vir...
Napsal: 09 bře 2010 14:11
Zdravím, tak jsem tu zase s prosbou o kontrolu logu. Přijdu domů a počítač byl napaden XP Antispy. Ten jsem pomoci MBAM odstranil, ale ted mi nejde nainstalovat Eset Smart security.
Hlásí, že nemám přístup ke složce, kam chce kopírovat soubory.
Logfile of random's system information tool 1.06 (written by random/random)
Run by admin at 2010-03-09 14:09:48
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 60 GB (79%) free of 76 GB
Total RAM: 2005 MB (82% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:09:57, on 9.3.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\LINKMAGIC\LINKMAGIC.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\Content.IE5\KXKH81G4\RSIT[1].exe
C:\Program Files\trend micro\admin.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [atchk] "C:\Program Files\Intel\AMT\atchk.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: LINKMAGIC.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 8054592625
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Intel(R) Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe
O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel - C:\Program Files\Intel\AMT\UNS.exe
--
End of file - 6468 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll [2010-03-09 798771]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll [2010-03-09 798771]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"atchk"=C:\Program Files\Intel\AMT\atchk.exe [2007-06-12 408344]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-08-01 1036288]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-05-29 150040]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-05-29 170520]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-05-29 141848]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
LINKMAGIC.lnk - C:\Program Files\LINKMAGIC\LINKMAGIC.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-04-02 212992]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2010-03-09 14:09:48 ----D---- C:\rsit
2010-03-09 14:09:48 ----D---- C:\Program Files\trend micro
2010-03-09 14:08:26 ----D---- C:\Documents and Settings\admin\Application Data\LangSoft
2010-03-09 13:46:27 ----D---- C:\Program Files\TRANSLAT
2010-03-09 13:46:22 ----D---- C:\Documents and Settings\All Users\Application Data\LangSoft
2010-03-09 13:26:34 ----A---- C:\WINDOWS\ntbtlog.txt
2010-03-09 13:22:34 ----D---- C:\Documents and Settings\admin\Application Data\Malwarebytes
2010-03-09 13:22:30 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-03-09 13:22:30 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-03-09 13:21:40 ----D---- C:\Documents and Settings\admin\Application Data\Mozilla
2010-03-08 17:29:06 ----SHD---- C:\RECYCLER
2010-03-08 15:35:14 ----SHD---- C:\WINDOWS\CSC
2010-03-08 15:33:41 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-03-08 15:33:34 ----D---- C:\Program Files\Common Files\Adobe
2010-03-08 15:33:34 ----D---- C:\Program Files\Adobe
2010-03-08 15:14:03 ----D---- C:\PP1390MF_v1.67
2010-03-08 15:13:17 ----D---- C:\LinkMagic
2010-03-08 15:13:14 ----A---- C:\WINDOWS\install.ini
2010-03-08 15:13:13 ----N---- C:\WINDOWS\rmreg.exe
2010-03-08 15:13:13 ----N---- C:\WINDOWS\Cm3.ini
2010-03-08 15:13:13 ----D---- C:\FBBM
2010-03-08 15:13:13 ----A---- C:\WINDOWS\system32\SP701ASM.exe
2010-03-08 15:13:13 ----A---- C:\WINDOWS\system32\SP701ALM.dll
2010-03-08 15:13:13 ----A---- C:\WINDOWS\rmdrv98.exe
2010-03-08 15:13:13 ----A---- C:\WINDOWS\rmdrv2k.exe
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lttwn12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\ltkrn12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\ltimg12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\ltfil12n.DLL
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\ltefx12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\LTDIS12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lftif12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lftga12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lfpcx12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lfimg12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lffax12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\LFCMP12n.DLL
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lfbmp12n.dll
2010-03-08 15:13:11 ----D---- C:\Program Files\LINKMAGIC
2010-03-08 15:12:27 ----D---- C:\Program Files\WinRAR
2010-03-08 15:09:23 ----HDC---- C:\WINDOWS\$NtUninstallKB977165-v2$
2010-03-08 15:09:08 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-03-08 15:09:02 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-03-08 15:06:54 ----D---- C:\WINDOWS\ie7updates
2010-03-08 15:06:01 ----D---- C:\WINDOWS\WBEM
2010-03-08 15:03:45 ----HDC---- C:\WINDOWS\ie7
2010-03-08 15:03:28 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
2010-03-08 15:03:00 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2010-03-08 14:51:16 ----D---- C:\Program Files\Mozilla Firefox
2010-03-08 14:45:56 ----D---- C:\WINDOWS\system32\1029
2010-03-08 14:44:33 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
2010-03-08 14:43:56 ----A---- C:\WINDOWS\system32\MRT.exe
2010-03-08 14:43:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-03-08 14:43:47 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-03-08 14:43:43 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-03-08 14:43:39 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-03-08 14:43:35 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-03-08 14:43:29 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-03-08 14:43:26 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-03-08 14:43:22 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-03-08 14:43:14 ----HDC---- C:\WINDOWS\$NtUninstallKB978207$
2010-03-08 14:43:10 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-03-08 14:43:05 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-03-08 14:43:00 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-03-08 14:42:56 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-03-08 14:42:52 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-03-08 14:42:48 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-03-08 14:42:43 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-03-08 14:42:39 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-03-08 14:42:36 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-03-08 14:42:31 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-03-08 14:42:28 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-03-08 14:42:25 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-03-08 14:42:20 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2010-03-08 14:42:15 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-03-08 14:42:12 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-03-08 14:42:09 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-03-08 14:42:05 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-03-08 14:42:03 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2010-03-08 14:41:59 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-03-08 14:41:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-03-08 14:41:39 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-03-08 14:41:36 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-03-08 14:41:32 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-03-08 14:41:28 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-03-08 14:41:25 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-03-08 14:41:21 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-03-08 14:41:17 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-03-08 14:41:12 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-03-08 14:41:08 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-03-08 14:41:04 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-03-08 14:41:00 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-03-08 14:40:56 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-03-08 14:40:51 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-03-08 14:40:43 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-03-08 14:40:38 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-03-08 14:39:40 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-03-08 14:39:37 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-03-08 14:39:32 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-03-08 14:39:27 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-03-08 14:39:22 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2010-03-08 14:39:17 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-03-08 14:39:13 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-03-08 14:39:08 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-03-08 14:39:02 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-03-08 14:38:55 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-03-08 14:38:48 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-03-08 14:38:43 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2010-03-08 14:38:37 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-03-08 14:38:32 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-03-08 14:38:27 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-03-08 14:38:24 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-03-08 14:38:14 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
2010-03-08 14:38:01 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-03-08 14:31:51 ----A---- C:\WINDOWS\system32\msonpmon.dll
2010-03-08 14:31:26 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2010-03-08 14:31:07 ----D---- C:\Program Files\Microsoft Works
2010-03-08 14:30:50 ----D---- C:\Program Files\MSBuild
2010-03-08 14:30:03 ----D---- C:\Program Files\Microsoft Visual Studio
2010-03-08 14:30:03 ----D---- C:\Program Files\Common Files\DESIGNER
2010-03-08 14:29:58 ----D---- C:\Public
2010-03-08 14:25:10 ----D---- C:\WINDOWS\SHELLNEW
2010-03-08 14:24:56 ----D---- C:\Program Files\Microsoft Office
2010-03-08 14:24:55 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-03-08 14:24:46 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2010-03-08 14:24:27 ----RHD---- C:\MSOCache
2010-03-08 14:22:39 ----D---- C:\ZALOHA
2010-03-08 14:20:25 ----D---- C:\totalcmd
2010-03-08 14:20:25 ----D---- C:\Documents and Settings\admin\Application Data\GHISLER
======List of files/folders modified in the last 1 months======
2010-03-09 14:09:48 ----RD---- C:\Program Files
2010-03-09 14:09:00 ----A---- C:\WINDOWS\system32\log.txt
2010-03-09 14:08:26 ----SHD---- C:\WINDOWS\Installer
2010-03-09 14:07:36 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-09 14:05:30 ----D---- C:\WINDOWS\system32\Restore
2010-03-09 13:59:39 ----D---- C:\WINDOWS\Prefetch
2010-03-09 13:59:10 ----D---- C:\WINDOWS\system32
2010-03-09 13:59:10 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-09 13:57:43 ----D---- C:\WINDOWS\Temp
2010-03-09 13:54:47 ----D---- C:\WINDOWS\system32\drivers
2010-03-09 13:42:53 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-09 13:40:02 ----D---- C:\WINDOWS
2010-03-09 13:21:32 ----SD---- C:\Documents and Settings\admin\Application Data\Microsoft
2010-03-09 13:20:59 ----HD---- C:\WINDOWS\inf
2010-03-09 13:20:51 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-09 13:20:39 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-08 15:40:18 ----D---- C:\WINDOWS\system32\CatRoot
2010-03-08 15:35:08 ----D---- C:\WINDOWS\Help
2010-03-08 15:35:08 ----D---- C:\Program Files\Internet Explorer
2010-03-08 15:33:42 ----D---- C:\WINDOWS\WinSxS
2010-03-08 15:33:34 ----D---- C:\Program Files\Common Files
2010-03-08 15:14:07 ----D---- C:\Documents and Settings
2010-03-08 15:13:11 ----HD---- C:\Program Files\InstallShield Installation Information
2010-03-08 15:12:52 ----D---- C:\Program Files\Common Files\InstallShield
2010-03-08 15:09:33 ----A---- C:\WINDOWS\imsins.BAK
2010-03-08 15:08:41 ----D---- C:\WINDOWS\system32\en-us
2010-03-08 15:06:03 ----D---- C:\WINDOWS\system32\config
2010-03-08 15:05:50 ----D---- C:\WINDOWS\Media
2010-03-08 15:01:46 ----D---- C:\WINDOWS\SoftwareDistribution
2010-03-08 14:53:52 ----D---- C:\WINDOWS\system32\wbem
2010-03-08 14:52:48 ----A---- C:\WINDOWS\OEWABLog.txt
2010-03-08 14:48:57 ----D---- C:\WINDOWS\mui
2010-03-08 14:48:57 ----D---- C:\WINDOWS\AppPatch
2010-03-08 14:46:51 ----D---- C:\WINDOWS\pchealth
2010-03-08 14:46:19 ----D---- C:\Program Files\Windows Media Player
2010-03-08 14:45:56 ----D---- C:\Program Files\Common Files\System
2010-03-08 14:41:26 ----D---- C:\Program Files\Outlook Express
2010-03-08 14:38:51 ----D---- C:\Program Files\Messenger
2010-03-08 14:31:00 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-03-08 14:29:07 ----RSD---- C:\WINDOWS\Fonts
2010-03-08 14:25:29 ----A---- C:\WINDOWS\win.ini
2010-03-08 14:24:07 ----SD---- C:\WINDOWS\Downloaded Program Files
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-08-03 307712]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2007-04-13 254872]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HECI;Intel(R) Management Engine Interface; C:\WINDOWS\system32\DRIVERS\HECI.sys [2007-06-12 45056]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-04-02 6008704]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 atchksrv;Intel(R) Active Management Technology System Status Service; C:\Program Files\Intel\AMT\atchksrv.exe [2007-06-12 183064]
R2 LMS;Intel(R) Active Management Technology Local Management Service; C:\Program Files\Intel\AMT\LMS.exe [2007-06-12 109336]
R2 UNS;Intel(R) Active Management Technology User Notification Service; C:\Program Files\Intel\AMT\UNS.exe [2007-06-12 2521880]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------
Hlásí, že nemám přístup ke složce, kam chce kopírovat soubory.
Logfile of random's system information tool 1.06 (written by random/random)
Run by admin at 2010-03-09 14:09:48
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 60 GB (79%) free of 76 GB
Total RAM: 2005 MB (82% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:09:57, on 9.3.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\LINKMAGIC\LINKMAGIC.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\Content.IE5\KXKH81G4\RSIT[1].exe
C:\Program Files\trend micro\admin.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [atchk] "C:\Program Files\Intel\AMT\atchk.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: LINKMAGIC.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 8054592625
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Intel(R) Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe
O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel - C:\Program Files\Intel\AMT\UNS.exe
--
End of file - 6468 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll [2010-03-09 798771]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\Documents and Settings\Hanka\Application Data\LangSoft\WebIE.dll [2010-03-09 798771]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"atchk"=C:\Program Files\Intel\AMT\atchk.exe [2007-06-12 408344]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-08-01 1036288]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-05-29 150040]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-05-29 170520]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-05-29 141848]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
LINKMAGIC.lnk - C:\Program Files\LINKMAGIC\LINKMAGIC.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-04-02 212992]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2010-03-09 14:09:48 ----D---- C:\rsit
2010-03-09 14:09:48 ----D---- C:\Program Files\trend micro
2010-03-09 14:08:26 ----D---- C:\Documents and Settings\admin\Application Data\LangSoft
2010-03-09 13:46:27 ----D---- C:\Program Files\TRANSLAT
2010-03-09 13:46:22 ----D---- C:\Documents and Settings\All Users\Application Data\LangSoft
2010-03-09 13:26:34 ----A---- C:\WINDOWS\ntbtlog.txt
2010-03-09 13:22:34 ----D---- C:\Documents and Settings\admin\Application Data\Malwarebytes
2010-03-09 13:22:30 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-03-09 13:22:30 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-03-09 13:21:40 ----D---- C:\Documents and Settings\admin\Application Data\Mozilla
2010-03-08 17:29:06 ----SHD---- C:\RECYCLER
2010-03-08 15:35:14 ----SHD---- C:\WINDOWS\CSC
2010-03-08 15:33:41 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-03-08 15:33:34 ----D---- C:\Program Files\Common Files\Adobe
2010-03-08 15:33:34 ----D---- C:\Program Files\Adobe
2010-03-08 15:14:03 ----D---- C:\PP1390MF_v1.67
2010-03-08 15:13:17 ----D---- C:\LinkMagic
2010-03-08 15:13:14 ----A---- C:\WINDOWS\install.ini
2010-03-08 15:13:13 ----N---- C:\WINDOWS\rmreg.exe
2010-03-08 15:13:13 ----N---- C:\WINDOWS\Cm3.ini
2010-03-08 15:13:13 ----D---- C:\FBBM
2010-03-08 15:13:13 ----A---- C:\WINDOWS\system32\SP701ASM.exe
2010-03-08 15:13:13 ----A---- C:\WINDOWS\system32\SP701ALM.dll
2010-03-08 15:13:13 ----A---- C:\WINDOWS\rmdrv98.exe
2010-03-08 15:13:13 ----A---- C:\WINDOWS\rmdrv2k.exe
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lttwn12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\ltkrn12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\ltimg12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\ltfil12n.DLL
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\ltefx12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\LTDIS12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lftif12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lftga12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lfpcx12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lfimg12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lffax12n.dll
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\LFCMP12n.DLL
2010-03-08 15:13:12 ----N---- C:\WINDOWS\system32\lfbmp12n.dll
2010-03-08 15:13:11 ----D---- C:\Program Files\LINKMAGIC
2010-03-08 15:12:27 ----D---- C:\Program Files\WinRAR
2010-03-08 15:09:23 ----HDC---- C:\WINDOWS\$NtUninstallKB977165-v2$
2010-03-08 15:09:08 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-03-08 15:09:02 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-03-08 15:06:54 ----D---- C:\WINDOWS\ie7updates
2010-03-08 15:06:01 ----D---- C:\WINDOWS\WBEM
2010-03-08 15:03:45 ----HDC---- C:\WINDOWS\ie7
2010-03-08 15:03:28 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
2010-03-08 15:03:00 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2010-03-08 14:51:16 ----D---- C:\Program Files\Mozilla Firefox
2010-03-08 14:45:56 ----D---- C:\WINDOWS\system32\1029
2010-03-08 14:44:33 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
2010-03-08 14:43:56 ----A---- C:\WINDOWS\system32\MRT.exe
2010-03-08 14:43:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-03-08 14:43:47 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-03-08 14:43:43 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-03-08 14:43:39 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-03-08 14:43:35 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-03-08 14:43:29 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-03-08 14:43:26 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-03-08 14:43:22 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-03-08 14:43:14 ----HDC---- C:\WINDOWS\$NtUninstallKB978207$
2010-03-08 14:43:10 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-03-08 14:43:05 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-03-08 14:43:00 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-03-08 14:42:56 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-03-08 14:42:52 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-03-08 14:42:48 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-03-08 14:42:43 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-03-08 14:42:39 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-03-08 14:42:36 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-03-08 14:42:31 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-03-08 14:42:28 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-03-08 14:42:25 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-03-08 14:42:20 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2010-03-08 14:42:15 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-03-08 14:42:12 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-03-08 14:42:09 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-03-08 14:42:05 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-03-08 14:42:03 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2010-03-08 14:41:59 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-03-08 14:41:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-03-08 14:41:39 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-03-08 14:41:36 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-03-08 14:41:32 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-03-08 14:41:28 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-03-08 14:41:25 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-03-08 14:41:21 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-03-08 14:41:17 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-03-08 14:41:12 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-03-08 14:41:08 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-03-08 14:41:04 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-03-08 14:41:00 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-03-08 14:40:56 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-03-08 14:40:51 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-03-08 14:40:43 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-03-08 14:40:38 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-03-08 14:39:40 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-03-08 14:39:37 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-03-08 14:39:32 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-03-08 14:39:27 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-03-08 14:39:22 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2010-03-08 14:39:17 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-03-08 14:39:13 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-03-08 14:39:08 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-03-08 14:39:02 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-03-08 14:38:55 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-03-08 14:38:48 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-03-08 14:38:43 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2010-03-08 14:38:37 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-03-08 14:38:32 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-03-08 14:38:27 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-03-08 14:38:24 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-03-08 14:38:14 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
2010-03-08 14:38:01 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-03-08 14:31:51 ----A---- C:\WINDOWS\system32\msonpmon.dll
2010-03-08 14:31:26 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2010-03-08 14:31:07 ----D---- C:\Program Files\Microsoft Works
2010-03-08 14:30:50 ----D---- C:\Program Files\MSBuild
2010-03-08 14:30:03 ----D---- C:\Program Files\Microsoft Visual Studio
2010-03-08 14:30:03 ----D---- C:\Program Files\Common Files\DESIGNER
2010-03-08 14:29:58 ----D---- C:\Public
2010-03-08 14:25:10 ----D---- C:\WINDOWS\SHELLNEW
2010-03-08 14:24:56 ----D---- C:\Program Files\Microsoft Office
2010-03-08 14:24:55 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-03-08 14:24:46 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2010-03-08 14:24:27 ----RHD---- C:\MSOCache
2010-03-08 14:22:39 ----D---- C:\ZALOHA
2010-03-08 14:20:25 ----D---- C:\totalcmd
2010-03-08 14:20:25 ----D---- C:\Documents and Settings\admin\Application Data\GHISLER
======List of files/folders modified in the last 1 months======
2010-03-09 14:09:48 ----RD---- C:\Program Files
2010-03-09 14:09:00 ----A---- C:\WINDOWS\system32\log.txt
2010-03-09 14:08:26 ----SHD---- C:\WINDOWS\Installer
2010-03-09 14:07:36 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-09 14:05:30 ----D---- C:\WINDOWS\system32\Restore
2010-03-09 13:59:39 ----D---- C:\WINDOWS\Prefetch
2010-03-09 13:59:10 ----D---- C:\WINDOWS\system32
2010-03-09 13:59:10 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-09 13:57:43 ----D---- C:\WINDOWS\Temp
2010-03-09 13:54:47 ----D---- C:\WINDOWS\system32\drivers
2010-03-09 13:42:53 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-09 13:40:02 ----D---- C:\WINDOWS
2010-03-09 13:21:32 ----SD---- C:\Documents and Settings\admin\Application Data\Microsoft
2010-03-09 13:20:59 ----HD---- C:\WINDOWS\inf
2010-03-09 13:20:51 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-09 13:20:39 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-08 15:40:18 ----D---- C:\WINDOWS\system32\CatRoot
2010-03-08 15:35:08 ----D---- C:\WINDOWS\Help
2010-03-08 15:35:08 ----D---- C:\Program Files\Internet Explorer
2010-03-08 15:33:42 ----D---- C:\WINDOWS\WinSxS
2010-03-08 15:33:34 ----D---- C:\Program Files\Common Files
2010-03-08 15:14:07 ----D---- C:\Documents and Settings
2010-03-08 15:13:11 ----HD---- C:\Program Files\InstallShield Installation Information
2010-03-08 15:12:52 ----D---- C:\Program Files\Common Files\InstallShield
2010-03-08 15:09:33 ----A---- C:\WINDOWS\imsins.BAK
2010-03-08 15:08:41 ----D---- C:\WINDOWS\system32\en-us
2010-03-08 15:06:03 ----D---- C:\WINDOWS\system32\config
2010-03-08 15:05:50 ----D---- C:\WINDOWS\Media
2010-03-08 15:01:46 ----D---- C:\WINDOWS\SoftwareDistribution
2010-03-08 14:53:52 ----D---- C:\WINDOWS\system32\wbem
2010-03-08 14:52:48 ----A---- C:\WINDOWS\OEWABLog.txt
2010-03-08 14:48:57 ----D---- C:\WINDOWS\mui
2010-03-08 14:48:57 ----D---- C:\WINDOWS\AppPatch
2010-03-08 14:46:51 ----D---- C:\WINDOWS\pchealth
2010-03-08 14:46:19 ----D---- C:\Program Files\Windows Media Player
2010-03-08 14:45:56 ----D---- C:\Program Files\Common Files\System
2010-03-08 14:41:26 ----D---- C:\Program Files\Outlook Express
2010-03-08 14:38:51 ----D---- C:\Program Files\Messenger
2010-03-08 14:31:00 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-03-08 14:29:07 ----RSD---- C:\WINDOWS\Fonts
2010-03-08 14:25:29 ----A---- C:\WINDOWS\win.ini
2010-03-08 14:24:07 ----SD---- C:\WINDOWS\Downloaded Program Files
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-08-03 307712]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2007-04-13 254872]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HECI;Intel(R) Management Engine Interface; C:\WINDOWS\system32\DRIVERS\HECI.sys [2007-06-12 45056]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-04-02 6008704]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 atchksrv;Intel(R) Active Management Technology System Status Service; C:\Program Files\Intel\AMT\atchksrv.exe [2007-06-12 183064]
R2 LMS;Intel(R) Active Management Technology Local Management Service; C:\Program Files\Intel\AMT\LMS.exe [2007-06-12 109336]
R2 UNS;Intel(R) Active Management Technology User Notification Service; C:\Program Files\Intel\AMT\UNS.exe [2007-06-12 2521880]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------