vir Alureon.B nelze odstranit
Napsal: 17 bře 2010 17:17
microsoft security essentials vyhledal vir Alureon.B ktery ale nejde odtranit proto teda prosim o pomoc a prikladam vypis z log
Logfile of random's system information tool 1.06 (written by random/random)
Run by Jan Svoboda at 2010-03-17 17:08:54
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 8 GB (2%) free of 477 GB
Total RAM: 2046 MB (41% free)
HijackThis download failed
======Scheduled tasks folder======
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\User_Feed_Synchronization-{D3BCFB12-CB3B-472F-9F00-1BB3D1BD21C9}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-02-01 1377576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\Jan Svoboda\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2009-07-14 150768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-03-30 668656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-01 35840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-01 148888]
"MSSE"=c:\Program Files\Microsoft Security Essentials\msseces.exe [2010-02-21 1093208]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-06-12 1414144]
"QIP2005"=C:\Program Files\QIP\qip.exe [2009-08-13 3276288]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4a825093-ca25-11de-9696-001d7d9b2181}]
shell\AutoRun\command - I:\StartUp.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a7dc171e-b272-11de-8df5-001d7d9b2181}]
shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8b888d1-eb82-11dc-9832-001d7d9b2181}]
shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce712d85-a269-11dd-ba48-001d7d9b2181}]
shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\Recycled\ctfmon.exe
shell\Open(0)\command - J:\Recycled\ctfmon.exe
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - "C:\Windows\system32\notepad.exe" "%1"
.scr - install -
.scr - config -
======List of files/folders created in the last 1 months======
2010-03-17 17:08:55 ----D---- C:\Program Files\trend micro
2010-03-17 17:08:54 ----D---- C:\rsit
2010-03-17 15:09:56 ----SHD---- C:\Config.Msi
2010-03-17 15:03:46 ----D---- C:\Program Files\Common Files\ParetoLogic
2010-03-17 14:44:48 ----D---- C:\Users\Jan Svoboda\AppData\Roaming\Malwarebytes
2010-03-17 14:44:44 ----D---- C:\ProgramData\Malwarebytes
2010-03-14 14:49:41 ----D---- C:\Program Files\Common Files\PCSuite
2010-03-14 14:49:37 ----D---- C:\Program Files\Common Files\Nokia
2010-03-14 14:49:18 ----D---- C:\Program Files\PC Connectivity Solution
2010-03-12 17:04:22 ----D---- C:\Users\Jan Svoboda\AppData\Roaming\Opera
2010-03-12 17:04:14 ----D---- C:\Program Files\Opera
2010-03-12 15:58:18 ----D---- C:\Program Files\NVIDIA Corporation
2010-03-12 15:57:07 ----A---- C:\Windows\system32\browserchoice.exe
2010-03-12 07:21:59 ----A---- C:\Windows\system32\nshhttp.dll
2010-03-12 07:21:57 ----A---- C:\Windows\system32\httpapi.dll
2010-02-26 15:22:24 ----A---- C:\Windows\system32\reboot.txt
2010-02-26 15:05:02 ----D---- C:\Program Files\Microsoft Security Essentials
2010-02-24 15:33:01 ----D---- C:\Program Files\Venetica
2010-02-24 13:38:55 ----A---- C:\Windows\system32\jscript.dll
2010-02-24 13:38:50 ----A---- C:\Windows\system32\tzres.dll
2010-02-24 13:38:38 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-24 13:38:38 ----A---- C:\Windows\system32\secproc.dll
2010-02-24 13:38:32 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-24 13:38:31 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-24 13:38:31 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-24 13:38:30 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-24 13:38:29 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-24 13:38:29 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-24 13:38:29 ----A---- C:\Windows\system32\msdrm.dll
2010-02-24 13:38:28 ----A---- C:\Windows\system32\gameux.dll
2010-02-24 13:38:27 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2010-02-24 13:38:27 ----A---- C:\Windows\system32\Apphlpdm.dll
======List of files/folders modified in the last 1 months======
2010-03-17 17:08:55 ----RD---- C:\Program Files
2010-03-17 17:08:52 ----D---- C:\Windows\Temp
2010-03-17 16:47:24 ----D---- C:\Windows\system32\drivers
2010-03-17 15:10:00 ----SHD---- C:\Windows\Installer
2010-03-17 15:09:59 ----HD---- C:\ProgramData
2010-03-17 15:09:58 ----D---- C:\Windows\System32
2010-03-17 15:09:48 ----D---- C:\Windows\Tasks
2010-03-17 15:09:48 ----D---- C:\Windows\system32\catroot
2010-03-17 15:03:57 ----D---- C:\Windows\system32\Tasks
2010-03-17 15:03:46 ----D---- C:\Program Files\Common Files
2010-03-17 14:57:49 ----AD---- C:\ProgramData\TEMP
2010-03-17 14:57:38 ----D---- C:\Windows
2010-03-17 14:54:02 ----D---- C:\Windows\Prefetch
2010-03-17 14:39:21 ----D---- C:\Windows\inf
2010-03-17 14:39:21 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-03-17 14:33:38 ----SHD---- C:\System Volume Information
2010-03-17 14:33:37 ----D---- C:\Windows\Logs
2010-03-16 19:48:13 ----D---- C:\ProgramData\Google Updater
2010-03-14 15:00:01 ----D---- C:\Users\Jan Svoboda\AppData\Roaming\Nokia
2010-03-14 14:51:13 ----D---- C:\Windows\SoftwareDistribution
2010-03-14 14:49:39 ----D---- C:\Program Files\Nokia
2010-03-14 14:49:29 ----D---- C:\Program Files\DIFX
2010-03-14 14:49:28 ----DC---- C:\Windows\system32\DRVSTORE
2010-03-14 14:48:18 ----D---- C:\Windows\system32\catroot2
2010-03-14 14:47:53 ----D---- C:\ProgramData\Installations
2010-03-12 16:55:54 ----D---- C:\Program Files\Mozilla Firefox
2010-03-12 15:59:08 ----D---- C:\ProgramData\NVIDIA
2010-03-12 15:57:21 ----D---- C:\Windows\winsxs
2010-03-12 14:08:22 ----D---- C:\Users\Jan Svoboda\AppData\Roaming\IM
2010-03-12 13:45:43 ----D---- C:\Windows\system32\LogFiles
2010-03-12 11:30:02 ----D---- C:\Windows\Debug
2010-03-12 07:25:54 ----D---- C:\Program Files\Windows Mail
2010-03-12 07:25:54 ----D---- C:\Program Files\Movie Maker
2010-03-12 07:24:49 ----D---- C:\ProgramData\Microsoft Help
2010-03-07 18:27:45 ----D---- C:\Users\Jan Svoboda\AppData\Roaming\DVD Flick
2010-03-05 15:07:33 ----D---- C:\Program Files\Warcraft III
2010-03-02 06:30:12 ----A---- C:\Windows\system32\mrt.exe
2010-02-26 15:33:15 ----A---- C:\Windows\win.ini
2010-02-26 15:22:28 ----D---- C:\Program Files\Hewlett-Packard
2010-02-26 14:52:16 ----D---- C:\Program Files\CCleaner
2010-02-25 15:11:54 ----D---- C:\Windows\rescache
2010-02-25 10:17:27 ----RSD---- C:\Windows\Fonts
2010-02-25 10:17:27 ----D---- C:\Windows\system32\cs-CZ
2010-02-25 10:17:27 ----D---- C:\Windows\AppPatch
2010-02-24 10:16:06 ----N---- C:\Windows\system32\MpSigStub.exe
2010-02-21 14:27:36 ----D---- C:\Users\Jan Svoboda\AppData\Roaming\Skype
2010-02-21 14:26:29 ----D---- C:\Users\Jan Svoboda\AppData\Roaming\skypePM
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2007-02-28 15440]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2009-12-02 149040]
R1 MpKsla90206f1;MpKsla90206f1; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9F32EEB8-95AD-4731-A8EF-3A25F7360218}\MpKsla90206f1.sys [2010-03-17 28880]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2007-12-26 278984]
R2 Hardlock;Hardlock; \??\C:\Windows\system32\drivers\hardlock.sys [2004-11-05 670208]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2007-12-26 25416]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2009-12-02 42368]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2010-01-12 11586280]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2008-01-31 47360]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2009-12-20 234016]
S3 AnyDVD;AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys []
S3 axitqewx;axitqewx; C:\Windows\system32\drivers\axitqewx.sys []
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 ElbyCDFL;ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [2005-05-03 27392]
S3 ElbyDelay;ElbyDelay; C:\Windows\System32\Drivers\ElbyDelay.sys [2007-02-16 11984]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2007-11-30 15600]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2008-05-13 25280]
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\Windows\system32\DRIVERS\k750bus.sys [2005-02-11 55216]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmb.sys [2009-02-09 17664]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2009-02-09 22016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2009-02-09 7808]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2009-04-11 27648]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2009-02-09 7808]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2009-12-09 17904]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-01-11 129640]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2008-11-26 66872]
R2 Remote Solver for COSMOSFloWorks 2007;Remote Solver for COSMOSFloWorks 2007; C:\Program Files\SolidWorks (2)\COSMOSFloWorks\FloWorks\binCFW\StandAloneSlv.exe [2007-07-23 675840]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 1533808]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-06-02 637952]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-30 183280]
S2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2008-01-28 85096]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-03-15 655624]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-16 271920]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2008-09-22 79360]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by Jan Svoboda at 2010-03-17 17:08:54
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 8 GB (2%) free of 477 GB
Total RAM: 2046 MB (41% free)
HijackThis download failed
======Scheduled tasks folder======
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\User_Feed_Synchronization-{D3BCFB12-CB3B-472F-9F00-1BB3D1BD21C9}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-02-01 1377576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\Jan Svoboda\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2009-07-14 150768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-03-30 668656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-01 35840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-01 148888]
"MSSE"=c:\Program Files\Microsoft Security Essentials\msseces.exe [2010-02-21 1093208]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-06-12 1414144]
"QIP2005"=C:\Program Files\QIP\qip.exe [2009-08-13 3276288]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4a825093-ca25-11de-9696-001d7d9b2181}]
shell\AutoRun\command - I:\StartUp.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a7dc171e-b272-11de-8df5-001d7d9b2181}]
shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8b888d1-eb82-11dc-9832-001d7d9b2181}]
shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce712d85-a269-11dd-ba48-001d7d9b2181}]
shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\Recycled\ctfmon.exe
shell\Open(0)\command - J:\Recycled\ctfmon.exe
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - "C:\Windows\system32\notepad.exe" "%1"
.scr - install -
.scr - config -
======List of files/folders created in the last 1 months======
2010-03-17 17:08:55 ----D---- C:\Program Files\trend micro
2010-03-17 17:08:54 ----D---- C:\rsit
2010-03-17 15:09:56 ----SHD---- C:\Config.Msi
2010-03-17 15:03:46 ----D---- C:\Program Files\Common Files\ParetoLogic
2010-03-17 14:44:48 ----D---- C:\Users\Jan Svoboda\AppData\Roaming\Malwarebytes
2010-03-17 14:44:44 ----D---- C:\ProgramData\Malwarebytes
2010-03-14 14:49:41 ----D---- C:\Program Files\Common Files\PCSuite
2010-03-14 14:49:37 ----D---- C:\Program Files\Common Files\Nokia
2010-03-14 14:49:18 ----D---- C:\Program Files\PC Connectivity Solution
2010-03-12 17:04:22 ----D---- C:\Users\Jan Svoboda\AppData\Roaming\Opera
2010-03-12 17:04:14 ----D---- C:\Program Files\Opera
2010-03-12 15:58:18 ----D---- C:\Program Files\NVIDIA Corporation
2010-03-12 15:57:07 ----A---- C:\Windows\system32\browserchoice.exe
2010-03-12 07:21:59 ----A---- C:\Windows\system32\nshhttp.dll
2010-03-12 07:21:57 ----A---- C:\Windows\system32\httpapi.dll
2010-02-26 15:22:24 ----A---- C:\Windows\system32\reboot.txt
2010-02-26 15:05:02 ----D---- C:\Program Files\Microsoft Security Essentials
2010-02-24 15:33:01 ----D---- C:\Program Files\Venetica
2010-02-24 13:38:55 ----A---- C:\Windows\system32\jscript.dll
2010-02-24 13:38:50 ----A---- C:\Windows\system32\tzres.dll
2010-02-24 13:38:38 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-24 13:38:38 ----A---- C:\Windows\system32\secproc.dll
2010-02-24 13:38:32 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-24 13:38:31 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-24 13:38:31 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-24 13:38:30 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-24 13:38:29 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-24 13:38:29 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-24 13:38:29 ----A---- C:\Windows\system32\msdrm.dll
2010-02-24 13:38:28 ----A---- C:\Windows\system32\gameux.dll
2010-02-24 13:38:27 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2010-02-24 13:38:27 ----A---- C:\Windows\system32\Apphlpdm.dll
======List of files/folders modified in the last 1 months======
2010-03-17 17:08:55 ----RD---- C:\Program Files
2010-03-17 17:08:52 ----D---- C:\Windows\Temp
2010-03-17 16:47:24 ----D---- C:\Windows\system32\drivers
2010-03-17 15:10:00 ----SHD---- C:\Windows\Installer
2010-03-17 15:09:59 ----HD---- C:\ProgramData
2010-03-17 15:09:58 ----D---- C:\Windows\System32
2010-03-17 15:09:48 ----D---- C:\Windows\Tasks
2010-03-17 15:09:48 ----D---- C:\Windows\system32\catroot
2010-03-17 15:03:57 ----D---- C:\Windows\system32\Tasks
2010-03-17 15:03:46 ----D---- C:\Program Files\Common Files
2010-03-17 14:57:49 ----AD---- C:\ProgramData\TEMP
2010-03-17 14:57:38 ----D---- C:\Windows
2010-03-17 14:54:02 ----D---- C:\Windows\Prefetch
2010-03-17 14:39:21 ----D---- C:\Windows\inf
2010-03-17 14:39:21 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-03-17 14:33:38 ----SHD---- C:\System Volume Information
2010-03-17 14:33:37 ----D---- C:\Windows\Logs
2010-03-16 19:48:13 ----D---- C:\ProgramData\Google Updater
2010-03-14 15:00:01 ----D---- C:\Users\Jan Svoboda\AppData\Roaming\Nokia
2010-03-14 14:51:13 ----D---- C:\Windows\SoftwareDistribution
2010-03-14 14:49:39 ----D---- C:\Program Files\Nokia
2010-03-14 14:49:29 ----D---- C:\Program Files\DIFX
2010-03-14 14:49:28 ----DC---- C:\Windows\system32\DRVSTORE
2010-03-14 14:48:18 ----D---- C:\Windows\system32\catroot2
2010-03-14 14:47:53 ----D---- C:\ProgramData\Installations
2010-03-12 16:55:54 ----D---- C:\Program Files\Mozilla Firefox
2010-03-12 15:59:08 ----D---- C:\ProgramData\NVIDIA
2010-03-12 15:57:21 ----D---- C:\Windows\winsxs
2010-03-12 14:08:22 ----D---- C:\Users\Jan Svoboda\AppData\Roaming\IM
2010-03-12 13:45:43 ----D---- C:\Windows\system32\LogFiles
2010-03-12 11:30:02 ----D---- C:\Windows\Debug
2010-03-12 07:25:54 ----D---- C:\Program Files\Windows Mail
2010-03-12 07:25:54 ----D---- C:\Program Files\Movie Maker
2010-03-12 07:24:49 ----D---- C:\ProgramData\Microsoft Help
2010-03-07 18:27:45 ----D---- C:\Users\Jan Svoboda\AppData\Roaming\DVD Flick
2010-03-05 15:07:33 ----D---- C:\Program Files\Warcraft III
2010-03-02 06:30:12 ----A---- C:\Windows\system32\mrt.exe
2010-02-26 15:33:15 ----A---- C:\Windows\win.ini
2010-02-26 15:22:28 ----D---- C:\Program Files\Hewlett-Packard
2010-02-26 14:52:16 ----D---- C:\Program Files\CCleaner
2010-02-25 15:11:54 ----D---- C:\Windows\rescache
2010-02-25 10:17:27 ----RSD---- C:\Windows\Fonts
2010-02-25 10:17:27 ----D---- C:\Windows\system32\cs-CZ
2010-02-25 10:17:27 ----D---- C:\Windows\AppPatch
2010-02-24 10:16:06 ----N---- C:\Windows\system32\MpSigStub.exe
2010-02-21 14:27:36 ----D---- C:\Users\Jan Svoboda\AppData\Roaming\Skype
2010-02-21 14:26:29 ----D---- C:\Users\Jan Svoboda\AppData\Roaming\skypePM
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2007-02-28 15440]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2009-12-02 149040]
R1 MpKsla90206f1;MpKsla90206f1; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9F32EEB8-95AD-4731-A8EF-3A25F7360218}\MpKsla90206f1.sys [2010-03-17 28880]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2007-12-26 278984]
R2 Hardlock;Hardlock; \??\C:\Windows\system32\drivers\hardlock.sys [2004-11-05 670208]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2007-12-26 25416]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2009-12-02 42368]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2010-01-12 11586280]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2008-01-31 47360]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2009-12-20 234016]
S3 AnyDVD;AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys []
S3 axitqewx;axitqewx; C:\Windows\system32\drivers\axitqewx.sys []
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 ElbyCDFL;ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [2005-05-03 27392]
S3 ElbyDelay;ElbyDelay; C:\Windows\System32\Drivers\ElbyDelay.sys [2007-02-16 11984]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2007-11-30 15600]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2008-05-13 25280]
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\Windows\system32\DRIVERS\k750bus.sys [2005-02-11 55216]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmb.sys [2009-02-09 17664]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2009-02-09 22016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2009-02-09 7808]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2009-04-11 27648]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2009-02-09 7808]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2009-12-09 17904]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-01-11 129640]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2008-11-26 66872]
R2 Remote Solver for COSMOSFloWorks 2007;Remote Solver for COSMOSFloWorks 2007; C:\Program Files\SolidWorks (2)\COSMOSFloWorks\FloWorks\binCFW\StandAloneSlv.exe [2007-07-23 675840]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 1533808]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-06-02 637952]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-30 183280]
S2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2008-01-28 85096]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-03-15 655624]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-16 271920]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2008-09-22 79360]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
-----------------EOF-----------------