Prosim o kontrolu logu,problem s yourgot.com
Napsal: 14 úno 2010 14:39
Po pripojeni na net mi vybehne okno od antiviru-blokovanie yourgot.com. Prosim o kontrolu logu:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Rasto at 2010-02-14 14:34:38
Microsoft Windows XP Professional Service Pack 3
System drive C: has 59 GB (45%) free of 131 GB
Total RAM: 2047 MB (74% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:35:10, on 14. 2. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AGI\common\win32\PythonService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Rasto\Desktop\RSIT.exe
C:\Program Files\trend micro\Rasto.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 5307 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-08 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-08 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-03-01 577536]
"VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2005-03-08 53248]
"VTTrayp"=C:\WINDOWS\system32\VTtrayp.exe [2005-08-03 163840]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-03-19 2029640]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-05-20 98304]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-01-11 246504]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-05-16 155648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoDriveTypeAutoRun"=323
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\sdc203\StrongDC.exe"="C:\Program Files\sdc203\StrongDC.exe:*:Enabled:StrongDC++"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\utorent\utorrent.exe"="C:\Program Files\utorent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2010-02-14 14:34:38 ----D---- C:\rsit
2010-02-14 14:34:38 ----D---- C:\Program Files\trend micro
2010-02-14 14:20:13 ----A---- C:\ComboFix.txt
2010-02-14 14:03:03 ----A---- C:\WINDOWS\MBR.exe
2010-02-14 14:03:00 ----A---- C:\WINDOWS\PEV.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\zip.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\SWSC.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\SWREG.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\sed.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\NIRCMD.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\grep.exe
2010-02-11 17:17:04 ----D---- C:\New Folder
2010-02-10 19:27:15 ----D---- C:\Documents and Settings\Rasto\Application Data\Broken Sword 2.5
2010-02-09 20:46:08 ----A---- C:\WINDOWS\system32\PnkBstrA.exe
2010-02-09 20:45:54 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2010-02-09 20:41:22 ----D---- C:\WINDOWS\system32\LogFiles
2010-02-09 19:16:01 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2010-02-09 19:16:01 ----A---- C:\WINDOWS\system32\x3daudio1_2.dll
2010-02-09 19:16:00 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2010-02-09 19:16:00 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2010-02-09 19:15:59 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2010-02-09 19:15:58 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2010-02-09 19:15:56 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2010-02-09 19:15:53 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2010-02-09 19:15:53 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2010-02-09 19:15:49 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2010-02-09 19:15:48 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2010-02-09 19:15:48 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2010-02-09 19:06:57 ----D---- C:\Program Files\DAEMON Tools Lite
2010-02-09 19:05:50 ----D---- C:\Documents and Settings\Rasto\Application Data\DAEMON Tools Lite
2010-02-09 19:05:46 ----D---- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
2010-02-09 12:20:17 ----D---- C:\WINDOWS\Sun
2010-02-08 21:11:22 ----D---- C:\Documents and Settings\All Users\Application Data\Sun
2010-02-08 21:11:18 ----D---- C:\Program Files\Common Files\Java
2010-02-08 21:10:44 ----A---- C:\WINDOWS\system32\javaws.exe
2010-02-08 21:10:44 ----A---- C:\WINDOWS\system32\javaw.exe
2010-02-08 21:10:44 ----A---- C:\WINDOWS\system32\java.exe
2010-02-08 21:10:44 ----A---- C:\WINDOWS\system32\deploytk.dll
2010-02-08 21:09:48 ----D---- C:\Program Files\Java
2010-02-08 18:44:20 ----D---- C:\MAMA NAPALIT
2010-02-07 20:43:05 ----A---- C:\WINDOWS\doom3.ini
2010-02-07 13:55:54 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2010-02-04 16:38:28 ----D---- C:\instalacky
2010-02-02 17:22:26 ----SHD---- C:\WINDOWS\ftpcache
2010-02-01 19:09:35 ----D---- C:\Documents and Settings\Rasto\Application Data\ATI
2010-02-01 19:09:35 ----D---- C:\Documents and Settings\All Users\Application Data\ATI
2010-02-01 19:00:51 ----D---- C:\Program Files\Common Files\ATI Technologies
2010-02-01 18:59:12 ----D---- C:\WINDOWS\RegisteredPackages
2010-02-01 18:57:35 ----A---- C:\WINDOWS\system32\psisdecd.dll
2010-02-01 18:57:23 ----A---- C:\WINDOWS\system32\dxdllreg.exe
2010-02-01 18:53:11 ----RSD---- C:\WINDOWS\assembly
2010-02-01 18:52:04 ----D---- C:\WINDOWS\Microsoft.NET
2010-02-01 18:50:35 ----N---- C:\WINDOWS\system32\ati2sgag.exe
2010-02-01 18:50:29 ----RA---- C:\WINDOWS\system32\atiiiexx.dll
2010-02-01 18:50:21 ----RA---- C:\WINDOWS\system32\ATIDEMGX.dll
2010-02-01 18:49:17 ----D---- C:\Program Files\ATI Technologies
2010-01-28 17:11:41 ----D---- C:\Program Files\PC Wizard 2008
2010-01-27 17:47:19 ----D---- C:\technicke info
2010-01-26 17:31:46 ----D---- C:\obrazky
2010-01-25 19:02:35 ----D---- C:\WINDOWS\system32\languages
2010-01-25 17:29:36 ----D---- C:\Documents and Settings\Rasto\Application Data\BSplayer Pro
2010-01-25 17:29:36 ----D---- C:\Documents and Settings\Rasto\Application Data\BSplayer
2010-01-25 16:00:37 ----D---- C:\Samsung
======List of files/folders modified in the last 1 months======
2010-02-14 14:34:57 ----D---- C:\WINDOWS\temp
2010-02-14 14:34:38 ----RD---- C:\Program Files
2010-02-14 14:30:25 ----D---- C:\Program Files\Mozilla Firefox
2010-02-14 14:20:05 ----D---- C:\Qoobox
2010-02-14 14:18:15 ----D---- C:\WINDOWS\ERDNT
2010-02-14 14:18:02 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-14 14:14:41 ----AD---- C:\WINDOWS
2010-02-14 14:14:41 ----A---- C:\WINDOWS\system.ini
2010-02-14 14:13:12 ----D---- C:\WINDOWS\system32\drivers
2010-02-14 14:10:57 ----D---- C:\WINDOWS\system32\config
2010-02-14 14:09:11 ----D---- C:\WINDOWS\system32
2010-02-14 14:09:09 ----D---- C:\Program Files\ICQ6.5
2010-02-14 14:08:02 ----D---- C:\WINDOWS\AppPatch
2010-02-14 14:07:56 ----D---- C:\Program Files\Common Files
2010-02-14 14:03:16 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-14 13:58:44 ----A---- C:\WINDOWS\wincmd.ini
2010-02-14 13:40:18 ----A---- C:\WINDOWS\wininit.ini
2010-02-13 23:00:32 ----D---- C:\WINDOWS\Prefetch
2010-02-13 22:30:25 ----SD---- C:\WINDOWS\Tasks
2010-02-13 21:44:23 ----D---- C:\torenty
2010-02-13 21:35:17 ----D---- C:\Documents and Settings\Rasto\Application Data\Skype
2010-02-13 19:55:41 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-13 15:18:35 ----D---- C:\instalacky programov
2010-02-12 18:15:11 ----D---- C:\hry
2010-02-12 16:29:36 ----HD---- C:\WINDOWS\inf
2010-02-12 13:22:44 ----D---- C:\Program Files\BSplayer
2010-02-11 21:17:35 ----D---- C:\Documents and Settings\All Users\Application Data\NFS Underground
2010-02-11 17:18:18 ----D---- C:\Documents and Settings\Rasto\Application Data\uTorrent
2010-02-11 17:01:05 ----D---- C:\Filmy
2010-02-10 12:55:33 ----D---- C:\Documents and Settings\Rasto\Application Data\ICQ
2010-02-09 20:41:27 ----SHD---- C:\WINDOWS\Installer
2010-02-09 19:16:02 ----D---- C:\WINDOWS\system32\DirectX
2010-02-09 18:14:54 ----D---- C:\instalacky hier
2010-02-07 13:14:00 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-06 19:19:27 ----SD---- C:\Documents and Settings\Rasto\Application Data\Microsoft
2010-02-06 18:43:28 ----RSD---- C:\WINDOWS\Fonts
2010-02-04 23:45:56 ----D---- C:\WINDOWS\Minidump
2010-02-01 19:03:41 ----D---- C:\WINDOWS\WinSxS
2010-02-01 18:59:12 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-01 18:56:45 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-02-01 18:52:14 ----D---- C:\Program Files\Internet Explorer
2010-02-01 18:48:12 ----D---- C:\Program Files\Common Files\InstallShield
2010-01-28 17:35:04 ----D---- C:\Program Files\Adobe
2010-01-25 19:02:37 ----D---- C:\Program Files\Codec Pack - All In 1
2010-01-25 19:01:38 ----A---- C:\WINDOWS\iun6002.exe
2010-01-23 18:09:14 ----D---- C:\Documents and Settings\Rasto\Application Data\Happy Foto
2010-01-16 14:15:12 ----D---- C:\faktury slovanet
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 BIOS;BIOS; \??\C:\WINDOWS\System32\drivers\BIOS.sys []
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-03-19 107256]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2009-02-17 24232]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-03-19 55768]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 36352]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-03-19 113960]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-03-19 131976]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-05-19 3965056]
R3 AnyDVD;AnyDVD; C:\WINDOWS\System32\Drivers\AnyDVD.sys [2009-03-18 103744]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-05-16 4069888]
R3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-03-19 33096]
R3 FETND5BV;VIA Rhine-Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2004-12-16 42496]
R3 OVT511Plus;Dual Mode USB Camera Plus; C:\WINDOWS\System32\Drivers\omcamvid.sys [2001-09-18 167816]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-05-24 47360]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 ayk4v5st;ayk4v5st; C:\WINDOWS\system32\drivers\ayk4v5st.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mbr;mbr; \??\C:\DOCUME~1\Rasto\LOCALS~1\Temp\mbr.sys []
S3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\WINDOWS\system32\DRIVERS\mcdbus.sys []
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 nv4;nv4; C:\WINDOWS\System32\DRIVERS\nv4.sys [2001-08-17 731648]
S3 S3chipid;S3chipid; \??\C:\DOCUME~1\Rasto\LOCALS~1\Temp\{2B43252C-A1E3-4C47-927C-9F2C276D3515}\S3chipid.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 viagfx;viagfx; C:\WINDOWS\system32\DRIVERS\vtmini.sys [2005-08-11 237312]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-23 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AGWinService;AG Windows Service; C:\Program Files\AGI\common\win32\PythonService.exe [2009-01-26 10240]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-05-16 602112]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-03-19 731840]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-02-08 153376]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-12-05 935208]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2010-02-10 66872]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-05-15 593920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-03-19 20680]
S3 getPlus(R) Helper;getPlus(R) Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-10-06 33752]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by Rasto at 2010-02-14 14:34:38
Microsoft Windows XP Professional Service Pack 3
System drive C: has 59 GB (45%) free of 131 GB
Total RAM: 2047 MB (74% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:35:10, on 14. 2. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AGI\common\win32\PythonService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Rasto\Desktop\RSIT.exe
C:\Program Files\trend micro\Rasto.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 5307 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-08 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-08 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-03-01 577536]
"VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2005-03-08 53248]
"VTTrayp"=C:\WINDOWS\system32\VTtrayp.exe [2005-08-03 163840]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-03-19 2029640]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-05-20 98304]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-01-11 246504]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-05-16 155648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoDriveTypeAutoRun"=323
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\sdc203\StrongDC.exe"="C:\Program Files\sdc203\StrongDC.exe:*:Enabled:StrongDC++"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\utorent\utorrent.exe"="C:\Program Files\utorent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2010-02-14 14:34:38 ----D---- C:\rsit
2010-02-14 14:34:38 ----D---- C:\Program Files\trend micro
2010-02-14 14:20:13 ----A---- C:\ComboFix.txt
2010-02-14 14:03:03 ----A---- C:\WINDOWS\MBR.exe
2010-02-14 14:03:00 ----A---- C:\WINDOWS\PEV.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\zip.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\SWSC.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\SWREG.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\sed.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\NIRCMD.exe
2010-02-14 10:16:29 ----A---- C:\WINDOWS\grep.exe
2010-02-11 17:17:04 ----D---- C:\New Folder
2010-02-10 19:27:15 ----D---- C:\Documents and Settings\Rasto\Application Data\Broken Sword 2.5
2010-02-09 20:46:08 ----A---- C:\WINDOWS\system32\PnkBstrA.exe
2010-02-09 20:45:54 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2010-02-09 20:41:22 ----D---- C:\WINDOWS\system32\LogFiles
2010-02-09 19:16:01 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2010-02-09 19:16:01 ----A---- C:\WINDOWS\system32\x3daudio1_2.dll
2010-02-09 19:16:00 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2010-02-09 19:16:00 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2010-02-09 19:15:59 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2010-02-09 19:15:58 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2010-02-09 19:15:56 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2010-02-09 19:15:53 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2010-02-09 19:15:53 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2010-02-09 19:15:49 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2010-02-09 19:15:48 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2010-02-09 19:15:48 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2010-02-09 19:06:57 ----D---- C:\Program Files\DAEMON Tools Lite
2010-02-09 19:05:50 ----D---- C:\Documents and Settings\Rasto\Application Data\DAEMON Tools Lite
2010-02-09 19:05:46 ----D---- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
2010-02-09 12:20:17 ----D---- C:\WINDOWS\Sun
2010-02-08 21:11:22 ----D---- C:\Documents and Settings\All Users\Application Data\Sun
2010-02-08 21:11:18 ----D---- C:\Program Files\Common Files\Java
2010-02-08 21:10:44 ----A---- C:\WINDOWS\system32\javaws.exe
2010-02-08 21:10:44 ----A---- C:\WINDOWS\system32\javaw.exe
2010-02-08 21:10:44 ----A---- C:\WINDOWS\system32\java.exe
2010-02-08 21:10:44 ----A---- C:\WINDOWS\system32\deploytk.dll
2010-02-08 21:09:48 ----D---- C:\Program Files\Java
2010-02-08 18:44:20 ----D---- C:\MAMA NAPALIT
2010-02-07 20:43:05 ----A---- C:\WINDOWS\doom3.ini
2010-02-07 13:55:54 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2010-02-04 16:38:28 ----D---- C:\instalacky
2010-02-02 17:22:26 ----SHD---- C:\WINDOWS\ftpcache
2010-02-01 19:09:35 ----D---- C:\Documents and Settings\Rasto\Application Data\ATI
2010-02-01 19:09:35 ----D---- C:\Documents and Settings\All Users\Application Data\ATI
2010-02-01 19:00:51 ----D---- C:\Program Files\Common Files\ATI Technologies
2010-02-01 18:59:12 ----D---- C:\WINDOWS\RegisteredPackages
2010-02-01 18:57:35 ----A---- C:\WINDOWS\system32\psisdecd.dll
2010-02-01 18:57:23 ----A---- C:\WINDOWS\system32\dxdllreg.exe
2010-02-01 18:53:11 ----RSD---- C:\WINDOWS\assembly
2010-02-01 18:52:04 ----D---- C:\WINDOWS\Microsoft.NET
2010-02-01 18:50:35 ----N---- C:\WINDOWS\system32\ati2sgag.exe
2010-02-01 18:50:29 ----RA---- C:\WINDOWS\system32\atiiiexx.dll
2010-02-01 18:50:21 ----RA---- C:\WINDOWS\system32\ATIDEMGX.dll
2010-02-01 18:49:17 ----D---- C:\Program Files\ATI Technologies
2010-01-28 17:11:41 ----D---- C:\Program Files\PC Wizard 2008
2010-01-27 17:47:19 ----D---- C:\technicke info
2010-01-26 17:31:46 ----D---- C:\obrazky
2010-01-25 19:02:35 ----D---- C:\WINDOWS\system32\languages
2010-01-25 17:29:36 ----D---- C:\Documents and Settings\Rasto\Application Data\BSplayer Pro
2010-01-25 17:29:36 ----D---- C:\Documents and Settings\Rasto\Application Data\BSplayer
2010-01-25 16:00:37 ----D---- C:\Samsung
======List of files/folders modified in the last 1 months======
2010-02-14 14:34:57 ----D---- C:\WINDOWS\temp
2010-02-14 14:34:38 ----RD---- C:\Program Files
2010-02-14 14:30:25 ----D---- C:\Program Files\Mozilla Firefox
2010-02-14 14:20:05 ----D---- C:\Qoobox
2010-02-14 14:18:15 ----D---- C:\WINDOWS\ERDNT
2010-02-14 14:18:02 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-14 14:14:41 ----AD---- C:\WINDOWS
2010-02-14 14:14:41 ----A---- C:\WINDOWS\system.ini
2010-02-14 14:13:12 ----D---- C:\WINDOWS\system32\drivers
2010-02-14 14:10:57 ----D---- C:\WINDOWS\system32\config
2010-02-14 14:09:11 ----D---- C:\WINDOWS\system32
2010-02-14 14:09:09 ----D---- C:\Program Files\ICQ6.5
2010-02-14 14:08:02 ----D---- C:\WINDOWS\AppPatch
2010-02-14 14:07:56 ----D---- C:\Program Files\Common Files
2010-02-14 14:03:16 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-14 13:58:44 ----A---- C:\WINDOWS\wincmd.ini
2010-02-14 13:40:18 ----A---- C:\WINDOWS\wininit.ini
2010-02-13 23:00:32 ----D---- C:\WINDOWS\Prefetch
2010-02-13 22:30:25 ----SD---- C:\WINDOWS\Tasks
2010-02-13 21:44:23 ----D---- C:\torenty
2010-02-13 21:35:17 ----D---- C:\Documents and Settings\Rasto\Application Data\Skype
2010-02-13 19:55:41 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-13 15:18:35 ----D---- C:\instalacky programov
2010-02-12 18:15:11 ----D---- C:\hry
2010-02-12 16:29:36 ----HD---- C:\WINDOWS\inf
2010-02-12 13:22:44 ----D---- C:\Program Files\BSplayer
2010-02-11 21:17:35 ----D---- C:\Documents and Settings\All Users\Application Data\NFS Underground
2010-02-11 17:18:18 ----D---- C:\Documents and Settings\Rasto\Application Data\uTorrent
2010-02-11 17:01:05 ----D---- C:\Filmy
2010-02-10 12:55:33 ----D---- C:\Documents and Settings\Rasto\Application Data\ICQ
2010-02-09 20:41:27 ----SHD---- C:\WINDOWS\Installer
2010-02-09 19:16:02 ----D---- C:\WINDOWS\system32\DirectX
2010-02-09 18:14:54 ----D---- C:\instalacky hier
2010-02-07 13:14:00 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-06 19:19:27 ----SD---- C:\Documents and Settings\Rasto\Application Data\Microsoft
2010-02-06 18:43:28 ----RSD---- C:\WINDOWS\Fonts
2010-02-04 23:45:56 ----D---- C:\WINDOWS\Minidump
2010-02-01 19:03:41 ----D---- C:\WINDOWS\WinSxS
2010-02-01 18:59:12 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-01 18:56:45 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-02-01 18:52:14 ----D---- C:\Program Files\Internet Explorer
2010-02-01 18:48:12 ----D---- C:\Program Files\Common Files\InstallShield
2010-01-28 17:35:04 ----D---- C:\Program Files\Adobe
2010-01-25 19:02:37 ----D---- C:\Program Files\Codec Pack - All In 1
2010-01-25 19:01:38 ----A---- C:\WINDOWS\iun6002.exe
2010-01-23 18:09:14 ----D---- C:\Documents and Settings\Rasto\Application Data\Happy Foto
2010-01-16 14:15:12 ----D---- C:\faktury slovanet
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 BIOS;BIOS; \??\C:\WINDOWS\System32\drivers\BIOS.sys []
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-03-19 107256]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2009-02-17 24232]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-03-19 55768]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 36352]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-03-19 113960]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-03-19 131976]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-05-19 3965056]
R3 AnyDVD;AnyDVD; C:\WINDOWS\System32\Drivers\AnyDVD.sys [2009-03-18 103744]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-05-16 4069888]
R3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-03-19 33096]
R3 FETND5BV;VIA Rhine-Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2004-12-16 42496]
R3 OVT511Plus;Dual Mode USB Camera Plus; C:\WINDOWS\System32\Drivers\omcamvid.sys [2001-09-18 167816]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-05-24 47360]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 ayk4v5st;ayk4v5st; C:\WINDOWS\system32\drivers\ayk4v5st.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mbr;mbr; \??\C:\DOCUME~1\Rasto\LOCALS~1\Temp\mbr.sys []
S3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\WINDOWS\system32\DRIVERS\mcdbus.sys []
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 nv4;nv4; C:\WINDOWS\System32\DRIVERS\nv4.sys [2001-08-17 731648]
S3 S3chipid;S3chipid; \??\C:\DOCUME~1\Rasto\LOCALS~1\Temp\{2B43252C-A1E3-4C47-927C-9F2C276D3515}\S3chipid.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 viagfx;viagfx; C:\WINDOWS\system32\DRIVERS\vtmini.sys [2005-08-11 237312]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-23 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AGWinService;AG Windows Service; C:\Program Files\AGI\common\win32\PythonService.exe [2009-01-26 10240]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-05-16 602112]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-03-19 731840]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-02-08 153376]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-12-05 935208]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2010-02-10 66872]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-05-15 593920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-03-19 20680]
S3 getPlus(R) Helper;getPlus(R) Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-10-06 33752]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
-----------------EOF-----------------