Kontrola logu
Napsal: 07 dub 2010 15:59
Prosim o kontolu logu. pocitac je spomaleny.
Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2010-04-07 16:56:41
Microsoft Windows XP Professional Service Pack 3
System drive I: has 28 GB (28%) free of 100 GB
Total RAM: 2046 MB (77% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:56:55, on 7. 4. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\nvsvc32.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\spoolsv.exe
I:\WINDOWS\Explorer.EXE
I:\WINDOWS\RTHDCPL.EXE
I:\Program Files\Common Files\Java\Java Update\jusched.exe
I:\Program Files\DAEMON Tools Lite\DTLite.exe
I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
I:\Program Files\Skype\Phone\Skype.exe
I:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
I:\Program Files\Java\jre6\bin\jqs.exe
I:\WINDOWS\runservice.exe
I:\WINDOWS\system32\PnkBstrA.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\wscntfy.exe
I:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
I:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
I:\Program Files\Skype\Plugin Manager\skypePM.exe
I:\Program Files\Opera\opera.exe
I:\WINDOWS\system32\PnkBstrB.exe
I:\Documents and Settings\Administrator\Desktop\RSIT.exe
I:\Program Files\trend micro\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - I:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - I:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - I:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - I:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - I:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - I:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] I:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] I:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE I:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE I:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "I:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "I:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] I:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "I:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "I:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [swg] "I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Skype] "I:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "I:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [EA Core] I:\Program Files\Electronic Arts\EADM\Core.exe -silent
O4 - HKCU\..\RunOnce: [WiseStubReboot] MSIEXEC /quiet SKIP_PPU_DRIVER_INSTALL=1 /I "I:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MSI" TRANSFORMS="I:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MST" WISE_SETUP_EXE_PATH="i:\nvidia\displaydriver\195.62\winxp\english\PhysX_9.09.0814_SystemSoftware.exe"
O4 - HKUS\S-1-5-21-1659004503-796845957-725345543-1004\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'postgrespass')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Google Sidewiki... - res://I:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - I:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - I:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - I:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - I:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - I:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - I:\WINDOWS\runservice.exe
O23 - Service: NBService - Nero AG - I:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - I:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - I:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - I:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - I:\Program Files\EA Games\Need for Speed Undercover\PB\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - I:\WINDOWS\system32\PnkBstrB.exe
--
End of file - 7102 bytes
======Scheduled tasks folder======
I:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
I:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - I:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-17 279664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - I:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-02-17 812528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - I:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-05 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - I:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-04-05 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - I:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-11-24 953800]
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - I:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-17 279664]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=I:\WINDOWS\RTHDCPL.EXE [2007-08-11 16384000]
"JMB36X IDE Setup"=I:\WINDOWS\RaidTool\xInsIDE.exe [2007-03-20 36864]
"36X Raid Configurer"=I:\WINDOWS\system32\xRaidSetup.exe [2007-05-25 1957888]
"NvMediaCenter"=I:\WINDOWS\system32\NvMcTray.dll [2009-11-20 110184]
"NvCplDaemon"=I:\WINDOWS\system32\NvCpl.dll [2009-11-20 12669544]
"Adobe Reader Speed Launcher"=I:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=I:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"NeroFilterCheck"=I:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"SunJavaUpdateSched"=I:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=I:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"swg"=I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-01-15 39408]
"Skype"=I:\Program Files\Skype\Phone\Skype.exe [2010-02-22 26101032]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=I:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"EA Core"=I:\Program Files\Electronic Arts\EADM\Core.exe [2008-07-22 2772992]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WiseStubReboot"=MSIEXEC /quiet SKIP_PPU_DRIVER_INSTALL=1 /I I:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MSI TRANSFORMS=I:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MST WISE_SETUP_EXE_PATH=i:\nvidia\displaydriver\195.62\winxp\english\PhysX_9.09.0814_SystemSoftware.exe []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
I:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"I:\Program Files\Skype\Plugin Manager\skypePM.exe"="I:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"I:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="I:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"I:\Program Files\Opera\opera.exe"="I:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"I:\Program Files\EA GAMES\Battlefield 2\BF2.exe"="I:\Program Files\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2"
"I:\Documents and Settings\Administrator\temp\TeamViewer\Version5\TeamViewer.exe"="I:\Documents and Settings\Administrator\temp\TeamViewer\Version5\TeamViewer.exe:*:Enabled:TeamViewer"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"I:\Program Files\Skype\Phone\Skype.exe"="I:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0238e934-f603-11de-b332-806d6172696f}]
shell\AutoRun\command - D:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a813a381-244e-11df-b340-0015588aac05}]
shell\AutoRun\command - C:\s1.exe
shell\open\command - C:\s1.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{acb7c6ef-002e-11df-b339-0015588aac05}]
shell\AutoRun\command - C:\s1.exe
shell\open\command - C:\s1.exe
======List of files/folders created in the last 1 months======
2010-04-07 14:57:50 ----RHD---- I:\Documents and Settings\Administrator\Application Data\SecuROM
2010-04-07 14:53:10 ----D---- I:\Documents and Settings\Administrator\Application Data\Leadertech
2010-04-07 14:33:18 ----D---- I:\WINDOWS\LastGood
2010-04-06 04:35:55 ----SHD---- I:\found.000
2010-04-05 14:43:32 ----D---- I:\Program Files\QuickTime
2010-04-05 14:43:16 ----D---- I:\Program Files\Common Files\TechSmith Shared
2010-04-05 14:43:15 ----D---- I:\Program Files\TechSmith
2010-04-05 08:56:57 ----D---- I:\WINDOWS\Sun
2010-04-05 08:56:13 ----D---- I:\Program Files\Common Files\Java
2010-04-05 08:56:01 ----A---- I:\WINDOWS\system32\javaws.exe
2010-04-05 08:56:01 ----A---- I:\WINDOWS\system32\javaw.exe
2010-04-05 08:56:01 ----A---- I:\WINDOWS\system32\java.exe
2010-04-05 08:55:50 ----D---- I:\Program Files\Java
2010-04-05 08:49:48 ----D---- I:\Documents and Settings\All Users\Application Data\Sun
2010-04-05 08:49:33 ----A---- I:\WINDOWS\system32\deploytk.dll
2010-04-05 08:48:27 ----D---- I:\Documents and Settings\Administrator\Application Data\Sun
2010-04-03 09:57:58 ----A---- I:\WINDOWS\_MSRSTRT.EXE
2010-04-03 08:52:51 ----D---- I:\Program Files\STDU Viewer
2010-04-03 08:52:51 ----D---- I:\Program Files\Common Files\STDUtility
2010-04-03 08:52:51 ----A---- I:\WINDOWS\system32\msvcr71.dll
2010-04-03 08:32:38 ----D---- I:\Documents and Settings\Administrator\Application Data\UDC Profiles
2010-04-03 08:32:09 ----A---- I:\WINDOWS\system32\udcpm.dll
2010-04-03 08:32:03 ----D---- I:\Program Files\Universal Document Converter
2010-03-31 19:24:06 ----D---- I:\Documents and Settings\All Users\Application Data\TechSmith
2010-03-31 18:32:23 ----D---- I:\Documents and Settings\Administrator\Application Data\Ahead
2010-03-31 18:32:04 ----D---- I:\Documents and Settings\All Users\Application Data\Ahead
2010-03-31 18:30:26 ----D---- I:\Program Files\Common Files\Ahead
2010-03-31 18:29:47 ----D---- I:\WINDOWS\RegisteredPackages
2010-03-31 16:34:22 ----D---- I:\Program Files\WM Converter
2010-03-31 14:31:16 ----A---- I:\WINDOWS\IE4 Error Log.txt
2010-03-25 21:50:39 ----A---- I:\WINDOWS\system32\tsccvid.dll
2010-03-25 21:50:38 ----D---- I:\WINDOWS\system32\QuickTime
2010-03-25 21:49:25 ----D---- I:\Program Files\TechSmith_Camtasia_Studio_6.0.3
2010-03-22 19:12:04 ----A---- I:\WINDOWS\system32\ptpusb.dll
2010-03-22 19:12:03 ----A---- I:\WINDOWS\system32\ptpusd.dll
2010-03-21 22:01:43 ----D---- I:\Program Files\Guitar Pro 5
2010-03-18 16:38:56 ----D---- I:\Program Files\Ubisoft
2010-03-13 10:21:42 ----D---- I:\rsit
2010-03-13 10:21:42 ----D---- I:\Program Files\trend micro
2010-03-10 20:14:47 ----A---- I:\WINDOWS\system32\systeminfo3.dll
2010-03-10 20:14:31 ----D---- I:\Documents and Settings\Administrator\Application Data\Vso
2010-03-10 20:14:31 ----A---- I:\Documents and Settings\Administrator\Application Data\inst.exe
2010-03-10 20:14:25 ----D---- I:\Program Files\CloneDVD5
2010-03-10 20:14:25 ----D---- I:\Documents and Settings\All Users\Application Data\DVDXStudio
2010-03-10 12:18:26 ----SHD---- I:\RECYCLER
2010-03-10 09:59:13 ----D---- I:\Documents and Settings\Administrator\Application Data\Skype
2010-03-10 09:59:09 ----D---- I:\Program Files\Common Files\Skype
2010-03-10 09:59:07 ----RD---- I:\Program Files\Skype
2010-03-09 08:40:09 ----D---- I:\WINDOWS\temp
2010-03-09 08:40:08 ----A---- I:\ComboFix.txt
2010-03-09 08:36:16 ----A---- I:\Boot.bak
2010-03-09 08:36:14 ----RASHD---- I:\cmdcons
2010-03-09 08:28:09 ----A---- I:\WINDOWS\zip.exe
2010-03-09 08:28:09 ----A---- I:\WINDOWS\SWXCACLS.exe
2010-03-09 08:28:09 ----A---- I:\WINDOWS\SWSC.exe
2010-03-09 08:28:09 ----A---- I:\WINDOWS\SWREG.exe
2010-03-09 08:28:09 ----A---- I:\WINDOWS\sed.exe
2010-03-09 08:28:09 ----A---- I:\WINDOWS\PEV.exe
2010-03-09 08:28:09 ----A---- I:\WINDOWS\NIRCMD.exe
2010-03-09 08:28:09 ----A---- I:\WINDOWS\MBR.exe
2010-03-09 08:28:09 ----A---- I:\WINDOWS\grep.exe
2010-03-09 08:27:57 ----D---- I:\WINDOWS\ERDNT
2010-03-09 08:25:39 ----D---- I:\ComboFix
2010-03-09 08:25:35 ----AD---- I:\Qoobox
======List of files/folders modified in the last 1 months======
2010-04-07 16:56:49 ----D---- I:\WINDOWS\Prefetch
2010-04-07 14:58:11 ----A---- I:\WINDOWS\system32\PnkBstrB.exe
2010-04-07 14:57:32 ----SHD---- I:\WINDOWS\Installer
2010-04-07 14:57:30 ----D---- I:\Program Files\Electronic Arts
2010-04-07 14:53:30 ----D---- I:\WINDOWS\system32
2010-04-07 14:33:42 ----D---- I:\Program Files\EA GAMES
2010-04-07 14:33:40 ----HD---- I:\WINDOWS\inf
2010-04-07 14:33:26 ----RSD---- I:\WINDOWS\assembly
2010-04-07 14:33:18 ----D---- I:\WINDOWS
2010-04-07 14:32:58 ----D---- I:\WINDOWS\system32\DirectX
2010-04-07 12:09:36 ----D---- I:\Program Files\PokerStars
2010-04-07 05:34:28 ----D---- I:\Documents and Settings\Administrator\Application Data\vlc
2010-04-07 04:33:53 ----A---- I:\WINDOWS\NeroDigital.ini
2010-04-06 12:33:59 ----RSHDC---- I:\WINDOWS\system32\dllcache
2010-04-06 12:33:53 ----D---- I:\WINDOWS\system32\drivers
2010-04-06 12:33:50 ----D---- I:\WINDOWS\system32\CatRoot2
2010-04-06 04:52:00 ----A---- I:\WINDOWS\SchedLgU.Txt
2010-04-06 04:37:51 ----D---- I:\Documents and Settings\Administrator\Application Data\skypePM
2010-04-05 14:43:32 ----RD---- I:\Program Files
2010-04-05 14:43:16 ----D---- I:\Program Files\Common Files
2010-04-05 14:41:34 ----D---- I:\Program Files\Instal
2010-04-03 10:01:19 ----A---- I:\WINDOWS\system32\PerfStringBackup.INI
2010-04-03 09:59:46 ----D---- I:\Program Files\FlashGet
2010-04-03 09:58:35 ----D---- I:\WINDOWS\security
2010-03-31 18:33:05 ----D---- I:\WINDOWS\WinSxS
2010-03-31 18:30:26 ----D---- I:\Program Files\Nero
2010-03-31 18:30:26 ----D---- I:\Documents and Settings\All Users\Application Data\Nero
2010-03-31 18:30:11 ----D---- I:\Program Files\Windows Media Player
2010-03-31 18:30:10 ----D---- I:\WINDOWS\Debug
2010-03-27 13:30:39 ----D---- I:\Program Files\Full Tilt Poker
2010-03-25 22:37:15 ----SD---- I:\WINDOWS\Downloaded Program Files
2010-03-21 22:45:09 ----D---- I:\Documents and Settings\Administrator\Application Data\dvdcss
2010-03-21 22:03:06 ----RSD---- I:\WINDOWS\Fonts
2010-03-18 16:39:04 ----HD---- I:\Program Files\InstallShield Installation Information
2010-03-10 09:59:07 ----D---- I:\Documents and Settings\All Users\Application Data\Skype
2010-03-09 08:39:31 ----A---- I:\WINDOWS\system.ini
2010-03-09 08:38:11 ----D---- I:\WINDOWS\AppPatch
2010-03-09 08:36:16 ----RASH---- I:\boot.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Intel Processor Driver; I:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R2 irda;IrDA Protocol; I:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-13 88192]
R3 Arp1394;1394 ARP Client Protocol; I:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; I:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; I:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); I:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-08-10 4603904]
R3 irsir;Microsoft Serial Infrared Driver; I:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 mouhid;Mouse HID Driver; I:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NIC1394;1394 Net Driver; I:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; I:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-11-21 10235968]
R3 pcouffin;VSO Software pcouffin; I:\WINDOWS\System32\Drivers\pcouffin.sys [2010-03-10 47360]
R3 PnkBstrK;PnkBstrK; \??\I:\WINDOWS\system32\drivers\PnkBstrK.sys []
R3 Rasirda;WAN Miniport (IrDA); I:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; I:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; I:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbstor;USB Mass Storage Driver; I:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; I:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; I:\WINDOWS\system32\DRIVERS\yk51x86.sys [2010-03-03 297344]
S3 aycx31fw;aycx31fw; I:\WINDOWS\system32\drivers\aycx31fw.sys []
S3 catchme;catchme; \??\I:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 dot4;MS IEEE-1284.4 Driver; I:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-13 206976]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; I:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; I:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 usbccgp;Microsoft USB Generic Parent Driver; I:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbscan;USB Scanner Driver; I:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Irmon;Infrared Monitor; I:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; I:\Program Files\Java\jre6\bin\jqs.exe [2010-04-05 153376]
R2 LicCtrlService;LicCtrl Service; I:\WINDOWS\runservice.exe [2010-03-04 16384]
R2 nvsvc;NVIDIA Display Driver Service; I:\WINDOWS\system32\nvsvc32.exe [2009-11-20 154216]
R2 pgsql-8.3;PostgreSQL Database Server 8.3; I:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe [2009-03-13 65536]
R2 PnkBstrA;PunkBuster; I:\Program Files\EA Games\Need for Speed Undercover\PB\PnkBstrA.exe [2008-10-23 63040]
R2 PnkBstrB;PnkBstrB; I:\WINDOWS\system32\PnkBstrB.exe [2010-04-07 183112]
R2 UMWdf;Windows User Mode Driver Framework; I:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R3 NMIndexingService;NMIndexingService; I:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S2 gupdate;Služba Google Update (gupdate); I:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-17 135664]
S3 aspnet_state;ASP.NET State Service; I:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; I:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; I:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; I:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-01-17 182768]
S3 IDriverT;InstallDriver Table Manager; I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; I:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; I:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 odserv;Microsoft Office Diagnostics Service; I:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; I:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; I:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2010-04-07 16:56:41
Microsoft Windows XP Professional Service Pack 3
System drive I: has 28 GB (28%) free of 100 GB
Total RAM: 2046 MB (77% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:56:55, on 7. 4. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\nvsvc32.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\spoolsv.exe
I:\WINDOWS\Explorer.EXE
I:\WINDOWS\RTHDCPL.EXE
I:\Program Files\Common Files\Java\Java Update\jusched.exe
I:\Program Files\DAEMON Tools Lite\DTLite.exe
I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
I:\Program Files\Skype\Phone\Skype.exe
I:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
I:\Program Files\Java\jre6\bin\jqs.exe
I:\WINDOWS\runservice.exe
I:\WINDOWS\system32\PnkBstrA.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\wscntfy.exe
I:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
I:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
I:\Program Files\Skype\Plugin Manager\skypePM.exe
I:\Program Files\Opera\opera.exe
I:\WINDOWS\system32\PnkBstrB.exe
I:\Documents and Settings\Administrator\Desktop\RSIT.exe
I:\Program Files\trend micro\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - I:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - I:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - I:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - I:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - I:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - I:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] I:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] I:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE I:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE I:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "I:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "I:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] I:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "I:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "I:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [swg] "I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Skype] "I:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "I:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [EA Core] I:\Program Files\Electronic Arts\EADM\Core.exe -silent
O4 - HKCU\..\RunOnce: [WiseStubReboot] MSIEXEC /quiet SKIP_PPU_DRIVER_INSTALL=1 /I "I:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MSI" TRANSFORMS="I:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MST" WISE_SETUP_EXE_PATH="i:\nvidia\displaydriver\195.62\winxp\english\PhysX_9.09.0814_SystemSoftware.exe"
O4 - HKUS\S-1-5-21-1659004503-796845957-725345543-1004\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'postgrespass')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Google Sidewiki... - res://I:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - I:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - I:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - I:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - I:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - I:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - I:\WINDOWS\runservice.exe
O23 - Service: NBService - Nero AG - I:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - I:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - I:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - I:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - I:\Program Files\EA Games\Need for Speed Undercover\PB\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - I:\WINDOWS\system32\PnkBstrB.exe
--
End of file - 7102 bytes
======Scheduled tasks folder======
I:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
I:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - I:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-17 279664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - I:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-02-17 812528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - I:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-05 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - I:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-04-05 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - I:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-11-24 953800]
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - I:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-17 279664]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=I:\WINDOWS\RTHDCPL.EXE [2007-08-11 16384000]
"JMB36X IDE Setup"=I:\WINDOWS\RaidTool\xInsIDE.exe [2007-03-20 36864]
"36X Raid Configurer"=I:\WINDOWS\system32\xRaidSetup.exe [2007-05-25 1957888]
"NvMediaCenter"=I:\WINDOWS\system32\NvMcTray.dll [2009-11-20 110184]
"NvCplDaemon"=I:\WINDOWS\system32\NvCpl.dll [2009-11-20 12669544]
"Adobe Reader Speed Launcher"=I:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=I:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"NeroFilterCheck"=I:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"SunJavaUpdateSched"=I:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=I:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"swg"=I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-01-15 39408]
"Skype"=I:\Program Files\Skype\Phone\Skype.exe [2010-02-22 26101032]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=I:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"EA Core"=I:\Program Files\Electronic Arts\EADM\Core.exe [2008-07-22 2772992]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WiseStubReboot"=MSIEXEC /quiet SKIP_PPU_DRIVER_INSTALL=1 /I I:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MSI TRANSFORMS=I:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MST WISE_SETUP_EXE_PATH=i:\nvidia\displaydriver\195.62\winxp\english\PhysX_9.09.0814_SystemSoftware.exe []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
I:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"I:\Program Files\Skype\Plugin Manager\skypePM.exe"="I:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"I:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="I:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"I:\Program Files\Opera\opera.exe"="I:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"I:\Program Files\EA GAMES\Battlefield 2\BF2.exe"="I:\Program Files\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2"
"I:\Documents and Settings\Administrator\temp\TeamViewer\Version5\TeamViewer.exe"="I:\Documents and Settings\Administrator\temp\TeamViewer\Version5\TeamViewer.exe:*:Enabled:TeamViewer"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"I:\Program Files\Skype\Phone\Skype.exe"="I:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0238e934-f603-11de-b332-806d6172696f}]
shell\AutoRun\command - D:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a813a381-244e-11df-b340-0015588aac05}]
shell\AutoRun\command - C:\s1.exe
shell\open\command - C:\s1.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{acb7c6ef-002e-11df-b339-0015588aac05}]
shell\AutoRun\command - C:\s1.exe
shell\open\command - C:\s1.exe
======List of files/folders created in the last 1 months======
2010-04-07 14:57:50 ----RHD---- I:\Documents and Settings\Administrator\Application Data\SecuROM
2010-04-07 14:53:10 ----D---- I:\Documents and Settings\Administrator\Application Data\Leadertech
2010-04-07 14:33:18 ----D---- I:\WINDOWS\LastGood
2010-04-06 04:35:55 ----SHD---- I:\found.000
2010-04-05 14:43:32 ----D---- I:\Program Files\QuickTime
2010-04-05 14:43:16 ----D---- I:\Program Files\Common Files\TechSmith Shared
2010-04-05 14:43:15 ----D---- I:\Program Files\TechSmith
2010-04-05 08:56:57 ----D---- I:\WINDOWS\Sun
2010-04-05 08:56:13 ----D---- I:\Program Files\Common Files\Java
2010-04-05 08:56:01 ----A---- I:\WINDOWS\system32\javaws.exe
2010-04-05 08:56:01 ----A---- I:\WINDOWS\system32\javaw.exe
2010-04-05 08:56:01 ----A---- I:\WINDOWS\system32\java.exe
2010-04-05 08:55:50 ----D---- I:\Program Files\Java
2010-04-05 08:49:48 ----D---- I:\Documents and Settings\All Users\Application Data\Sun
2010-04-05 08:49:33 ----A---- I:\WINDOWS\system32\deploytk.dll
2010-04-05 08:48:27 ----D---- I:\Documents and Settings\Administrator\Application Data\Sun
2010-04-03 09:57:58 ----A---- I:\WINDOWS\_MSRSTRT.EXE
2010-04-03 08:52:51 ----D---- I:\Program Files\STDU Viewer
2010-04-03 08:52:51 ----D---- I:\Program Files\Common Files\STDUtility
2010-04-03 08:52:51 ----A---- I:\WINDOWS\system32\msvcr71.dll
2010-04-03 08:32:38 ----D---- I:\Documents and Settings\Administrator\Application Data\UDC Profiles
2010-04-03 08:32:09 ----A---- I:\WINDOWS\system32\udcpm.dll
2010-04-03 08:32:03 ----D---- I:\Program Files\Universal Document Converter
2010-03-31 19:24:06 ----D---- I:\Documents and Settings\All Users\Application Data\TechSmith
2010-03-31 18:32:23 ----D---- I:\Documents and Settings\Administrator\Application Data\Ahead
2010-03-31 18:32:04 ----D---- I:\Documents and Settings\All Users\Application Data\Ahead
2010-03-31 18:30:26 ----D---- I:\Program Files\Common Files\Ahead
2010-03-31 18:29:47 ----D---- I:\WINDOWS\RegisteredPackages
2010-03-31 16:34:22 ----D---- I:\Program Files\WM Converter
2010-03-31 14:31:16 ----A---- I:\WINDOWS\IE4 Error Log.txt
2010-03-25 21:50:39 ----A---- I:\WINDOWS\system32\tsccvid.dll
2010-03-25 21:50:38 ----D---- I:\WINDOWS\system32\QuickTime
2010-03-25 21:49:25 ----D---- I:\Program Files\TechSmith_Camtasia_Studio_6.0.3
2010-03-22 19:12:04 ----A---- I:\WINDOWS\system32\ptpusb.dll
2010-03-22 19:12:03 ----A---- I:\WINDOWS\system32\ptpusd.dll
2010-03-21 22:01:43 ----D---- I:\Program Files\Guitar Pro 5
2010-03-18 16:38:56 ----D---- I:\Program Files\Ubisoft
2010-03-13 10:21:42 ----D---- I:\rsit
2010-03-13 10:21:42 ----D---- I:\Program Files\trend micro
2010-03-10 20:14:47 ----A---- I:\WINDOWS\system32\systeminfo3.dll
2010-03-10 20:14:31 ----D---- I:\Documents and Settings\Administrator\Application Data\Vso
2010-03-10 20:14:31 ----A---- I:\Documents and Settings\Administrator\Application Data\inst.exe
2010-03-10 20:14:25 ----D---- I:\Program Files\CloneDVD5
2010-03-10 20:14:25 ----D---- I:\Documents and Settings\All Users\Application Data\DVDXStudio
2010-03-10 12:18:26 ----SHD---- I:\RECYCLER
2010-03-10 09:59:13 ----D---- I:\Documents and Settings\Administrator\Application Data\Skype
2010-03-10 09:59:09 ----D---- I:\Program Files\Common Files\Skype
2010-03-10 09:59:07 ----RD---- I:\Program Files\Skype
2010-03-09 08:40:09 ----D---- I:\WINDOWS\temp
2010-03-09 08:40:08 ----A---- I:\ComboFix.txt
2010-03-09 08:36:16 ----A---- I:\Boot.bak
2010-03-09 08:36:14 ----RASHD---- I:\cmdcons
2010-03-09 08:28:09 ----A---- I:\WINDOWS\zip.exe
2010-03-09 08:28:09 ----A---- I:\WINDOWS\SWXCACLS.exe
2010-03-09 08:28:09 ----A---- I:\WINDOWS\SWSC.exe
2010-03-09 08:28:09 ----A---- I:\WINDOWS\SWREG.exe
2010-03-09 08:28:09 ----A---- I:\WINDOWS\sed.exe
2010-03-09 08:28:09 ----A---- I:\WINDOWS\PEV.exe
2010-03-09 08:28:09 ----A---- I:\WINDOWS\NIRCMD.exe
2010-03-09 08:28:09 ----A---- I:\WINDOWS\MBR.exe
2010-03-09 08:28:09 ----A---- I:\WINDOWS\grep.exe
2010-03-09 08:27:57 ----D---- I:\WINDOWS\ERDNT
2010-03-09 08:25:39 ----D---- I:\ComboFix
2010-03-09 08:25:35 ----AD---- I:\Qoobox
======List of files/folders modified in the last 1 months======
2010-04-07 16:56:49 ----D---- I:\WINDOWS\Prefetch
2010-04-07 14:58:11 ----A---- I:\WINDOWS\system32\PnkBstrB.exe
2010-04-07 14:57:32 ----SHD---- I:\WINDOWS\Installer
2010-04-07 14:57:30 ----D---- I:\Program Files\Electronic Arts
2010-04-07 14:53:30 ----D---- I:\WINDOWS\system32
2010-04-07 14:33:42 ----D---- I:\Program Files\EA GAMES
2010-04-07 14:33:40 ----HD---- I:\WINDOWS\inf
2010-04-07 14:33:26 ----RSD---- I:\WINDOWS\assembly
2010-04-07 14:33:18 ----D---- I:\WINDOWS
2010-04-07 14:32:58 ----D---- I:\WINDOWS\system32\DirectX
2010-04-07 12:09:36 ----D---- I:\Program Files\PokerStars
2010-04-07 05:34:28 ----D---- I:\Documents and Settings\Administrator\Application Data\vlc
2010-04-07 04:33:53 ----A---- I:\WINDOWS\NeroDigital.ini
2010-04-06 12:33:59 ----RSHDC---- I:\WINDOWS\system32\dllcache
2010-04-06 12:33:53 ----D---- I:\WINDOWS\system32\drivers
2010-04-06 12:33:50 ----D---- I:\WINDOWS\system32\CatRoot2
2010-04-06 04:52:00 ----A---- I:\WINDOWS\SchedLgU.Txt
2010-04-06 04:37:51 ----D---- I:\Documents and Settings\Administrator\Application Data\skypePM
2010-04-05 14:43:32 ----RD---- I:\Program Files
2010-04-05 14:43:16 ----D---- I:\Program Files\Common Files
2010-04-05 14:41:34 ----D---- I:\Program Files\Instal
2010-04-03 10:01:19 ----A---- I:\WINDOWS\system32\PerfStringBackup.INI
2010-04-03 09:59:46 ----D---- I:\Program Files\FlashGet
2010-04-03 09:58:35 ----D---- I:\WINDOWS\security
2010-03-31 18:33:05 ----D---- I:\WINDOWS\WinSxS
2010-03-31 18:30:26 ----D---- I:\Program Files\Nero
2010-03-31 18:30:26 ----D---- I:\Documents and Settings\All Users\Application Data\Nero
2010-03-31 18:30:11 ----D---- I:\Program Files\Windows Media Player
2010-03-31 18:30:10 ----D---- I:\WINDOWS\Debug
2010-03-27 13:30:39 ----D---- I:\Program Files\Full Tilt Poker
2010-03-25 22:37:15 ----SD---- I:\WINDOWS\Downloaded Program Files
2010-03-21 22:45:09 ----D---- I:\Documents and Settings\Administrator\Application Data\dvdcss
2010-03-21 22:03:06 ----RSD---- I:\WINDOWS\Fonts
2010-03-18 16:39:04 ----HD---- I:\Program Files\InstallShield Installation Information
2010-03-10 09:59:07 ----D---- I:\Documents and Settings\All Users\Application Data\Skype
2010-03-09 08:39:31 ----A---- I:\WINDOWS\system.ini
2010-03-09 08:38:11 ----D---- I:\WINDOWS\AppPatch
2010-03-09 08:36:16 ----RASH---- I:\boot.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Intel Processor Driver; I:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R2 irda;IrDA Protocol; I:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-13 88192]
R3 Arp1394;1394 ARP Client Protocol; I:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; I:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; I:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); I:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-08-10 4603904]
R3 irsir;Microsoft Serial Infrared Driver; I:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 mouhid;Mouse HID Driver; I:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NIC1394;1394 Net Driver; I:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; I:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-11-21 10235968]
R3 pcouffin;VSO Software pcouffin; I:\WINDOWS\System32\Drivers\pcouffin.sys [2010-03-10 47360]
R3 PnkBstrK;PnkBstrK; \??\I:\WINDOWS\system32\drivers\PnkBstrK.sys []
R3 Rasirda;WAN Miniport (IrDA); I:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; I:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; I:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbstor;USB Mass Storage Driver; I:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; I:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; I:\WINDOWS\system32\DRIVERS\yk51x86.sys [2010-03-03 297344]
S3 aycx31fw;aycx31fw; I:\WINDOWS\system32\drivers\aycx31fw.sys []
S3 catchme;catchme; \??\I:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 dot4;MS IEEE-1284.4 Driver; I:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-13 206976]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; I:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; I:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 usbccgp;Microsoft USB Generic Parent Driver; I:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbscan;USB Scanner Driver; I:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Irmon;Infrared Monitor; I:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; I:\Program Files\Java\jre6\bin\jqs.exe [2010-04-05 153376]
R2 LicCtrlService;LicCtrl Service; I:\WINDOWS\runservice.exe [2010-03-04 16384]
R2 nvsvc;NVIDIA Display Driver Service; I:\WINDOWS\system32\nvsvc32.exe [2009-11-20 154216]
R2 pgsql-8.3;PostgreSQL Database Server 8.3; I:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe [2009-03-13 65536]
R2 PnkBstrA;PunkBuster; I:\Program Files\EA Games\Need for Speed Undercover\PB\PnkBstrA.exe [2008-10-23 63040]
R2 PnkBstrB;PnkBstrB; I:\WINDOWS\system32\PnkBstrB.exe [2010-04-07 183112]
R2 UMWdf;Windows User Mode Driver Framework; I:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R3 NMIndexingService;NMIndexingService; I:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S2 gupdate;Služba Google Update (gupdate); I:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-17 135664]
S3 aspnet_state;ASP.NET State Service; I:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; I:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; I:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; I:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-01-17 182768]
S3 IDriverT;InstallDriver Table Manager; I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; I:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; I:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 odserv;Microsoft Office Diagnostics Service; I:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; I:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; I:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------