Avast hlásí zavirovaný C:\window.exe
Napsal: 19 bře 2010 22:22
Výpis z RSIT:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2010-03-19 22:16:23
Microsoft Windows 2000 Professional Service Pack 4
System drive C: has 12 GB (65%) free of 19 GB
Total RAM: 255 MB (59% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:16:49, on 19.3.2010
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\system32\yuykmm.exe
C:\WINNT\SYSTEM32\DNTUS26.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\NMSSvc.exe
C:\WINNT\system32\HPZipm12.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINNT\system32\Promon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\RSIT.exe
C:\Program Files\trend micro\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [Promon.exe] Promon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {2CA0FF2C-0CE1-4382-A0C4-B2782965CCC2} (G-Vista ActiveX) - http://www.cenia.cz/3dmodel/mzp/plugin/gvista31.cab
O16 - DPF: {E99D3E39-5D92-4360-BA86-2C563B3CFFEB} (Microsoft CMS HTML Editor Toolbar) - https://cms.skoda-auto.com/Centria/CMS/ ... rdhtml.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FADF8571-2163-415C-91D8-8D3EA0124FA1}: NameServer = 212.20.64.1,212.20.64.2
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: aewsd (cae) - Unknown owner - C:\WINNT\system32\yuykmm.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare NT Utilities 2.6 (DNTUS26) - DameWare Development LLC - C:\WINNT\SYSTEM32\DNTUS26.EXE
O23 - Service: NMS Service (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Microsoft Windows Genuine Updater (wgudtr) - Unknown owner - C:\WINNT\csrss.exe
O23 - Service: Microsoft Event Manager (wlg) - Unknown owner - C:\WINNT\system32\wlgs.exe
--
End of file - 5152 bytes
======Scheduled tasks folder======
C:\WINNT\tasks\Avast041.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E718888-423F-11D2-876E-00A0C9082467} - &Rádio - C:\WINNT\system32\msdxm.ocx [2005-06-03 849168]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"=mobsync.exe /logon []
"Smapp"=C:\Program Files\Analog Devices\SoundMAX\Smtray.exe [2001-08-08 69632]
"EM_EXEC"=C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE [2001-07-26 34816]
"Promon.exe"=C:\WINNT\system32\Promon.exe [2001-07-05 31232]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2004-03-10 77824]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]
"NeroFilterCheck"=C:\WINNT\system32\NeroCheck.exe [2001-07-09 155648]
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2008-12-08 54576]
""= []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"=C:\WINNT\system32\internat.exe [2001-06-13 20752]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\nwprovau]
C:\WINNT\system32\nwprovau.dll [2006-09-01 140048]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=149
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\WINNT\System32\Notepad.exe %1
.js - open - C:\WINNT\System32\WScript.exe "%1" %*
.scr - open - "%1" /S "%3"
.vbs - edit - C:\WINNT\System32\Notepad.exe %1
.vbs - open - C:\WINNT\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-03-19 22:16:28 ----D---- C:\Program Files\trend micro
2010-03-19 22:16:23 ----D---- C:\rsit
2010-03-19 22:07:44 ----A---- C:\RSIT.exe
2010-03-19 21:53:41 ----A---- C:\window.exe
2010-03-15 11:16:51 ----A---- C:\WINNT\system32\msir2jp.dll
2010-03-15 11:16:51 ----A---- C:\WINNT\system32\kbdnecAT.dll
2010-03-15 11:16:51 ----A---- C:\WINNT\system32\kbdlk41j.dll
2010-03-15 11:16:51 ----A---- C:\WINNT\system32\kbdlk41a.dll
2010-03-15 11:16:50 ----A---- C:\WINNT\system32\kbdnecNT.dll
2010-03-15 11:16:50 ----A---- C:\WINNT\system32\kbdnec95.dll
2010-03-15 11:16:50 ----A---- C:\WINNT\system32\kbdibm02.dll
2010-03-15 11:16:50 ----A---- C:\WINNT\system32\kbdax2.dll
2010-03-15 11:16:50 ----A---- C:\WINNT\system32\kbd106n.dll
2010-03-15 11:16:50 ----A---- C:\WINNT\system32\kbd101.dll
2010-03-15 11:16:50 ----A---- C:\WINNT\system32\f3ahvoas.dll
2010-03-15 11:16:49 ----A---- C:\WINNT\system32\imejpmgr.exe
2010-03-15 11:16:32 ----A---- C:\WINNT\system32\ftlx0411.dll
2010-03-15 11:16:20 ----A---- C:\WINNT\system32\kbdjpn.dll
2010-03-15 11:16:16 ----A---- C:\WINNT\system32\kbd106.dll
2010-03-14 16:02:23 ----A---- C:\run.vbs
2010-03-12 17:54:24 ----A---- C:\WINNT\system32\135.exe
2010-03-12 12:26:43 ----A---- C:\WINNT\system32\chsbrkr.dll
2010-03-12 12:26:31 ----A---- C:\WINNT\system32\pyime.exe
2010-03-11 16:18:20 ----A---- C:\WINNT\system32\MRT.INI
2010-03-11 14:38:24 ----AS---- C:\WINNT\csrss.exe
2010-03-10 13:22:19 ----A---- C:\WINNT\system32\se6.exe
2010-03-06 13:07:52 ----A---- C:\WINNT\lee.exe
2010-03-06 13:07:42 ----A---- C:\WINNT\vis.bat
2010-03-05 12:51:41 ----A---- C:\WINNT\system32\yuykmm.exe
2010-03-04 10:20:23 ----A---- C:\WINNT\system32\svchost.exe.txt
2010-03-04 00:38:45 ----A---- C:\ff.bat
2010-03-04 00:38:45 ----A---- C:\a.bat
2010-02-22 17:13:20 ----AH---- C:\WINNT\system32\wlgs.exe
2010-02-22 13:45:13 ----RA---- C:\WINNT\system32\sc.exe
2010-02-22 13:45:11 ----RA---- C:\WINNT\system32\reg.exe
2010-02-22 13:45:10 ----RA---- C:\WINNT\system32\instsrv.exe
2010-02-22 13:44:48 ----A---- C:\WINNT\system32\DNTUS26.EXE
2010-02-22 01:37:20 ----A---- C:\WINNT\system32\find.bat
2010-02-22 01:37:20 ----A---- C:\WINNT\system32\edu.ini
2010-02-22 01:36:49 ----A---- C:\WINNT\system32\explorers.exe
2010-02-21 22:58:59 ----RASH---- C:\WINNT\asr_33364.exe
2010-02-21 13:45:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\HP
2010-02-21 13:41:24 ----D---- C:\Program Files\Common Files\HP
2010-02-21 13:37:12 ----D---- C:\Program Files\Common Files\Hewlett-Packard
2010-02-21 13:33:36 ----RA---- C:\WINNT\system32\HPZc3212.dll
2010-02-21 13:33:36 ----RA---- C:\WINNT\system32\hpovst08.dll
2010-02-21 13:33:35 ----RA---- C:\WINNT\system32\hpotscl.dll
2010-02-21 13:33:35 ----RA---- C:\WINNT\system32\hpgtpusd.dll
2010-02-21 13:30:08 ----A---- C:\WINNT\system32\HPZisn12.dll
2010-02-21 13:30:08 ----A---- C:\WINNT\system32\HPZipt12.dll
2010-02-21 13:30:08 ----A---- C:\WINNT\system32\HPZipm12.exe
2010-02-21 13:30:08 ----A---- C:\WINNT\system32\HPZinw12.exe
2010-02-21 13:30:07 ----A---- C:\WINNT\system32\HPZipr12.dll
2010-02-21 13:30:07 ----A---- C:\WINNT\system32\HPZidr12.dll
2010-02-21 13:21:35 ----D---- C:\Documents and Settings\All Users\Data aplikací\PrevxCSI
2010-02-21 13:21:34 ----A---- C:\WINNT\wininit.ini
2010-02-21 13:17:29 ----AHD---- C:\Config.Msi
2010-02-21 13:15:10 ----D---- C:\Documents and Settings\Administrator\Data aplikací\HP
======List of files/folders modified in the last 1 months======
2010-03-19 22:16:28 ----RD---- C:\Program Files
2010-03-19 22:16:27 ----D---- C:\WINNT\SYSTEM32
2010-03-19 20:31:15 ----D---- C:\WINNT\Temp
2010-03-19 12:00:51 ----D---- C:\WINNT\SECURITY
2010-03-19 08:12:40 ----D---- C:\WINNT\Debug
2010-03-19 08:10:50 ----SHD---- C:\WINNT\CSC
2010-03-19 08:10:49 ----D---- C:\WINNT\system32\CONFIG
2010-03-19 08:10:06 ----D---- C:\WINNT
2010-03-19 07:58:01 ----A---- C:\WINNT\run.vbs
2010-03-16 04:13:06 ----D---- C:\Program Files\Google
2010-03-15 11:16:57 ----D---- C:\WINNT\system32\DLLCACHE
2010-03-15 11:16:51 ----D---- C:\WINNT\Help
2010-03-15 11:16:37 ----RSD---- C:\WINNT\Fonts
2010-03-12 11:25:49 ----D---- C:\WINNT\system32\NtmsData
2010-03-11 21:56:45 ----A---- C:\WINNT\SchedLgU.Txt
2010-03-02 06:30:12 ----A---- C:\WINNT\system32\MRT.exe
2010-02-26 10:19:19 ----SD---- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
2010-02-22 16:27:24 ----SD---- C:\WINNT\Tasks
2010-02-21 13:48:39 ----SHD---- C:\WINNT\Installer
2010-02-21 13:46:58 ----A---- C:\WINNT\WIN.INI
2010-02-21 13:41:24 ----D---- C:\Program Files\Hp
2010-02-21 13:41:24 ----D---- C:\Program Files\Common Files
2010-02-21 13:38:14 ----D---- C:\WINNT\system32\DRIVERS
2010-02-21 13:38:10 ----D---- C:\WINNT\TWAIN_32
2010-02-21 13:28:08 ----HD---- C:\WINNT\INF
2010-02-20 15:04:09 ----D---- C:\Documents and Settings
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINNT\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 aswSP;avast! Self Protection; C:\WINNT\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINNT\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 Cdr4_2K;Cdr4_2K; C:\WINNT\system32\drivers\Cdr4_2K.sys [2001-03-02 52720]
R1 ClntMgmt.sys;ClntMgmt; C:\WINNT\System32\Drivers\ClntMgmt.sys [2001-05-18 44624]
R2 aswFsBlk;aswFsBlk; C:\WINNT\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon;avast! Standard Shield Support; C:\WINNT\system32\drivers\aswMon.sys [2009-11-25 93424]
R2 Cdralw2k;Cdralw2k; C:\WINNT\system32\drivers\Cdralw2k.sys [2001-03-02 22585]
R3 aswRdr;aswRdr; C:\WINNT\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 E100B;Intel(R) PRO Adapter Driver; C:\WINNT\System32\DRIVERS\e100bnt5.sys [2001-05-18 119056]
R3 FTD2XX;FTD2XX.SYS FT8U2XX device driver; C:\WINNT\System32\Drivers\FTD2XX.sys [2004-10-15 29292]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINNT\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINNT\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINNT\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
R3 ichaud;Služba pro ovladač AC'97 (WDM); C:\WINNT\system32\drivers\ichaud.sys [1999-10-22 32592]
R3 l8042pr2;Logitech PS/2 Mouse Filter Driver; C:\WINNT\System32\DRIVERS\L8042pr2.sys [2001-07-23 50462]
R3 lkbdflt2;Logitech Keyboard Class Filter Driver; C:\WINNT\System32\DRIVERS\lkbdflt2.sys [2001-07-23 5838]
R3 lmouflt2;Logitech Mouse Class Filter Driver; C:\WINNT\System32\DRIVERS\lmouflt2.sys [2001-07-23 66142]
R3 NMSCFG;NIC Management Service Configuration Driver; \??\C:\WINNT\system32\drivers\NMSCFG.SYS []
R3 nv4;nv4; C:\WINNT\System32\DRIVERS\nv4_mini.sys [2001-06-07 785625]
R3 uhcd;Ovladač univerzálního hostitelského řadiče USB; C:\WINNT\System32\DRIVERS\uhcd.sys [2003-06-19 32848]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINNT\System32\DRIVERS\usbhub.sys [2003-06-19 40176]
R3 usbprint;Třída USB Printer; C:\WINNT\System32\DRIVERS\usbprint.sys [2003-06-19 21872]
R3 usbscan;Ovladač skeneru USB; C:\WINNT\System32\DRIVERS\usbscan.sys [2003-06-19 12592]
S2 HidUsb;Ovladač třídy standardu HID; C:\WINNT\System32\DRIVERS\hidusb.sys [1999-10-04 13904]
S3 CCDECODE;Closed Caption Decoder; C:\WINNT\system32\DRIVERS\CCDECODE.sys [2001-10-08 15264]
S3 Dot4;HPPA IEEE-1284.4 Driver; C:\WINNT\system32\DRIVERS\hppadt40.sys [2001-01-16 50576]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINNT\system32\DRIVERS\hppaprt0.sys [2001-01-16 15792]
S3 mouhid;Ovladač myši standardu HID; C:\WINNT\System32\DRIVERS\mouhid.sys [2003-06-19 11632]
S3 MPE;BDA MPE Filter; C:\WINNT\system32\DRIVERS\MPE.sys [2001-10-16 13952]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINNT\system32\drivers\MSTEE.sys [2002-05-01 4896]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINNT\system32\DRIVERS\NABTSFEC.sys [2001-10-08 86016]
S3 SLIP;BDA Slip De-Framer; C:\WINNT\system32\DRIVERS\SLIP.sys [2001-10-16 10368]
S3 smwdm;smwdm; C:\WINNT\system32\drivers\smwdm.sys [2001-08-24 442168]
S3 streamip;BDA IPSink; C:\WINNT\system32\DRIVERS\StreamIP.sys [2001-10-16 14400]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINNT\System32\DRIVERS\USBSTOR.SYS [2003-06-19 21552]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINNT\system32\DRIVERS\WSTCODEC.SYS [2001-10-08 18208]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 cae;aewsd; C:\WINNT\system32\yuykmm.exe [2010-03-05 45056]
R2 DNTUS26;DameWare NT Utilities 2.6; C:\WINNT\SYSTEM32\DNTUS26.EXE [2008-11-24 114688]
R2 ias;rtpyfhmy; C:\WINNT\System32\svchost.exe [2001-06-13 7952]
R2 NMSSvc;NMS Service; C:\WINNT\System32\NMSSvc.exe [2001-04-16 1036288]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINNT\system32\HPZipm12.exe [2004-09-29 69632]
R2 StiSvc;Still Image Service; C:\WINNT\system32\stisvc.exe [2003-06-19 61712]
R2 WMDM PMSP Service;WMDM PMSP Service; C:\WINNT\system32\mspmspsv.exe [2001-05-01 53248]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
S2 wlg;Microsoft Event Manager; C:\WINNT\system32\wlgs.exe [2007-01-02 15360]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 wgudtr;Microsoft Windows Genuine Updater; C:\WINNT\csrss.exe [2004-08-11 65536]
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2010-03-19 22:16:23
Microsoft Windows 2000 Professional Service Pack 4
System drive C: has 12 GB (65%) free of 19 GB
Total RAM: 255 MB (59% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:16:49, on 19.3.2010
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\system32\yuykmm.exe
C:\WINNT\SYSTEM32\DNTUS26.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\NMSSvc.exe
C:\WINNT\system32\HPZipm12.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINNT\system32\Promon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\RSIT.exe
C:\Program Files\trend micro\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [Promon.exe] Promon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {2CA0FF2C-0CE1-4382-A0C4-B2782965CCC2} (G-Vista ActiveX) - http://www.cenia.cz/3dmodel/mzp/plugin/gvista31.cab
O16 - DPF: {E99D3E39-5D92-4360-BA86-2C563B3CFFEB} (Microsoft CMS HTML Editor Toolbar) - https://cms.skoda-auto.com/Centria/CMS/ ... rdhtml.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FADF8571-2163-415C-91D8-8D3EA0124FA1}: NameServer = 212.20.64.1,212.20.64.2
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: aewsd (cae) - Unknown owner - C:\WINNT\system32\yuykmm.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare NT Utilities 2.6 (DNTUS26) - DameWare Development LLC - C:\WINNT\SYSTEM32\DNTUS26.EXE
O23 - Service: NMS Service (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Microsoft Windows Genuine Updater (wgudtr) - Unknown owner - C:\WINNT\csrss.exe
O23 - Service: Microsoft Event Manager (wlg) - Unknown owner - C:\WINNT\system32\wlgs.exe
--
End of file - 5152 bytes
======Scheduled tasks folder======
C:\WINNT\tasks\Avast041.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E718888-423F-11D2-876E-00A0C9082467} - &Rádio - C:\WINNT\system32\msdxm.ocx [2005-06-03 849168]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"=mobsync.exe /logon []
"Smapp"=C:\Program Files\Analog Devices\SoundMAX\Smtray.exe [2001-08-08 69632]
"EM_EXEC"=C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE [2001-07-26 34816]
"Promon.exe"=C:\WINNT\system32\Promon.exe [2001-07-05 31232]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2004-03-10 77824]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]
"NeroFilterCheck"=C:\WINNT\system32\NeroCheck.exe [2001-07-09 155648]
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2008-12-08 54576]
""= []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"=C:\WINNT\system32\internat.exe [2001-06-13 20752]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\nwprovau]
C:\WINNT\system32\nwprovau.dll [2006-09-01 140048]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=149
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\WINNT\System32\Notepad.exe %1
.js - open - C:\WINNT\System32\WScript.exe "%1" %*
.scr - open - "%1" /S "%3"
.vbs - edit - C:\WINNT\System32\Notepad.exe %1
.vbs - open - C:\WINNT\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-03-19 22:16:28 ----D---- C:\Program Files\trend micro
2010-03-19 22:16:23 ----D---- C:\rsit
2010-03-19 22:07:44 ----A---- C:\RSIT.exe
2010-03-19 21:53:41 ----A---- C:\window.exe
2010-03-15 11:16:51 ----A---- C:\WINNT\system32\msir2jp.dll
2010-03-15 11:16:51 ----A---- C:\WINNT\system32\kbdnecAT.dll
2010-03-15 11:16:51 ----A---- C:\WINNT\system32\kbdlk41j.dll
2010-03-15 11:16:51 ----A---- C:\WINNT\system32\kbdlk41a.dll
2010-03-15 11:16:50 ----A---- C:\WINNT\system32\kbdnecNT.dll
2010-03-15 11:16:50 ----A---- C:\WINNT\system32\kbdnec95.dll
2010-03-15 11:16:50 ----A---- C:\WINNT\system32\kbdibm02.dll
2010-03-15 11:16:50 ----A---- C:\WINNT\system32\kbdax2.dll
2010-03-15 11:16:50 ----A---- C:\WINNT\system32\kbd106n.dll
2010-03-15 11:16:50 ----A---- C:\WINNT\system32\kbd101.dll
2010-03-15 11:16:50 ----A---- C:\WINNT\system32\f3ahvoas.dll
2010-03-15 11:16:49 ----A---- C:\WINNT\system32\imejpmgr.exe
2010-03-15 11:16:32 ----A---- C:\WINNT\system32\ftlx0411.dll
2010-03-15 11:16:20 ----A---- C:\WINNT\system32\kbdjpn.dll
2010-03-15 11:16:16 ----A---- C:\WINNT\system32\kbd106.dll
2010-03-14 16:02:23 ----A---- C:\run.vbs
2010-03-12 17:54:24 ----A---- C:\WINNT\system32\135.exe
2010-03-12 12:26:43 ----A---- C:\WINNT\system32\chsbrkr.dll
2010-03-12 12:26:31 ----A---- C:\WINNT\system32\pyime.exe
2010-03-11 16:18:20 ----A---- C:\WINNT\system32\MRT.INI
2010-03-11 14:38:24 ----AS---- C:\WINNT\csrss.exe
2010-03-10 13:22:19 ----A---- C:\WINNT\system32\se6.exe
2010-03-06 13:07:52 ----A---- C:\WINNT\lee.exe
2010-03-06 13:07:42 ----A---- C:\WINNT\vis.bat
2010-03-05 12:51:41 ----A---- C:\WINNT\system32\yuykmm.exe
2010-03-04 10:20:23 ----A---- C:\WINNT\system32\svchost.exe.txt
2010-03-04 00:38:45 ----A---- C:\ff.bat
2010-03-04 00:38:45 ----A---- C:\a.bat
2010-02-22 17:13:20 ----AH---- C:\WINNT\system32\wlgs.exe
2010-02-22 13:45:13 ----RA---- C:\WINNT\system32\sc.exe
2010-02-22 13:45:11 ----RA---- C:\WINNT\system32\reg.exe
2010-02-22 13:45:10 ----RA---- C:\WINNT\system32\instsrv.exe
2010-02-22 13:44:48 ----A---- C:\WINNT\system32\DNTUS26.EXE
2010-02-22 01:37:20 ----A---- C:\WINNT\system32\find.bat
2010-02-22 01:37:20 ----A---- C:\WINNT\system32\edu.ini
2010-02-22 01:36:49 ----A---- C:\WINNT\system32\explorers.exe
2010-02-21 22:58:59 ----RASH---- C:\WINNT\asr_33364.exe
2010-02-21 13:45:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\HP
2010-02-21 13:41:24 ----D---- C:\Program Files\Common Files\HP
2010-02-21 13:37:12 ----D---- C:\Program Files\Common Files\Hewlett-Packard
2010-02-21 13:33:36 ----RA---- C:\WINNT\system32\HPZc3212.dll
2010-02-21 13:33:36 ----RA---- C:\WINNT\system32\hpovst08.dll
2010-02-21 13:33:35 ----RA---- C:\WINNT\system32\hpotscl.dll
2010-02-21 13:33:35 ----RA---- C:\WINNT\system32\hpgtpusd.dll
2010-02-21 13:30:08 ----A---- C:\WINNT\system32\HPZisn12.dll
2010-02-21 13:30:08 ----A---- C:\WINNT\system32\HPZipt12.dll
2010-02-21 13:30:08 ----A---- C:\WINNT\system32\HPZipm12.exe
2010-02-21 13:30:08 ----A---- C:\WINNT\system32\HPZinw12.exe
2010-02-21 13:30:07 ----A---- C:\WINNT\system32\HPZipr12.dll
2010-02-21 13:30:07 ----A---- C:\WINNT\system32\HPZidr12.dll
2010-02-21 13:21:35 ----D---- C:\Documents and Settings\All Users\Data aplikací\PrevxCSI
2010-02-21 13:21:34 ----A---- C:\WINNT\wininit.ini
2010-02-21 13:17:29 ----AHD---- C:\Config.Msi
2010-02-21 13:15:10 ----D---- C:\Documents and Settings\Administrator\Data aplikací\HP
======List of files/folders modified in the last 1 months======
2010-03-19 22:16:28 ----RD---- C:\Program Files
2010-03-19 22:16:27 ----D---- C:\WINNT\SYSTEM32
2010-03-19 20:31:15 ----D---- C:\WINNT\Temp
2010-03-19 12:00:51 ----D---- C:\WINNT\SECURITY
2010-03-19 08:12:40 ----D---- C:\WINNT\Debug
2010-03-19 08:10:50 ----SHD---- C:\WINNT\CSC
2010-03-19 08:10:49 ----D---- C:\WINNT\system32\CONFIG
2010-03-19 08:10:06 ----D---- C:\WINNT
2010-03-19 07:58:01 ----A---- C:\WINNT\run.vbs
2010-03-16 04:13:06 ----D---- C:\Program Files\Google
2010-03-15 11:16:57 ----D---- C:\WINNT\system32\DLLCACHE
2010-03-15 11:16:51 ----D---- C:\WINNT\Help
2010-03-15 11:16:37 ----RSD---- C:\WINNT\Fonts
2010-03-12 11:25:49 ----D---- C:\WINNT\system32\NtmsData
2010-03-11 21:56:45 ----A---- C:\WINNT\SchedLgU.Txt
2010-03-02 06:30:12 ----A---- C:\WINNT\system32\MRT.exe
2010-02-26 10:19:19 ----SD---- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
2010-02-22 16:27:24 ----SD---- C:\WINNT\Tasks
2010-02-21 13:48:39 ----SHD---- C:\WINNT\Installer
2010-02-21 13:46:58 ----A---- C:\WINNT\WIN.INI
2010-02-21 13:41:24 ----D---- C:\Program Files\Hp
2010-02-21 13:41:24 ----D---- C:\Program Files\Common Files
2010-02-21 13:38:14 ----D---- C:\WINNT\system32\DRIVERS
2010-02-21 13:38:10 ----D---- C:\WINNT\TWAIN_32
2010-02-21 13:28:08 ----HD---- C:\WINNT\INF
2010-02-20 15:04:09 ----D---- C:\Documents and Settings
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINNT\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 aswSP;avast! Self Protection; C:\WINNT\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINNT\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 Cdr4_2K;Cdr4_2K; C:\WINNT\system32\drivers\Cdr4_2K.sys [2001-03-02 52720]
R1 ClntMgmt.sys;ClntMgmt; C:\WINNT\System32\Drivers\ClntMgmt.sys [2001-05-18 44624]
R2 aswFsBlk;aswFsBlk; C:\WINNT\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon;avast! Standard Shield Support; C:\WINNT\system32\drivers\aswMon.sys [2009-11-25 93424]
R2 Cdralw2k;Cdralw2k; C:\WINNT\system32\drivers\Cdralw2k.sys [2001-03-02 22585]
R3 aswRdr;aswRdr; C:\WINNT\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 E100B;Intel(R) PRO Adapter Driver; C:\WINNT\System32\DRIVERS\e100bnt5.sys [2001-05-18 119056]
R3 FTD2XX;FTD2XX.SYS FT8U2XX device driver; C:\WINNT\System32\Drivers\FTD2XX.sys [2004-10-15 29292]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINNT\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINNT\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINNT\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
R3 ichaud;Služba pro ovladač AC'97 (WDM); C:\WINNT\system32\drivers\ichaud.sys [1999-10-22 32592]
R3 l8042pr2;Logitech PS/2 Mouse Filter Driver; C:\WINNT\System32\DRIVERS\L8042pr2.sys [2001-07-23 50462]
R3 lkbdflt2;Logitech Keyboard Class Filter Driver; C:\WINNT\System32\DRIVERS\lkbdflt2.sys [2001-07-23 5838]
R3 lmouflt2;Logitech Mouse Class Filter Driver; C:\WINNT\System32\DRIVERS\lmouflt2.sys [2001-07-23 66142]
R3 NMSCFG;NIC Management Service Configuration Driver; \??\C:\WINNT\system32\drivers\NMSCFG.SYS []
R3 nv4;nv4; C:\WINNT\System32\DRIVERS\nv4_mini.sys [2001-06-07 785625]
R3 uhcd;Ovladač univerzálního hostitelského řadiče USB; C:\WINNT\System32\DRIVERS\uhcd.sys [2003-06-19 32848]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINNT\System32\DRIVERS\usbhub.sys [2003-06-19 40176]
R3 usbprint;Třída USB Printer; C:\WINNT\System32\DRIVERS\usbprint.sys [2003-06-19 21872]
R3 usbscan;Ovladač skeneru USB; C:\WINNT\System32\DRIVERS\usbscan.sys [2003-06-19 12592]
S2 HidUsb;Ovladač třídy standardu HID; C:\WINNT\System32\DRIVERS\hidusb.sys [1999-10-04 13904]
S3 CCDECODE;Closed Caption Decoder; C:\WINNT\system32\DRIVERS\CCDECODE.sys [2001-10-08 15264]
S3 Dot4;HPPA IEEE-1284.4 Driver; C:\WINNT\system32\DRIVERS\hppadt40.sys [2001-01-16 50576]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINNT\system32\DRIVERS\hppaprt0.sys [2001-01-16 15792]
S3 mouhid;Ovladač myši standardu HID; C:\WINNT\System32\DRIVERS\mouhid.sys [2003-06-19 11632]
S3 MPE;BDA MPE Filter; C:\WINNT\system32\DRIVERS\MPE.sys [2001-10-16 13952]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINNT\system32\drivers\MSTEE.sys [2002-05-01 4896]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINNT\system32\DRIVERS\NABTSFEC.sys [2001-10-08 86016]
S3 SLIP;BDA Slip De-Framer; C:\WINNT\system32\DRIVERS\SLIP.sys [2001-10-16 10368]
S3 smwdm;smwdm; C:\WINNT\system32\drivers\smwdm.sys [2001-08-24 442168]
S3 streamip;BDA IPSink; C:\WINNT\system32\DRIVERS\StreamIP.sys [2001-10-16 14400]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINNT\System32\DRIVERS\USBSTOR.SYS [2003-06-19 21552]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINNT\system32\DRIVERS\WSTCODEC.SYS [2001-10-08 18208]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 cae;aewsd; C:\WINNT\system32\yuykmm.exe [2010-03-05 45056]
R2 DNTUS26;DameWare NT Utilities 2.6; C:\WINNT\SYSTEM32\DNTUS26.EXE [2008-11-24 114688]
R2 ias;rtpyfhmy; C:\WINNT\System32\svchost.exe [2001-06-13 7952]
R2 NMSSvc;NMS Service; C:\WINNT\System32\NMSSvc.exe [2001-04-16 1036288]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINNT\system32\HPZipm12.exe [2004-09-29 69632]
R2 StiSvc;Still Image Service; C:\WINNT\system32\stisvc.exe [2003-06-19 61712]
R2 WMDM PMSP Service;WMDM PMSP Service; C:\WINNT\system32\mspmspsv.exe [2001-05-01 53248]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
S2 wlg;Microsoft Event Manager; C:\WINNT\system32\wlgs.exe [2007-01-02 15360]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 wgudtr;Microsoft Windows Genuine Updater; C:\WINNT\csrss.exe [2004-08-11 65536]
-----------------EOF-----------------