VIRUS, MALWARE
Napsal: 28 bře 2010 09:53
Dobrý den, mám problém s chováním počítače: některé akce jsou zpomalené, padá většina webových stránek. Prosím o radu. Zasílám scan z RSIT.
Díky.
Logfile of random's system information tool 1.06 (written by random/random)
Run by MJ at 2010-03-28 10:51:36
Systém Microsoft Windows XP Professional Service Pack 1
System drive C: has 29 GB (77%) free of 38 GB
Total RAM: 1014 MB (79% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:51:44, on 28.3.2010
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\MJ\Plocha\RSIT.exe
C:\Program Files\trend micro\MJ.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\msupdt.exe,
O1 - Hosts: 1.2.3.4 13iii.com
O1 - Hosts: 1.2.3.4 2-spyware.com
O1 - Hosts: 1.2.3.4 247fixes.com
O1 - Hosts: 1.2.3.4 360.cn
O1 - Hosts: 1.2.3.4 360.com
O1 - Hosts: 1.2.3.4 360safe.cn
O1 - Hosts: 1.2.3.4 360safe.com
O1 - Hosts: 1.2.3.4 4-gsmteam.com
O1 - Hosts: 1.2.3.4 51nb.com
O1 - Hosts: 1.2.3.4 Merijn.org
O1 - Hosts: 1.2.3.4 abgenis.net
O1 - Hosts: 1.2.3.4 acs.pandasoftware.com
O1 - Hosts: 1.2.3.4 acs.pandasoftware.com
O1 - Hosts: 1.2.3.4 ad-aware-se.uptodown.com
O1 - Hosts: 1.2.3.4 ad13.geekstogo.com
O1 - Hosts: 1.2.3.4 aknow.prevx.com
O1 - Hosts: 1.2.3.4 alabamawomen.org
O1 - Hosts: 1.2.3.4 alerta-antivirus.inteco.es
O1 - Hosts: 1.2.3.4 alerta-antivirus.inteco.es
O1 - Hosts: 1.2.3.4 alerta-antivirus.red.es
O1 - Hosts: 1.2.3.4 alfrasha.maktoob.com
O1 - Hosts: 1.2.3.4 analysis.seclab.tuwien.ac.at
O1 - Hosts: 1.2.3.4 andymanchesta.com
O1 - Hosts: 1.2.3.4 andymanchesta.com
O1 - Hosts: 1.2.3.4 angui123.cn
O1 - Hosts: 1.2.3.4 anti-virus-softwarereview.
O1 - Hosts: 1.2.3.4 toptenreviews.com
O1 - Hosts: 1.2.3.4 antirootkit.com
O1 - Hosts: 1.2.3.4 antitrick.com
O1 - Hosts: 1.2.3.4 antivir.es
O1 - Hosts: 1.2.3.4 antivirus.about.com
O1 - Hosts: 1.2.3.4 antivirus.comodo.com
O1 - Hosts: 1.2.3.4 ar.answers.yahoo.com
O1 - Hosts: 1.2.3.4 arenajunkies.com
O1 - Hosts: 1.2.3.4 ariefew.com
O1 - Hosts: 1.2.3.4 arswp.com
O1 - Hosts: 1.2.3.4 askmehelpdesk.com
O1 - Hosts: 1.2.3.4 atazita.blogspot.com
O1 - Hosts: 1.2.3.4 auditmypc.com
O1 - Hosts: 1.2.3.4 avast-home.uptodown.com
O1 - Hosts: 1.2.3.4 avast.com
O1 - Hosts: 1.2.3.4 avg-antivirus.net
O1 - Hosts: 1.2.3.4 avast.com
O1 - Hosts: 1.2.3.4 avg-antivirus.net
O1 - Hosts: 1.2.3.4 avg.vo.llnwd.net
O1 - Hosts: 1.2.3.4 avira.com
O1 - Hosts: 1.2.3.4 avp.com
O1 - Hosts: 1.2.3.4 avpclub.ddns.info
O1 - Hosts: 1.2.3.4 avsoft.ru
O1 - Hosts: 1.2.3.4 babooforum.com.br
O1 - Hosts: 1.2.3.4 baike.360.cn
O1 - Hosts: 1.2.3.4 baike.360.com
O1 - Hosts: 1.2.3.4 bakunos.com
O1 - Hosts: 1.2.3.4 bb1.th3kings.net
O1 - Hosts: 1.2.3.4 bbs.360safe.cn
O1 - Hosts: 1.2.3.4 bbs.360safe.cn
O1 - Hosts: 1.2.3.4 bbs.360safe.com
O1 - Hosts: 1.2.3.4 bbs.360safe.com
O1 - Hosts: 1.2.3.4 bbs.cfan.com.cn
O1 - Hosts: 1.2.3.4 bbs.duba.net
O1 - Hosts: 1.2.3.4 bbs.ikaka.com
O1 - Hosts: 1.2.3.4 bbs.kafan.cn
O1 - Hosts: 1.2.3.4 bbs.kafan.com
O1 - Hosts: 1.2.3.4 bbs.kaspersky.com.cn
O1 - Hosts: 1.2.3.4 bbs.kpfans.com
O1 - Hosts: 1.2.3.4 bbs.s-sos.net
O1 - Hosts: 1.2.3.4 bbs.taisha.org
O1 - Hosts: 1.2.3.4 bbs.winzheng.com
O1 - Hosts: 1.2.3.4 beniono.wordpress.com
O1 - Hosts: 1.2.3.4 beta.eset.com
O1 - Hosts: 1.2.3.4 betterantivirus.com
O1 - Hosts: 1.2.3.4 bitdefender.com
O1 - Hosts: 1.2.3.4 bitdefender.es
O1 - Hosts: 1.2.3.4 bleedingthreats.net
O1 - Hosts: 1.2.3.4 bleepingcomputer.com
O1 - Hosts: 1.2.3.4 blindedbytech.com
O1 - Hosts: 1.2.3.4 blog.hispasec.com
O1 - Hosts: 1.2.3.4 blog.rnsafe.com
O1 - Hosts: 1.2.3.4 blog.threatfire.com
O1 - Hosts: 1.2.3.4 blogs.icerocket.com
O1 - Hosts: 1.2.3.4 blogschapines.com
O1 - Hosts: 1.2.3.4 blokvesti.net
O1 - Hosts: 1.2.3.4 board.softpedia.com
O1 - Hosts: 1.2.3.4 blokvesti.net
O1 - Hosts: 1.2.3.4 board.softpedia.com
O1 - Hosts: 1.2.3.4 boardreader.com
O1 - Hosts: 1.2.3.4 box.net
O1 - Hosts: 1.2.3.4 bub.th3kings.net
O1 - Hosts: 1.2.3.4 ca.com
O1 - Hosts: 1.2.3.4 cairopt.net
O1 - Hosts: 1.2.3.4 cairopt.net
O1 - Hosts: 1.2.3.4 castlecops.com
O1 - Hosts: 1.2.3.4 castlecrops.com
O1 - Hosts: 1.2.3.4 cddchiangmai.net
O1 - Hosts: 1.2.3.4 cddchiangmai.net
O1 - Hosts: 1.2.3.4 cert.inteco.es
O1 - Hosts: 1.2.3.4 cfan.com.cn
O1 - Hosts: 1.2.3.4 changedetection.com
O1 - Hosts: 1.2.3.4 changelog.fr
O1 - Hosts: 1.2.3.4 chkrootkit.org
O1 - Hosts: 1.2.3.4 cisrt.org
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [syncman] c:\windows\system32\wuaucldt.exe
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [syncman] c:\documents and settings\mj\wuaucldt.exe
O4 - HKCU\..\Run: [cleansweep.exe] C:\cleansweep.exe\cleansweep.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O15 - Trusted Zone: http://asia.msi.com.tw
O15 - Trusted Zone: http://global.msi.com.tw
O15 - Trusted Zone: http://www.msi.com.tw
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0800136140
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/L ... nstall.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: LGootkitSSO - {93D17AF7-7ECC-4086-95A8-8C983F3051AF} - (no file)
O21 - SSODL: GootkitSSO - {BAEA9C10-EA4D-44AB-84E4-95F9ABD95AB6} - (no file)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Služba Google Update (gupdate1ca8f788138d1b4) (gupdate1ca8f788138d1b4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
--
End of file - 9147 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Gqhbg.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-01-30 279664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-01-30 812528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E718888-423F-11D2-876E-00A0C9082467} - &Rádio - C:\WINDOWS\System32\msdxm.ocx [2002-09-20 844828]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-01-30 279664]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2009-12-10 18789920]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-12-28 417792]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"RemoteControl"=C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe [2004-11-02 32768]
"InCD"=C:\Program Files\Ahead\InCD\InCD.exe [2005-07-08 1397760]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"syncman"=c:\windows\system32\wuaucldt.exe [2010-03-24 29475]
"Regedit32"=C:\WINDOWS\system32\regedit.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-12-14 39408]
"syncman"=c:\documents and settings\mj\wuaucldt.exe [2010-03-24 29475]
"cleansweep.exe"=C:\cleansweep.exe\cleansweep.exe [2002-09-20 89088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
LGootkitSSO - {93D17AF7-7ECC-4086-95A8-8C983F3051AF}
GootkitSSO - {BAEA9C10-EA4D-44AB-84E4-95F9ABD95AB6}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2010-03-28 10:46:59 ----A---- C:\WINDOWS\ntbtlog.txt
2010-03-24 20:08:46 ----A---- C:\WINDOWS\System32\sblog.txt
2010-03-24 20:08:30 ----A---- C:\WINDOWS\System32\wuaucldt.exe
2010-03-10 20:11:28 ----A---- C:\WINDOWS\NeroDigital.ini
2010-03-10 20:11:24 ----D---- C:\Documents and Settings\MJ\Data aplikací\CyberLink
2010-03-10 20:10:25 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\CyberLink
2010-03-10 20:06:02 ----D---- C:\Program Files\Common Files\LightScribe
2010-03-10 20:04:47 ----N---- C:\WINDOWS\System32\TwnLib4.dll
2010-03-10 20:04:47 ----A---- C:\WINDOWS\System32\TwnLib20.dll
2010-03-10 20:04:44 ----N---- C:\WINDOWS\System32\ImagXRA7.dll
2010-03-10 20:04:44 ----N---- C:\WINDOWS\System32\ImagXR7.dll
2010-03-10 20:04:43 ----N---- C:\WINDOWS\System32\ImagXpr7.dll
2010-03-10 20:04:43 ----N---- C:\WINDOWS\System32\ImagX7.dll
2010-03-10 20:04:42 ----A---- C:\WINDOWS\System32\NeroCheck.exe
2010-03-10 20:04:10 ----N---- C:\WINDOWS\NuNinst.exe
2010-03-10 20:04:07 ----D---- C:\Program Files\Common Files\Ahead
2010-03-10 20:04:04 ----D---- C:\WINDOWS\InCD
2010-03-10 20:04:04 ----D---- C:\Program Files\Ahead
2010-03-10 20:02:14 ----D---- C:\Program Files\CyberLink
2010-03-10 20:01:58 ----D---- C:\MyWorks
2010-03-10 20:01:48 ----A---- C:\Program Files\Uninstall_CDS.exe
2010-03-10 20:01:47 ----D---- C:\Program Files\CyberLink DVD Solution
2010-03-02 21:36:40 ----D---- C:\Program Files\GRETECH
======List of files/folders modified in the last 1 months======
2010-03-28 10:51:38 ----D---- C:\Program Files\trend micro
2010-03-28 10:46:59 ----D---- C:\WINDOWS
2010-03-28 10:46:07 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-28 10:45:12 ----D---- C:\Documents and Settings\MJ\Data aplikací\Skype
2010-03-28 10:29:42 ----D---- C:\WINDOWS\temp
2010-03-28 10:28:43 ----D---- C:\WINDOWS\system32
2010-03-28 10:28:43 ----A---- C:\WINDOWS\System32\PerfStringBackup.INI
2010-03-28 10:28:34 ----D---- C:\Documents and Settings\MJ\Data aplikací\skypePM
2010-03-28 10:28:27 ----D---- C:\WINDOWS\System32\CatRoot2
2010-03-28 10:28:20 ----D---- C:\WINDOWS\Prefetch
2010-03-28 10:27:04 ----D---- C:\WINDOWS\Debug
2010-03-25 00:16:21 ----D---- C:\WINDOWS\Minidump
2010-03-24 20:08:38 ----D---- C:\cleansweep.exe
2010-03-24 20:08:36 ----RSHDC---- C:\WINDOWS\System32\dllcache
2010-03-24 20:08:35 ----D---- C:\WINDOWS\System32\drivers
2010-03-18 08:15:26 ----SHD---- C:\WINDOWS\Installer
2010-03-10 20:06:02 ----D---- C:\Program Files\Common Files
2010-03-10 20:04:04 ----RD---- C:\Program Files
2010-03-10 20:03:37 ----HD---- C:\Program Files\InstallShield Installation Information
2010-03-10 20:01:02 ----D---- C:\Program Files\Common Files\InstallShield
2010-03-04 16:15:28 ----D---- C:\Program Files\Winamp
2010-03-02 23:27:21 ----D---- C:\Documents and Settings\MJ\Data aplikací\Adobe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgntdd;avgntdd; C:\WINDOWS\SYSTEM32\DRIVERS\avgntdd.sys [2009-02-13 45416]
R1 InCDPass;InCDPass; C:\WINDOWS\System32\DRIVERS\InCDPass.sys [2005-07-08 29696]
R1 incdrm;InCD Reader; C:\WINDOWS\System32\drivers\incdrm.sys [2005-07-08 28672]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtenicxp.sys [2009-06-05 142336]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2002-08-29 19328]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2002-08-29 51968]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2002-08-29 19328]
S1 avipbb;avipbb; C:\WINDOWS\System32\DRIVERS\avipbb.sys [2009-03-30 96104]
S1 ssmdrv;ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-12-10 6017568]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2002-08-29 14208]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2002-08-29 21760]
S4 InCDfs;InCD File System; C:\WINDOWS\System32\drivers\InCDfs.sys [2005-07-08 99584]
S4 IntelIde;IntelIde; C:\WINDOWS\System32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
S2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
S2 gupdate1ca8f788138d1b4;Služba Google Update (gupdate1ca8f788138d1b4); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-07 133104]
S2 InCDsrv;InCD Helper; C:\Program Files\Ahead\InCD\InCDsrv.exe [2005-07-08 871424]
S2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-02-17 73728]
S2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\System32\wdfmgr.exe [2005-01-28 38912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-14 182768]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2010-02-23 79360]
-----------------EOF-----------------
Díky.
Logfile of random's system information tool 1.06 (written by random/random)
Run by MJ at 2010-03-28 10:51:36
Systém Microsoft Windows XP Professional Service Pack 1
System drive C: has 29 GB (77%) free of 38 GB
Total RAM: 1014 MB (79% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:51:44, on 28.3.2010
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\MJ\Plocha\RSIT.exe
C:\Program Files\trend micro\MJ.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\msupdt.exe,
O1 - Hosts: 1.2.3.4 13iii.com
O1 - Hosts: 1.2.3.4 2-spyware.com
O1 - Hosts: 1.2.3.4 247fixes.com
O1 - Hosts: 1.2.3.4 360.cn
O1 - Hosts: 1.2.3.4 360.com
O1 - Hosts: 1.2.3.4 360safe.cn
O1 - Hosts: 1.2.3.4 360safe.com
O1 - Hosts: 1.2.3.4 4-gsmteam.com
O1 - Hosts: 1.2.3.4 51nb.com
O1 - Hosts: 1.2.3.4 Merijn.org
O1 - Hosts: 1.2.3.4 abgenis.net
O1 - Hosts: 1.2.3.4 acs.pandasoftware.com
O1 - Hosts: 1.2.3.4 acs.pandasoftware.com
O1 - Hosts: 1.2.3.4 ad-aware-se.uptodown.com
O1 - Hosts: 1.2.3.4 ad13.geekstogo.com
O1 - Hosts: 1.2.3.4 aknow.prevx.com
O1 - Hosts: 1.2.3.4 alabamawomen.org
O1 - Hosts: 1.2.3.4 alerta-antivirus.inteco.es
O1 - Hosts: 1.2.3.4 alerta-antivirus.inteco.es
O1 - Hosts: 1.2.3.4 alerta-antivirus.red.es
O1 - Hosts: 1.2.3.4 alfrasha.maktoob.com
O1 - Hosts: 1.2.3.4 analysis.seclab.tuwien.ac.at
O1 - Hosts: 1.2.3.4 andymanchesta.com
O1 - Hosts: 1.2.3.4 andymanchesta.com
O1 - Hosts: 1.2.3.4 angui123.cn
O1 - Hosts: 1.2.3.4 anti-virus-softwarereview.
O1 - Hosts: 1.2.3.4 toptenreviews.com
O1 - Hosts: 1.2.3.4 antirootkit.com
O1 - Hosts: 1.2.3.4 antitrick.com
O1 - Hosts: 1.2.3.4 antivir.es
O1 - Hosts: 1.2.3.4 antivirus.about.com
O1 - Hosts: 1.2.3.4 antivirus.comodo.com
O1 - Hosts: 1.2.3.4 ar.answers.yahoo.com
O1 - Hosts: 1.2.3.4 arenajunkies.com
O1 - Hosts: 1.2.3.4 ariefew.com
O1 - Hosts: 1.2.3.4 arswp.com
O1 - Hosts: 1.2.3.4 askmehelpdesk.com
O1 - Hosts: 1.2.3.4 atazita.blogspot.com
O1 - Hosts: 1.2.3.4 auditmypc.com
O1 - Hosts: 1.2.3.4 avast-home.uptodown.com
O1 - Hosts: 1.2.3.4 avast.com
O1 - Hosts: 1.2.3.4 avg-antivirus.net
O1 - Hosts: 1.2.3.4 avast.com
O1 - Hosts: 1.2.3.4 avg-antivirus.net
O1 - Hosts: 1.2.3.4 avg.vo.llnwd.net
O1 - Hosts: 1.2.3.4 avira.com
O1 - Hosts: 1.2.3.4 avp.com
O1 - Hosts: 1.2.3.4 avpclub.ddns.info
O1 - Hosts: 1.2.3.4 avsoft.ru
O1 - Hosts: 1.2.3.4 babooforum.com.br
O1 - Hosts: 1.2.3.4 baike.360.cn
O1 - Hosts: 1.2.3.4 baike.360.com
O1 - Hosts: 1.2.3.4 bakunos.com
O1 - Hosts: 1.2.3.4 bb1.th3kings.net
O1 - Hosts: 1.2.3.4 bbs.360safe.cn
O1 - Hosts: 1.2.3.4 bbs.360safe.cn
O1 - Hosts: 1.2.3.4 bbs.360safe.com
O1 - Hosts: 1.2.3.4 bbs.360safe.com
O1 - Hosts: 1.2.3.4 bbs.cfan.com.cn
O1 - Hosts: 1.2.3.4 bbs.duba.net
O1 - Hosts: 1.2.3.4 bbs.ikaka.com
O1 - Hosts: 1.2.3.4 bbs.kafan.cn
O1 - Hosts: 1.2.3.4 bbs.kafan.com
O1 - Hosts: 1.2.3.4 bbs.kaspersky.com.cn
O1 - Hosts: 1.2.3.4 bbs.kpfans.com
O1 - Hosts: 1.2.3.4 bbs.s-sos.net
O1 - Hosts: 1.2.3.4 bbs.taisha.org
O1 - Hosts: 1.2.3.4 bbs.winzheng.com
O1 - Hosts: 1.2.3.4 beniono.wordpress.com
O1 - Hosts: 1.2.3.4 beta.eset.com
O1 - Hosts: 1.2.3.4 betterantivirus.com
O1 - Hosts: 1.2.3.4 bitdefender.com
O1 - Hosts: 1.2.3.4 bitdefender.es
O1 - Hosts: 1.2.3.4 bleedingthreats.net
O1 - Hosts: 1.2.3.4 bleepingcomputer.com
O1 - Hosts: 1.2.3.4 blindedbytech.com
O1 - Hosts: 1.2.3.4 blog.hispasec.com
O1 - Hosts: 1.2.3.4 blog.rnsafe.com
O1 - Hosts: 1.2.3.4 blog.threatfire.com
O1 - Hosts: 1.2.3.4 blogs.icerocket.com
O1 - Hosts: 1.2.3.4 blogschapines.com
O1 - Hosts: 1.2.3.4 blokvesti.net
O1 - Hosts: 1.2.3.4 board.softpedia.com
O1 - Hosts: 1.2.3.4 blokvesti.net
O1 - Hosts: 1.2.3.4 board.softpedia.com
O1 - Hosts: 1.2.3.4 boardreader.com
O1 - Hosts: 1.2.3.4 box.net
O1 - Hosts: 1.2.3.4 bub.th3kings.net
O1 - Hosts: 1.2.3.4 ca.com
O1 - Hosts: 1.2.3.4 cairopt.net
O1 - Hosts: 1.2.3.4 cairopt.net
O1 - Hosts: 1.2.3.4 castlecops.com
O1 - Hosts: 1.2.3.4 castlecrops.com
O1 - Hosts: 1.2.3.4 cddchiangmai.net
O1 - Hosts: 1.2.3.4 cddchiangmai.net
O1 - Hosts: 1.2.3.4 cert.inteco.es
O1 - Hosts: 1.2.3.4 cfan.com.cn
O1 - Hosts: 1.2.3.4 changedetection.com
O1 - Hosts: 1.2.3.4 changelog.fr
O1 - Hosts: 1.2.3.4 chkrootkit.org
O1 - Hosts: 1.2.3.4 cisrt.org
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [syncman] c:\windows\system32\wuaucldt.exe
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [syncman] c:\documents and settings\mj\wuaucldt.exe
O4 - HKCU\..\Run: [cleansweep.exe] C:\cleansweep.exe\cleansweep.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O15 - Trusted Zone: http://asia.msi.com.tw
O15 - Trusted Zone: http://global.msi.com.tw
O15 - Trusted Zone: http://www.msi.com.tw
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0800136140
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/L ... nstall.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: LGootkitSSO - {93D17AF7-7ECC-4086-95A8-8C983F3051AF} - (no file)
O21 - SSODL: GootkitSSO - {BAEA9C10-EA4D-44AB-84E4-95F9ABD95AB6} - (no file)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Služba Google Update (gupdate1ca8f788138d1b4) (gupdate1ca8f788138d1b4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
--
End of file - 9147 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Gqhbg.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-01-30 279664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-01-30 812528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E718888-423F-11D2-876E-00A0C9082467} - &Rádio - C:\WINDOWS\System32\msdxm.ocx [2002-09-20 844828]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-01-30 279664]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2009-12-10 18789920]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-12-28 417792]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"RemoteControl"=C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe [2004-11-02 32768]
"InCD"=C:\Program Files\Ahead\InCD\InCD.exe [2005-07-08 1397760]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"syncman"=c:\windows\system32\wuaucldt.exe [2010-03-24 29475]
"Regedit32"=C:\WINDOWS\system32\regedit.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-12-14 39408]
"syncman"=c:\documents and settings\mj\wuaucldt.exe [2010-03-24 29475]
"cleansweep.exe"=C:\cleansweep.exe\cleansweep.exe [2002-09-20 89088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
LGootkitSSO - {93D17AF7-7ECC-4086-95A8-8C983F3051AF}
GootkitSSO - {BAEA9C10-EA4D-44AB-84E4-95F9ABD95AB6}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2010-03-28 10:46:59 ----A---- C:\WINDOWS\ntbtlog.txt
2010-03-24 20:08:46 ----A---- C:\WINDOWS\System32\sblog.txt
2010-03-24 20:08:30 ----A---- C:\WINDOWS\System32\wuaucldt.exe
2010-03-10 20:11:28 ----A---- C:\WINDOWS\NeroDigital.ini
2010-03-10 20:11:24 ----D---- C:\Documents and Settings\MJ\Data aplikací\CyberLink
2010-03-10 20:10:25 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\CyberLink
2010-03-10 20:06:02 ----D---- C:\Program Files\Common Files\LightScribe
2010-03-10 20:04:47 ----N---- C:\WINDOWS\System32\TwnLib4.dll
2010-03-10 20:04:47 ----A---- C:\WINDOWS\System32\TwnLib20.dll
2010-03-10 20:04:44 ----N---- C:\WINDOWS\System32\ImagXRA7.dll
2010-03-10 20:04:44 ----N---- C:\WINDOWS\System32\ImagXR7.dll
2010-03-10 20:04:43 ----N---- C:\WINDOWS\System32\ImagXpr7.dll
2010-03-10 20:04:43 ----N---- C:\WINDOWS\System32\ImagX7.dll
2010-03-10 20:04:42 ----A---- C:\WINDOWS\System32\NeroCheck.exe
2010-03-10 20:04:10 ----N---- C:\WINDOWS\NuNinst.exe
2010-03-10 20:04:07 ----D---- C:\Program Files\Common Files\Ahead
2010-03-10 20:04:04 ----D---- C:\WINDOWS\InCD
2010-03-10 20:04:04 ----D---- C:\Program Files\Ahead
2010-03-10 20:02:14 ----D---- C:\Program Files\CyberLink
2010-03-10 20:01:58 ----D---- C:\MyWorks
2010-03-10 20:01:48 ----A---- C:\Program Files\Uninstall_CDS.exe
2010-03-10 20:01:47 ----D---- C:\Program Files\CyberLink DVD Solution
2010-03-02 21:36:40 ----D---- C:\Program Files\GRETECH
======List of files/folders modified in the last 1 months======
2010-03-28 10:51:38 ----D---- C:\Program Files\trend micro
2010-03-28 10:46:59 ----D---- C:\WINDOWS
2010-03-28 10:46:07 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-28 10:45:12 ----D---- C:\Documents and Settings\MJ\Data aplikací\Skype
2010-03-28 10:29:42 ----D---- C:\WINDOWS\temp
2010-03-28 10:28:43 ----D---- C:\WINDOWS\system32
2010-03-28 10:28:43 ----A---- C:\WINDOWS\System32\PerfStringBackup.INI
2010-03-28 10:28:34 ----D---- C:\Documents and Settings\MJ\Data aplikací\skypePM
2010-03-28 10:28:27 ----D---- C:\WINDOWS\System32\CatRoot2
2010-03-28 10:28:20 ----D---- C:\WINDOWS\Prefetch
2010-03-28 10:27:04 ----D---- C:\WINDOWS\Debug
2010-03-25 00:16:21 ----D---- C:\WINDOWS\Minidump
2010-03-24 20:08:38 ----D---- C:\cleansweep.exe
2010-03-24 20:08:36 ----RSHDC---- C:\WINDOWS\System32\dllcache
2010-03-24 20:08:35 ----D---- C:\WINDOWS\System32\drivers
2010-03-18 08:15:26 ----SHD---- C:\WINDOWS\Installer
2010-03-10 20:06:02 ----D---- C:\Program Files\Common Files
2010-03-10 20:04:04 ----RD---- C:\Program Files
2010-03-10 20:03:37 ----HD---- C:\Program Files\InstallShield Installation Information
2010-03-10 20:01:02 ----D---- C:\Program Files\Common Files\InstallShield
2010-03-04 16:15:28 ----D---- C:\Program Files\Winamp
2010-03-02 23:27:21 ----D---- C:\Documents and Settings\MJ\Data aplikací\Adobe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgntdd;avgntdd; C:\WINDOWS\SYSTEM32\DRIVERS\avgntdd.sys [2009-02-13 45416]
R1 InCDPass;InCDPass; C:\WINDOWS\System32\DRIVERS\InCDPass.sys [2005-07-08 29696]
R1 incdrm;InCD Reader; C:\WINDOWS\System32\drivers\incdrm.sys [2005-07-08 28672]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtenicxp.sys [2009-06-05 142336]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2002-08-29 19328]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2002-08-29 51968]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2002-08-29 19328]
S1 avipbb;avipbb; C:\WINDOWS\System32\DRIVERS\avipbb.sys [2009-03-30 96104]
S1 ssmdrv;ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-12-10 6017568]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2002-08-29 14208]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2002-08-29 21760]
S4 InCDfs;InCD File System; C:\WINDOWS\System32\drivers\InCDfs.sys [2005-07-08 99584]
S4 IntelIde;IntelIde; C:\WINDOWS\System32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
S2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
S2 gupdate1ca8f788138d1b4;Služba Google Update (gupdate1ca8f788138d1b4); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-07 133104]
S2 InCDsrv;InCD Helper; C:\Program Files\Ahead\InCD\InCDsrv.exe [2005-07-08 871424]
S2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-02-17 73728]
S2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\System32\wdfmgr.exe [2005-01-28 38912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-14 182768]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2010-02-23 79360]
-----------------EOF-----------------