exe="C:\Program Files\Brother\Brmfl08h\FAXRX.exe:*:Enabled:FAXRX.EXE"
C:\Program Files\iTunes\iTunes.exe="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
======List of files/folders created in the last 1 months======
2010-01-11 08:32:08 ----A---- C:\hubsch.exe
2010-01-08 15:30:45 ----D---- C:\backups
2010-01-08 15:03:59 ----D---- C:\Program Files\SubtitleCreator
2010-01-06 14:37:54 ----SHD---- C:\RECYCLER
2010-01-06 12:54:16 ----D---- C:\WINDOWS\temp
2010-01-06 12:44:53 ----D---- C:\ComboFix
2010-01-05 09:29:37 ----A---- C:\Pokus.bat
2010-01-05 09:03:22 ----A---- C:\Zpráva o Analýze Hijack.txt
2010-01-05 08:04:33 ----A---- C:\ComboFix log.txt
2010-01-05 07:49:19 ----A---- C:\Boot.bak
2010-01-05 07:49:11 ----RASHD---- C:\cmdcons
2010-01-05 07:47:30 ----A---- C:\WINDOWS\MBR.exe
2010-01-05 07:47:29 ----A---- C:\WINDOWS\NIRCMD.exe
2010-01-05 07:47:27 ----A---- C:\WINDOWS\PEV.exe
2010-01-05 07:47:26 ----A---- C:\WINDOWS\zip.exe
2010-01-05 07:47:26 ----A---- C:\WINDOWS\SWSC.exe
2010-01-05 07:47:26 ----A---- C:\WINDOWS\SWREG.exe
2010-01-05 07:47:26 ----A---- C:\WINDOWS\sed.exe
2010-01-05 07:47:26 ----A---- C:\WINDOWS\grep.exe
2010-01-05 07:47:25 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-01-05 07:37:33 ----A---- C:\hijackthis.exe
2010-01-04 07:14:44 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Avira
2009-12-18 14:24:27 ----D---- C:\Documents and Settings\Elektro\Data aplikací\Virtual City
2009-12-17 09:04:07 ----D---- C:\divx
2009-12-17 08:43:29 ----D---- C:\Program Files\Common Files\DivX Shared
2009-12-17 08:35:44 ----A---- C:\DivXInstaller.exe
2009-12-15 13:13:38 ----A---- C:\se-setup.exe
2009-12-15 12:48:09 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-12-15 12:47:39 ----A---- C:\mbam-setup.exe
2009-12-15 11:59:50 ----AD---- C:\WINDOWS\rundll16.exe
2009-12-15 11:59:50 ----AD---- C:\WINDOWS\logo1_.exe
2009-12-15 10:26:43 ----D---- C:\Documents and Settings\Elektro\Data aplikací\DAEMON Tools Lite
2009-12-15 10:26:41 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\DAEMON Tools Lite
2009-12-15 09:05:59 ----D---- C:\Documents and Settings\Elektro\Data aplikací\EurekaLog
2009-12-15 07:46:59 ----D---- C:\Program Files\CCleaner
2009-12-15 07:43:09 ----AD---- C:\WINDOWS\VDLL.DLL
2009-12-15 07:43:09 ----AD---- C:\WINDOWS\system32\runouce.exe
2009-12-15 07:43:09 ----AD---- C:\WINDOWS\RUNDL132.EXE
2009-12-15 07:43:09 ----AD---- C:\WINDOWS\logo_1.exe
2009-12-15 07:42:05 ----A---- C:\WINDOWS\system32\eEmpty.exe
2009-12-15 07:42:02 ----A---- C:\WINDOWS\system32\T.COM
2009-12-15 07:42:01 ----A---- C:\WINDOWS\R.COM
2009-12-15 07:41:58 ----D---- C:\Program Files\Common Files\MicroWorld
2009-12-15 07:41:55 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\MicroWorld
2009-12-15 07:30:03 ----D---- C:\rsit
2009-12-15 07:30:03 ----D---- C:\Program Files\trend micro
2009-12-14 08:35:22 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2009-12-14 08:35:01 ----HDC---- C:\WINDOWS\$NtUninstallKB976098-v2$
2009-12-14 08:34:38 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2009-12-14 08:34:12 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2009-12-14 08:33:22 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2009-12-14 08:32:46 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2009-12-14 08:32:02 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2009-12-14 08:31:25 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2009-12-14 08:31:02 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2009-12-14 08:30:34 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2009-12-14 08:30:03 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2009-12-14 08:28:28 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2009-12-14 08:28:01 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2009-12-14 08:27:31 ----HDC---- C:\WINDOWS\$NtUninstallKB973525$
2009-12-14 08:23:02 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2009-12-14 08:22:35 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2009-12-14 08:22:06 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2009-12-14 07:55:43 ----A---- C:\SeaToolsforWindowsSetup-1201.exe
2009-12-14 07:48:27 ----D---- C:\Documents and Settings\Elektro\Data aplikací\ESET
2009-12-14 07:47:52 ----D---- C:\Program Files\ESET
2009-12-14 07:47:52 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\ESET
======List of files/folders modified in the last 1 months======
2010-01-11 08:31:15 ----A---- C:\WINDOWS\VISTA32.INI
2010-01-11 08:28:36 ----D---- C:\W
2010-01-11 08:16:09 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-11 07:43:58 ----D---- C:\WINDOWS\Prefetch
2010-01-08 15:21:59 ----SHD---- C:\WINDOWS\CSC
2010-01-08 15:03:59 ----RD---- C:\Program Files
2010-01-08 13:52:45 ----A---- C:\WINDOWS\win.ini
2010-01-08 13:37:41 ----SHD---- C:\WINDOWS\Installer
2010-01-08 13:37:40 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-01-08 13:37:40 ----D---- C:\Config.Msi
2010-01-08 11:03:54 ----D---- C:\Program Files\Sony
2010-01-08 10:58:57 ----D---- C:\Documents and Settings\Elektro\Data aplikací\Sony
2010-01-08 10:57:59 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Sony
2010-01-08 10:57:43 ----D---- C:\WINDOWS\system32
2010-01-08 10:57:08 ----D---- C:\WINDOWS\WinSxS
2010-01-08 10:39:34 ----D---- C:\WINDOWS\system32\drivers
2010-01-08 10:36:53 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-08 07:21:29 ----D---- C:\WINDOWS
2010-01-08 07:12:28 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Kaspersky Lab
2010-01-08 07:10:24 ----HD---- C:\WINDOWS\inf
2010-01-07 14:56:27 ----A---- C:\WINDOWS\NeroDigital.ini
2010-01-07 14:36:10 ----D---- C:\WINDOWS\system32\config
2010-01-07 12:58:54 ----D---- C:\WINDOWS\system32\Restore
2010-01-07 12:53:08 ----SHD---- C:\System Volume Information
2010-01-07 11:52:14 ----D---- C:\DVD
2010-01-07 11:01:34 ----A---- C:\WINDOWS\umaxuapi.ini
2010-01-06 12:54:28 ----A---- C:\WINDOWS\system.ini
2010-01-06 12:51:41 ----D---- C:\WINDOWS\AppPatch
2010-01-06 12:51:37 ----D---- C:\Program Files\Common Files
2010-01-06 12:45:16 ----D---- C:\Qoobox
2010-01-06 09:35:27 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-01-06 09:34:36 ----D---- C:\Program Files\Ranch Rush
2010-01-06 09:34:36 ----D---- C:\Program Files\Farm Frenzy 2
2010-01-06 09:34:36 ----D---- C:\Program Files\Ancient Quest of Saqqarah
2010-01-05 09:30:35 ----D---- C:\WINDOWS\SoftwareDistribution
2010-01-05 08:02:49 ----SD---- C:\WINDOWS\Tasks
2010-01-05 08:02:27 ----D---- C:\WINDOWS\ERDNT
2010-01-05 08:00:13 ----D---- C:\WINDOWS\system
2010-01-05 07:49:20 ----RASH---- C:\boot.ini
2010-01-04 18:50:11 ----D---- C:\Program Files\DVD-RB PRO
2010-01-04 14:15:23 ----D---- C:\Documents and Settings\Elektro\Data aplikací\vlc
2010-01-04 13:11:50 ----D---- C:\CENÍKY
2010-01-04 09:40:30 ----SD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Microsoft
2010-01-04 07:40:00 ----D---- C:\Program Files\Easy CD-DA Extractor 12
2009-12-18 14:48:34 ----AD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP
2009-12-18 08:46:50 ----D---- C:\Program Files\DivX
2009-12-17 09:34:22 ----D---- C:\Documents and Settings\Elektro\Data aplikací\dvdcss
2009-12-17 09:33:57 ----D---- C:\Documents and Settings\Elektro\Data aplikací\DivX
2009-12-15 08:35:59 ----RSD---- C:\WINDOWS\assembly
2009-12-15 08:31:54 ----D---- C:\WINDOWS\Microsoft.NET
2009-12-15 07:50:54 ----D---- C:\WINDOWS\Debug
2009-12-15 07:50:53 ----D---- C:\WINDOWS\Minidump
2009-12-15 07:42:07 ----A---- C:\WINDOWS\system32\msvcr80.dll
2009-12-15 07:42:05 ----A---- C:\WINDOWS\system32\msvcp80.dll
2009-12-14 15:20:27 ----D---- C:\Program Files\Canon
2009-12-14 08:38:57 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-12-14 08:35:28 ----D---- C:\WINDOWS\system32\CatRoot
2009-12-14 08:34:42 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-12-14 08:30:33 ----HD---- C:\WINDOWS\$hf_mig$
2009-12-14 08:29:23 ----D---- C:\WINDOWS\system32\cs-cz
2009-12-14 08:29:22 ----D---- C:\Program Files\Internet Explorer
2009-12-14 08:28:59 ----D---- C:\WINDOWS\ie7updates
2009-12-14 07:58:46 ----D---- C:\Program Files\Seagate
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 cdrbsdrv;cdrbsdrv; C:\WINDOWS\system32\drivers\cdrbsdrv.sys [2008-11-04 33408]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-11-16 55768]
R1 HMFAxCore46691b2fe72383a3b643d95081ef1d95;HMFAxCore46691b2fe72383a3b643d95081ef1d95; \??\C:\WINDOWS\system32\drivers\HMFAxCore46691b2fe72383a3b643d95081ef1d95.sys []
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}; \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl []
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2008-10-03 278984]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-11-16 135048]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2008-10-03 25416]
R2 PARCLASS1;PARCLASS1; \??\C:\WINDOWS\system32\drivers\PARCLASS1.sys []
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-03-16 3597312]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-06-19 33096]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-01-30 4725760]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [2004-08-15 5810]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtenicxp.sys [2007-12-05 104064]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-10-24 6784]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-13 17152]
S2 DeviceScanner;UMAX Astra 4400 Scanner; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S2 Parclass;Parclass; C:\WINDOWS\System32\Drivers\Parclass.sys [2006-12-08 20272]
S3 afepmrjq;afepmrjq; C:\WINDOWS\system32\drivers\afepmrjq.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\Elektro\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 cpuz132;cpuz132; \??\C:\WINDOWS\system32\drivers\cpuz132_x32.sys []
S3 CXFALCON;AVerMedia AVerTV Video Capture (Falcon); C:\WINDOWS\system32\drivers\AF2VCap.sys [2006-06-23 345344]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys []
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2008-09-09 47360]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys []
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2005-10-21 12800]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-08-28 40448]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\system32\DRIVERS\sr.sys [2008-04-14 73344]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2003-04-16 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-03-16 602112]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-11-16 735960]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2008-04-08 241734]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-11-16 20680]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2008-11-21 79360]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-03-17 593920]
S4 Canon Driver Information Assist Service;Canon Driver Information Assist Service; C:\Program Files\Canon\DIAS\CnxDIAS.exe []
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------