Strasne spomaleny notebook mam :(
Napsal: 20 led 2010 18:48
Zdravim strasne pomaly ide mi notebook...neviem preco..antivirak nemam este ted ziadny nainstalovany....doraz nainstalujem...mam original ESS tu je log z RSIT :
Logfile of random's system information tool 1.06 (written by random/random)
Run by Jozef Čopík at 2010-01-20 18:47:36
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 119 GB (78%) free of 153 GB
Total RAM: 1014 MB (53% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:47:45, on 20.1.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AhnRpta.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\VVSN\VVSN.exe
C:\Program Files\Hotbar\bin\11.0.78.0\HotbarSA.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hotbar\bin\11.0.78.0\Weather.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Opera\Opera.exe
F:\Programy\Programy na Vyrusy\RSIT.exe
C:\Program Files\trend micro\Jozef Čopík.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.gamingharbor.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Jozef Čopík\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: ShopperReports - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShopperReports3\bin\3.0.268.0\ShopperReports.dll
O2 - BHO: Media Access Startup - {25B8D58C-B0CB-46b0-BA64-05B3804E4E86} - (no file)
O2 - BHO: NP Helper Class - {35B8D58C-B0CB-46b0-BA64-05B3804E4E86} - (no file)
O2 - BHO: Hotbar - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Hotbar\bin\11.0.78.0\HostIE.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Jozef Čopík\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: System Search Dispatcher - {CDBFB47B-58A8-4111-BF95-06178DCE326D} - C:\Program Files\System Search Dispatcher\1.4.0.970\ssd.dll
O3 - Toolbar: Hotbar - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Hotbar\bin\11.0.78.0\HostIE.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [nvch] rundll32.exe rchnewver.dll,go
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe
O4 - HKLM\..\Run: [HotbarSA] "C:\Program Files\Hotbar\bin\11.0.78.0\HotbarSA.exe"
O4 - HKLM\..\RunOnce: [NSSInstallation] C:\WINDOWS\system32\Adobe\Shockwave 11\nssstub.exe /runonce
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe
O4 - HKCU\..\Run: [cdoosoft] C:\DOCUME~1\JOZEFO~1\LOCALS~1\Temp\herss.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [WeatherDPA] "C:\Program Files\Hotbar\bin\11.0.78.0\Weather.exe" -auto
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShopperReports3\bin\3.0.268.0\ShopperReports.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShopperReports3\bin\3.0.268.0\ShopperReports.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
--
End of file - 6965 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\NSSstub.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{100EB1FD-D03E-47FD-81F3-EE91287F9465}]
ShopperReports - C:\Program Files\ShopperReports3\bin\3.0.268.0\ShopperReports.dll [2009-12-21 1081856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25B8D58C-B0CB-46b0-BA64-05B3804E4E86}]
Media Access Startup
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35B8D58C-B0CB-46b0-BA64-05B3804E4E86}]
NP Helper Class
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B}]
Hotbar - C:\Program Files\Hotbar\bin\11.0.78.0\HostIE.dll [2009-09-15 537904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Documents and Settings\Jozef Čopík\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2009-07-14 150768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CDBFB47B-58A8-4111-BF95-06178DCE326D}]
System Search Dispatcher - C:\Program Files\System Search Dispatcher\1.4.0.970\ssd.dll [2009-08-21 294912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - Hotbar - C:\Program Files\Hotbar\bin\11.0.78.0\HostIE.dll [2009-09-15 537904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2009-06-12 16861696]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2009-06-12 69632]
"AzMixerSel"=C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe [2009-06-12 53248]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2009-06-12 141848]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2009-06-12 166424]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2009-06-12 137752]
"nvch"=rchnewver.dll,go []
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"VVSN"=C:\Program Files\VVSN\VVSN.exe [2005-10-25 107520]
"HotbarSA"=C:\Program Files\Hotbar\bin\11.0.78.0\HotbarSA.exe [2009-09-15 768816]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"NSSInstallation"=C:\WINDOWS\system32\Adobe\Shockwave 11\nssstub.exe [2009-11-14 284024]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"kamsoft"=C:\WINDOWS\system32\ckvo.exe [2008-10-25 106524]
"cdoosoft"=C:\DOCUME~1\JOZEFO~1\LOCALS~1\Temp\herss.exe [2010-01-19 118272]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe []
"WeatherDPA"=C:\Program Files\Hotbar\bin\11.0.78.0\Weather.exe [2009-09-15 353584]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2007-09-13 22880040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2009-06-12 208896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B03A4BE6-5E5A-483E-B9B3-C484D4B20B72}"=C:\WINDOWS\system32\softqq1.dll [2008-04-14 165637]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\usmt\migwiz.exe"="C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Průvodce přenesením souborů a nastavení"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"c:\program files\relevantknowledge\rlvknlg.exe"="c:\program files\relevantknowledge\rlvknlg.exe:*:Enabled:rlvknlg.exe"
"C:\Program Files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat"="C:\Program Files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{90085232-76cd-11de-a8a3-001eec51da1d}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bcf1ea79-59c5-11de-a86a-001eec51da1d}]
shell\AutoRun\command - E:\xih9.cmd
shell\explore\command - E:\xih9.cmd
shell\open\command - E:\xih9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f31a3ac1-e27f-11de-a9ca-001eec51da1d}]
shell\AutoRun\command - E:\xih9.cmd
shell\explore\command - E:\xih9.cmd
shell\open\command - E:\xih9.cmd
======List of files/folders created in the last 1 months======
2010-01-20 18:47:37 ----D---- C:\Program Files\trend micro
2010-01-20 18:47:36 ----D---- C:\rsit
2010-01-19 19:17:16 ----D---- C:\Program Files\Photodex Presenter
2010-01-19 19:17:16 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Netscape
2010-01-19 19:17:03 ----D---- C:\Program Files\Photodex
2010-01-19 19:16:48 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Photodex
2010-01-19 18:39:18 ----RSH---- C:\9fo3ar0j.exe
2010-01-18 17:58:00 ----RSH---- C:\sywyrl0q.exe
2010-01-17 21:00:21 ----D---- C:\Program Files\MPC HomeCinema
2010-01-17 20:58:05 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Opera
2010-01-17 20:57:54 ----D---- C:\Program Files\Opera
2010-01-17 20:33:04 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Ashampoo
2010-01-17 20:32:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\ashampoo
2010-01-17 20:32:31 ----D---- C:\Program Files\Ashampoo
2010-01-17 20:30:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2010-01-17 20:29:53 ----A---- C:\WINDOWS\ODBC.INI
2010-01-17 20:29:47 ----A---- C:\WINDOWS\system32\mdimon.dll
2010-01-17 20:28:38 ----D---- C:\Program Files\Common Files\DESIGNER
2010-01-17 20:28:32 ----D---- C:\Program Files\Microsoft Works
2010-01-17 20:28:26 ----D---- C:\Program Files\Microsoft Visual Studio
2010-01-17 20:28:06 ----D---- C:\WINDOWS\SHELLNEW
2010-01-17 20:28:03 ----D---- C:\Program Files\Microsoft.NET
2010-01-17 20:28:03 ----D---- C:\Program Files\Microsoft Office
2010-01-17 20:25:19 ----RHD---- C:\MSOCache
2010-01-17 20:24:59 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Skype
2010-01-17 20:24:26 ----D---- C:\Program Files\Skype
2010-01-17 20:24:26 ----D---- C:\Program Files\Common Files\Skype
2010-01-17 20:24:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2010-01-17 20:05:02 ----SHD---- C:\Config.Msi
2010-01-17 19:48:43 ----D---- C:\Program Files\QIP
2010-01-17 19:27:19 ----D---- C:\Program Files\CCleaner
2010-01-17 18:24:13 ----RSH---- C:\9xf8.exe
2010-01-16 17:27:56 ----RSH---- C:\mh.exe
2010-01-12 17:32:53 ----RSH---- C:\kmj.exe
2010-01-09 16:42:38 ----RSH---- C:\8xcrbho6.exe
2010-01-09 15:40:08 ----RSH---- C:\ljy.exe
2010-01-08 18:33:23 ----RSH---- C:\31lyx.exe
2010-01-08 18:17:45 ----RSH---- C:\mltox.exe
2010-01-07 19:09:46 ----RSH---- C:\f2kmj.exe
2010-01-07 17:28:42 ----D---- C:\Program Files\Microsoft Silverlight
2010-01-04 13:44:34 ----RSH---- C:\e9naq.exe
2010-01-01 18:13:18 ----RSH---- C:\h0.exe
2009-12-31 10:37:15 ----RSH---- C:\anoataly.exe
2009-12-30 17:39:24 ----RSH---- C:\wisf1.exe
2009-12-29 19:07:50 ----RSH---- C:\3exi.exe
2009-12-28 19:04:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\HotbarSA
2009-12-28 19:04:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
2009-12-28 19:04:55 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\WeatherDPA
2009-12-28 19:04:50 ----D---- C:\Program Files\Hotbar
2009-12-28 19:04:50 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Hotbar
2009-12-28 19:04:17 ----D---- C:\Program Files\ShopperReports3
2009-12-28 19:04:17 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\ShopperReports3
2009-12-26 19:02:45 ----RSH---- C:\imghyva6.exe
2009-12-23 19:40:30 ----RSH---- C:\u16sqrqn.exe
======List of files/folders modified in the last 1 months======
2010-01-20 18:47:44 ----D---- C:\WINDOWS\Prefetch
2010-01-20 18:47:37 ----RD---- C:\Program Files
2010-01-20 15:01:37 ----D---- C:\Program Files\Mozilla Firefox
2010-01-20 14:11:23 ----D---- C:\WINDOWS\system32
2010-01-20 14:11:22 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-01-20 14:06:48 ----D---- C:\WINDOWS\Temp
2010-01-20 14:06:43 ----RSH---- C:\WINDOWS\system32\ckvo0.dll
2010-01-20 14:06:43 ----D---- C:\WINDOWS\system32\drivers
2010-01-20 13:08:48 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-19 19:17:16 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Mozilla
2010-01-17 21:43:18 ----SD---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Microsoft
2010-01-17 20:58:04 ----SHD---- C:\WINDOWS\Installer
2010-01-17 20:48:13 ----D---- C:\Program Files\Google
2010-01-17 20:30:20 ----SD---- C:\WINDOWS\Tasks
2010-01-17 20:29:58 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-01-17 20:29:53 ----AD---- C:\WINDOWS
2010-01-17 20:29:41 ----RSD---- C:\WINDOWS\assembly
2010-01-17 20:29:36 ----A---- C:\WINDOWS\win.ini
2010-01-17 20:29:19 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-01-17 20:29:16 ----RSD---- C:\WINDOWS\Fonts
2010-01-17 20:28:38 ----D---- C:\Program Files\Common Files
2010-01-17 20:28:36 ----HD---- C:\WINDOWS\inf
2010-01-17 20:28:11 ----D---- C:\Program Files\Common Files\System
2010-01-17 20:25:24 ----D---- C:\WINDOWS\system
2010-01-17 20:08:18 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-17 20:07:42 ----D---- C:\Program Files\EA SPORTS
2010-01-17 19:58:47 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-17 19:58:31 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\uTorrent
2010-01-17 19:55:34 ----D---- C:\Program Files\PowerISO
2010-01-17 19:44:23 ----HDC---- C:\Documents and Settings\All Users\Data aplikací\~0
2010-01-17 19:27:55 ----D---- C:\WINDOWS\Minidump
2010-01-17 19:27:55 ----D---- C:\WINDOWS\Debug
2010-01-12 16:46:29 ----A---- C:\WINDOWS\wwp.INI
2010-01-07 18:21:44 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Google
2010-01-03 14:00:13 ----SHD---- C:\RECYCLER
2010-01-02 15:00:19 ----D---- C:\WINDOWS\system32\Adobe
2010-01-02 14:42:59 ----RSH---- C:\WINDOWS\system32\nmdfgds0.dll
2010-01-02 14:42:56 ----RSH---- C:\yudald.bat
2010-01-02 14:42:56 ----RSH---- C:\WINDOWS\system32\olhrwef.exe
2009-12-21 11:29:35 ----RSH---- C:\nx.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2008-04-14 225664]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2008-04-14 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2008-04-14 55936]
R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2007-07-26 547904]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2008-05-30 161792]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2009-06-12 5851488]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-06-12 4785664]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2009-11-19 223128]
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-14 40320]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 6to4;Pomocná služba protokolu IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 NwSapAgent;Agent SAP; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 ScsiAccess;ScsiAccess; C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe [2010-01-19 181312]
R2 SNMP;SNMP; C:\WINDOWS\System32\snmp.exe [2008-04-14 32768]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268288]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-21 182768]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 LPDSVC;Tiskový server TCP/IP; C:\WINDOWS\system32\tcpsvcs.exe [2008-04-14 19456]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SNMPTRAP;Zachytávání pro službu SNMP; C:\WINDOWS\System32\snmptrap.exe [2008-04-14 8704]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by Jozef Čopík at 2010-01-20 18:47:36
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 119 GB (78%) free of 153 GB
Total RAM: 1014 MB (53% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:47:45, on 20.1.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AhnRpta.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\VVSN\VVSN.exe
C:\Program Files\Hotbar\bin\11.0.78.0\HotbarSA.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hotbar\bin\11.0.78.0\Weather.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Opera\Opera.exe
F:\Programy\Programy na Vyrusy\RSIT.exe
C:\Program Files\trend micro\Jozef Čopík.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.gamingharbor.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Jozef Čopík\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: ShopperReports - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShopperReports3\bin\3.0.268.0\ShopperReports.dll
O2 - BHO: Media Access Startup - {25B8D58C-B0CB-46b0-BA64-05B3804E4E86} - (no file)
O2 - BHO: NP Helper Class - {35B8D58C-B0CB-46b0-BA64-05B3804E4E86} - (no file)
O2 - BHO: Hotbar - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Hotbar\bin\11.0.78.0\HostIE.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Jozef Čopík\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: System Search Dispatcher - {CDBFB47B-58A8-4111-BF95-06178DCE326D} - C:\Program Files\System Search Dispatcher\1.4.0.970\ssd.dll
O3 - Toolbar: Hotbar - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Hotbar\bin\11.0.78.0\HostIE.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [nvch] rundll32.exe rchnewver.dll,go
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe
O4 - HKLM\..\Run: [HotbarSA] "C:\Program Files\Hotbar\bin\11.0.78.0\HotbarSA.exe"
O4 - HKLM\..\RunOnce: [NSSInstallation] C:\WINDOWS\system32\Adobe\Shockwave 11\nssstub.exe /runonce
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe
O4 - HKCU\..\Run: [cdoosoft] C:\DOCUME~1\JOZEFO~1\LOCALS~1\Temp\herss.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [WeatherDPA] "C:\Program Files\Hotbar\bin\11.0.78.0\Weather.exe" -auto
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShopperReports3\bin\3.0.268.0\ShopperReports.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShopperReports3\bin\3.0.268.0\ShopperReports.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
--
End of file - 6965 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\NSSstub.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{100EB1FD-D03E-47FD-81F3-EE91287F9465}]
ShopperReports - C:\Program Files\ShopperReports3\bin\3.0.268.0\ShopperReports.dll [2009-12-21 1081856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25B8D58C-B0CB-46b0-BA64-05B3804E4E86}]
Media Access Startup
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35B8D58C-B0CB-46b0-BA64-05B3804E4E86}]
NP Helper Class
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B}]
Hotbar - C:\Program Files\Hotbar\bin\11.0.78.0\HostIE.dll [2009-09-15 537904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Documents and Settings\Jozef Čopík\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2009-07-14 150768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CDBFB47B-58A8-4111-BF95-06178DCE326D}]
System Search Dispatcher - C:\Program Files\System Search Dispatcher\1.4.0.970\ssd.dll [2009-08-21 294912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - Hotbar - C:\Program Files\Hotbar\bin\11.0.78.0\HostIE.dll [2009-09-15 537904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2009-06-12 16861696]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2009-06-12 69632]
"AzMixerSel"=C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe [2009-06-12 53248]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2009-06-12 141848]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2009-06-12 166424]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2009-06-12 137752]
"nvch"=rchnewver.dll,go []
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"VVSN"=C:\Program Files\VVSN\VVSN.exe [2005-10-25 107520]
"HotbarSA"=C:\Program Files\Hotbar\bin\11.0.78.0\HotbarSA.exe [2009-09-15 768816]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"NSSInstallation"=C:\WINDOWS\system32\Adobe\Shockwave 11\nssstub.exe [2009-11-14 284024]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"kamsoft"=C:\WINDOWS\system32\ckvo.exe [2008-10-25 106524]
"cdoosoft"=C:\DOCUME~1\JOZEFO~1\LOCALS~1\Temp\herss.exe [2010-01-19 118272]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe []
"WeatherDPA"=C:\Program Files\Hotbar\bin\11.0.78.0\Weather.exe [2009-09-15 353584]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2007-09-13 22880040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2009-06-12 208896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B03A4BE6-5E5A-483E-B9B3-C484D4B20B72}"=C:\WINDOWS\system32\softqq1.dll [2008-04-14 165637]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\usmt\migwiz.exe"="C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Průvodce přenesením souborů a nastavení"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"c:\program files\relevantknowledge\rlvknlg.exe"="c:\program files\relevantknowledge\rlvknlg.exe:*:Enabled:rlvknlg.exe"
"C:\Program Files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat"="C:\Program Files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{90085232-76cd-11de-a8a3-001eec51da1d}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bcf1ea79-59c5-11de-a86a-001eec51da1d}]
shell\AutoRun\command - E:\xih9.cmd
shell\explore\command - E:\xih9.cmd
shell\open\command - E:\xih9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f31a3ac1-e27f-11de-a9ca-001eec51da1d}]
shell\AutoRun\command - E:\xih9.cmd
shell\explore\command - E:\xih9.cmd
shell\open\command - E:\xih9.cmd
======List of files/folders created in the last 1 months======
2010-01-20 18:47:37 ----D---- C:\Program Files\trend micro
2010-01-20 18:47:36 ----D---- C:\rsit
2010-01-19 19:17:16 ----D---- C:\Program Files\Photodex Presenter
2010-01-19 19:17:16 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Netscape
2010-01-19 19:17:03 ----D---- C:\Program Files\Photodex
2010-01-19 19:16:48 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Photodex
2010-01-19 18:39:18 ----RSH---- C:\9fo3ar0j.exe
2010-01-18 17:58:00 ----RSH---- C:\sywyrl0q.exe
2010-01-17 21:00:21 ----D---- C:\Program Files\MPC HomeCinema
2010-01-17 20:58:05 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Opera
2010-01-17 20:57:54 ----D---- C:\Program Files\Opera
2010-01-17 20:33:04 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Ashampoo
2010-01-17 20:32:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\ashampoo
2010-01-17 20:32:31 ----D---- C:\Program Files\Ashampoo
2010-01-17 20:30:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2010-01-17 20:29:53 ----A---- C:\WINDOWS\ODBC.INI
2010-01-17 20:29:47 ----A---- C:\WINDOWS\system32\mdimon.dll
2010-01-17 20:28:38 ----D---- C:\Program Files\Common Files\DESIGNER
2010-01-17 20:28:32 ----D---- C:\Program Files\Microsoft Works
2010-01-17 20:28:26 ----D---- C:\Program Files\Microsoft Visual Studio
2010-01-17 20:28:06 ----D---- C:\WINDOWS\SHELLNEW
2010-01-17 20:28:03 ----D---- C:\Program Files\Microsoft.NET
2010-01-17 20:28:03 ----D---- C:\Program Files\Microsoft Office
2010-01-17 20:25:19 ----RHD---- C:\MSOCache
2010-01-17 20:24:59 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Skype
2010-01-17 20:24:26 ----D---- C:\Program Files\Skype
2010-01-17 20:24:26 ----D---- C:\Program Files\Common Files\Skype
2010-01-17 20:24:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2010-01-17 20:05:02 ----SHD---- C:\Config.Msi
2010-01-17 19:48:43 ----D---- C:\Program Files\QIP
2010-01-17 19:27:19 ----D---- C:\Program Files\CCleaner
2010-01-17 18:24:13 ----RSH---- C:\9xf8.exe
2010-01-16 17:27:56 ----RSH---- C:\mh.exe
2010-01-12 17:32:53 ----RSH---- C:\kmj.exe
2010-01-09 16:42:38 ----RSH---- C:\8xcrbho6.exe
2010-01-09 15:40:08 ----RSH---- C:\ljy.exe
2010-01-08 18:33:23 ----RSH---- C:\31lyx.exe
2010-01-08 18:17:45 ----RSH---- C:\mltox.exe
2010-01-07 19:09:46 ----RSH---- C:\f2kmj.exe
2010-01-07 17:28:42 ----D---- C:\Program Files\Microsoft Silverlight
2010-01-04 13:44:34 ----RSH---- C:\e9naq.exe
2010-01-01 18:13:18 ----RSH---- C:\h0.exe
2009-12-31 10:37:15 ----RSH---- C:\anoataly.exe
2009-12-30 17:39:24 ----RSH---- C:\wisf1.exe
2009-12-29 19:07:50 ----RSH---- C:\3exi.exe
2009-12-28 19:04:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\HotbarSA
2009-12-28 19:04:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
2009-12-28 19:04:55 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\WeatherDPA
2009-12-28 19:04:50 ----D---- C:\Program Files\Hotbar
2009-12-28 19:04:50 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Hotbar
2009-12-28 19:04:17 ----D---- C:\Program Files\ShopperReports3
2009-12-28 19:04:17 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\ShopperReports3
2009-12-26 19:02:45 ----RSH---- C:\imghyva6.exe
2009-12-23 19:40:30 ----RSH---- C:\u16sqrqn.exe
======List of files/folders modified in the last 1 months======
2010-01-20 18:47:44 ----D---- C:\WINDOWS\Prefetch
2010-01-20 18:47:37 ----RD---- C:\Program Files
2010-01-20 15:01:37 ----D---- C:\Program Files\Mozilla Firefox
2010-01-20 14:11:23 ----D---- C:\WINDOWS\system32
2010-01-20 14:11:22 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-01-20 14:06:48 ----D---- C:\WINDOWS\Temp
2010-01-20 14:06:43 ----RSH---- C:\WINDOWS\system32\ckvo0.dll
2010-01-20 14:06:43 ----D---- C:\WINDOWS\system32\drivers
2010-01-20 13:08:48 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-19 19:17:16 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Mozilla
2010-01-17 21:43:18 ----SD---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Microsoft
2010-01-17 20:58:04 ----SHD---- C:\WINDOWS\Installer
2010-01-17 20:48:13 ----D---- C:\Program Files\Google
2010-01-17 20:30:20 ----SD---- C:\WINDOWS\Tasks
2010-01-17 20:29:58 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-01-17 20:29:53 ----AD---- C:\WINDOWS
2010-01-17 20:29:41 ----RSD---- C:\WINDOWS\assembly
2010-01-17 20:29:36 ----A---- C:\WINDOWS\win.ini
2010-01-17 20:29:19 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-01-17 20:29:16 ----RSD---- C:\WINDOWS\Fonts
2010-01-17 20:28:38 ----D---- C:\Program Files\Common Files
2010-01-17 20:28:36 ----HD---- C:\WINDOWS\inf
2010-01-17 20:28:11 ----D---- C:\Program Files\Common Files\System
2010-01-17 20:25:24 ----D---- C:\WINDOWS\system
2010-01-17 20:08:18 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-17 20:07:42 ----D---- C:\Program Files\EA SPORTS
2010-01-17 19:58:47 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-17 19:58:31 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\uTorrent
2010-01-17 19:55:34 ----D---- C:\Program Files\PowerISO
2010-01-17 19:44:23 ----HDC---- C:\Documents and Settings\All Users\Data aplikací\~0
2010-01-17 19:27:55 ----D---- C:\WINDOWS\Minidump
2010-01-17 19:27:55 ----D---- C:\WINDOWS\Debug
2010-01-12 16:46:29 ----A---- C:\WINDOWS\wwp.INI
2010-01-07 18:21:44 ----D---- C:\Documents and Settings\Jozef Čopík\Data aplikací\Google
2010-01-03 14:00:13 ----SHD---- C:\RECYCLER
2010-01-02 15:00:19 ----D---- C:\WINDOWS\system32\Adobe
2010-01-02 14:42:59 ----RSH---- C:\WINDOWS\system32\nmdfgds0.dll
2010-01-02 14:42:56 ----RSH---- C:\yudald.bat
2010-01-02 14:42:56 ----RSH---- C:\WINDOWS\system32\olhrwef.exe
2009-12-21 11:29:35 ----RSH---- C:\nx.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2008-04-14 225664]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2008-04-14 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2008-04-14 55936]
R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2007-07-26 547904]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2008-05-30 161792]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2009-06-12 5851488]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-06-12 4785664]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2009-11-19 223128]
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-14 40320]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 6to4;Pomocná služba protokolu IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 NwSapAgent;Agent SAP; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 ScsiAccess;ScsiAccess; C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe [2010-01-19 181312]
R2 SNMP;SNMP; C:\WINDOWS\System32\snmp.exe [2008-04-14 32768]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268288]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-21 182768]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 LPDSVC;Tiskový server TCP/IP; C:\WINDOWS\system32\tcpsvcs.exe [2008-04-14 19456]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SNMPTRAP;Zachytávání pro službu SNMP; C:\WINDOWS\System32\snmptrap.exe [2008-04-14 8704]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]
-----------------EOF-----------------