Kontrola
Napsal: 10 dub 2010 11:36
Logfile of random's system information tool 1.06 (written by random/random)
Run by Daiw at 2010-04-10 12:35:28
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 13 GB (34%) free of 40 GB
Total RAM: 1023 MB (42% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:35:47, on 10. 4. 2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\Explorer.EXE
C:\WINDOWS\TBPanel.exe
C:\windows\system32\RUNDLL32.EXE
C:\Program Files\Eset\nod32kui.exe
C:\windows\RTHDCPL.EXE
C:\windows\system32\ctfmon.exe
C:\program files\steam\steam.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Eset\nod32krn.exe
C:\windows\system32\nvsvc32.exe
C:\Program Files\VentriloMIX\Ventrilo 2.1.4.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\TeamViewer\Version5\TeamViewer.exe
C:\Documents and Settings\Daiw\My Documents\Preberanie\RSIT.exe
C:\Documents and Settings\Daiw\My Documents\Preberanie\RSIT.exe
C:\Program Files\trend micro\Daiw.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
O2 - BHO: PHPNukeEN Toolbar - {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - C:\Program Files\PHPNukeEN\tbPHP0.dll
O3 - Toolbar: PHPNukeEN Toolbar - {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - C:\Program Files\PHPNukeEN\tbPHP0.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Gainward] C:\WINDOWS\TBPanel.exe /A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
--
End of file - 3363 bytes
======Scheduled tasks folder======
C:\windows\tasks\Ad-Aware Update (Weekly).job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}]
PHPNukeEN Toolbar - C:\Program Files\PHPNukeEN\tbPHP0.dll [2010-02-14 2349080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{dd02a4eb-4afd-4d60-99d8-e67f964ca813} - PHPNukeEN Toolbar - C:\Program Files\PHPNukeEN\tbPHP0.dll [2010-02-14 2349080]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SkyTel"=C:\windows\SkyTel.EXE [2006-05-16 2879488]
"Gainward"=C:\WINDOWS\TBPanel.exe [2007-06-26 2173480]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-07-23 8466432]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-07-23 81920]
"nod32kui"=C:\Program Files\Eset\nod32kui.exe [2005-11-15 921600]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"RTHDCPL"=C:\windows\RTHDCPL.EXE [2006-12-19 16062464]
"Alcmtr"=C:\windows\ALCMTR.EXE [2005-05-03 69632]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\windows\system32\ctfmon.exe [2007-07-27 15360]
"Steam"=c:\program files\steam\steam.exe [2010-03-24 1217872]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-03-09 26100520]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Steam\SteamApps\6daw6\counter-strike source\hl2.exe"="C:\Program Files\Steam\SteamApps\6daw6\counter-strike source\hl2.exe:*:Enabled:hl2"
"D:\Lord of the ring 2\game.dat"="D:\Lord of the ring 2\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"D:\Lord of the ring 2\patchget.dat"="D:\Lord of the ring 2\patchget.dat:*:Enabled:patchgrabber"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Steam\SteamApps\6daw6\half-life 2 deathmatch\hl2.exe"="C:\Program Files\Steam\SteamApps\6daw6\half-life 2 deathmatch\hl2.exe:*:Enabled:hl2"
"D:\Counter-Strike Source\hl2.exe"="D:\Counter-Strike Source\hl2.exe:*:Enabled:hl2"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"
"C:\Program Files\MotoRacer3\MotoRacer3.exe"="C:\Program Files\MotoRacer3\MotoRacer3.exe:*:Enabled:Moto Racer 3 PC"
"C:\Program Files\Atari\Test Drive Unlimited\TestDriveUnlimited.exe"="C:\Program Files\Atari\Test Drive Unlimited\TestDriveUnlimited.exe:*:Enabled:Test Drive Unlimited"
"C:\Program Files\EA SPORTS\NHL07\nhl2007pal.exe"="C:\Program Files\EA SPORTS\NHL07\nhl2007pal.exe:*:Enabled:nhl2007pal"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Steam\steamapps\daiw8\counter-strike source\hl2.exe"="C:\Program Files\Steam\steamapps\daiw8\counter-strike source\hl2.exe:*:Enabled:hl2"
"C:\Program Files\Steam\steamapps\common\zero gear\Server\ZeroGearServer.exe"="C:\Program Files\Steam\steamapps\common\zero gear\Server\ZeroGearServer.exe:*:Enabled:ZeroGearServer"
"C:\Program Files\EA SPORTS\FIFA 10\FIFA10.exe"="C:\Program Files\EA SPORTS\FIFA 10\FIFA10.exe:*:Enabled:FIFA10"
"C:\Program Files\Steam\steamapps\daiw8\insurgency\hl2.exe"="C:\Program Files\Steam\steamapps\daiw8\insurgency\hl2.exe:*:Enabled:hl2"
"C:\Program Files\Steam\steamapps\common\trackmania nations forever\TmForever.exe"="C:\Program Files\Steam\steamapps\common\trackmania nations forever\TmForever.exe:*:Enabled:TrackMania Nations Forever"
"C:\Program Files\Steam\steamapps\common\trackmania nations forever\TmForeverLauncher.exe"="C:\Program Files\Steam\steamapps\common\trackmania nations forever\TmForeverLauncher.exe:*:Enabled:TrackMania Nations Forever"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\TeamViewer\Version5\TeamViewer.exe"="C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-04-10 12:35:29 ----D---- C:\Program Files\trend micro
2010-04-10 12:35:28 ----D---- C:\rsit
2010-04-10 12:27:43 ----D---- C:\Documents and Settings\Daiw\Application Data\TeamViewer
2010-04-10 12:26:39 ----D---- C:\Program Files\TeamViewer
2010-04-07 15:49:55 ----A---- C:\windows\madagascar.ini
2010-04-07 15:37:35 ----D---- C:\Program Files\Activision
2010-03-27 20:48:26 ----D---- C:\Documents and Settings\Daiw\Application Data\Mumble
2010-03-27 20:47:48 ----D---- C:\Program Files\Mumble
2010-03-26 22:53:47 ----D---- C:\Documents and Settings\Daiw\Application Data\skypePM
2010-03-26 22:53:18 ----D---- C:\Documents and Settings\Daiw\Application Data\Skype
2010-03-26 22:53:07 ----D---- C:\Program Files\Common Files\Skype
2010-03-26 22:53:01 ----RD---- C:\Program Files\Skype
2010-03-25 12:22:37 ----A---- C:\windows\system32\XAudio2_6.dll
2010-03-25 12:22:37 ----A---- C:\windows\system32\XAPOFX1_4.dll
2010-03-25 12:22:36 ----A---- C:\windows\system32\xactengine3_6.dll
2010-03-25 12:22:35 ----A---- C:\windows\system32\X3DAudio1_7.dll
2010-03-25 12:21:59 ----D---- C:\Program Files\X-ray Anti-Cheat
2010-03-25 10:03:47 ----D---- C:\Documents and Settings\Daiw\Application Data\Ventrilo
2010-03-25 10:03:20 ----D---- C:\Program Files\VentriloMIX
2010-03-24 21:58:40 ----D---- C:\Documents and Settings\Daiw\Application Data\Ahead
2010-03-24 16:36:47 ----D---- C:\Program Files\Steam
2010-03-24 16:21:02 ----D---- C:\Documents and Settings\Daiw\Application Data\Macromedia
2010-03-24 16:21:02 ----D---- C:\Documents and Settings\Daiw\Application Data\Adobe
2010-03-24 16:20:17 ----D---- C:\Documents and Settings\Daiw\Application Data\Mozilla
2010-03-24 14:56:01 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2010-03-24 14:43:04 ----D---- C:\Documents and Settings\Daiw\Application Data\Identities
2010-03-24 14:42:53 ----ASH---- C:\Documents and Settings\Daiw\Application Data\desktop.ini
2010-03-24 14:42:52 ----SD---- C:\Documents and Settings\Daiw\Application Data\Microsoft
2010-03-20 13:25:52 ----D---- C:\Program Files\Hunting Unlimited 3
======List of files/folders modified in the last 1 months======
2010-04-10 12:35:29 ----RD---- C:\Program Files
2010-04-10 12:31:04 ----A---- C:\windows\DFC.INI
2010-04-10 12:30:33 ----D---- C:\Program Files\DAEMON Tools Toolbar
2010-04-10 12:30:11 ----D---- C:\windows\Prefetch
2010-04-10 11:56:09 ----D---- C:\windows\system32\CatRoot2
2010-04-10 11:42:14 ----D---- C:\windows\Temp
2010-04-10 08:45:30 ----A---- C:\windows\SchedLgU.Txt
2010-04-07 15:49:57 ----HD---- C:\Program Files\InstallShield Installation Information
2010-04-07 15:49:55 ----SHD---- C:\windows\Installer
2010-04-07 15:49:55 ----D---- C:\WINDOWS
2010-04-06 19:02:54 ----D---- C:\Program Files\Online Services
2010-04-06 12:26:34 ----A---- C:\windows\PhotoSnapViewer.INI
2010-04-06 12:06:54 ----D---- C:\Program Files\Mozilla Firefox
2010-04-02 18:07:50 ----A---- C:\windows\NeroDigital.ini
2010-03-31 16:44:26 ----HD---- C:\windows\inf
2010-03-28 07:46:20 ----D---- C:\windows\system32
2010-03-28 07:46:20 ----A---- C:\windows\system32\PerfStringBackup.INI
2010-03-26 22:53:07 ----D---- C:\Program Files\Common Files
2010-03-26 22:53:01 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2010-03-25 12:22:37 ----D---- C:\windows\system32\DirectX
2010-03-25 12:22:08 ----D---- C:\windows\WinSxS
2010-03-24 16:36:12 ----SHD---- C:\RECYCLER
2010-03-24 14:56:01 ----SD---- C:\windows\Tasks
2010-03-24 14:56:01 ----D---- C:\Program Files\Google
2010-03-24 14:51:10 ----D---- C:\Program Files\Lavasoft
2010-03-24 14:43:07 ----A---- C:\windows\OEWABLog.txt
2010-03-24 14:42:52 ----D---- C:\Documents and Settings
2010-03-14 09:53:45 ----A---- C:\windows\wininit.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\windows\System32\drivers\ws2ifsl.sys [2007-07-27 12032]
R2 AMON;AMON; \??\C:\WINDOWS\system32\drivers\amon.sys []
R2 TBPanel;TBPanel; C:\windows\system32\drivers\TBPanel.sys [2007-03-16 12256]
R3 hamachi;Hamachi Network Interface; C:\windows\system32\DRIVERS\hamachi.sys [2010-02-06 25280]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\windows\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Microsoft HID Class Driver; C:\windows\system32\DRIVERS\hidusb.sys [2007-07-27 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RtkHDAud.sys [2006-12-21 4405248]
R3 nv;nv; C:\windows\system32\DRIVERS\nv4_mini.sys [2007-07-23 6807328]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\windows\system32\DRIVERS\NVENETFD.sys [2006-07-11 57856]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\windows\system32\DRIVERS\nvnetbus.sys [2006-07-11 20480]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\windows\system32\DRIVERS\usbehci.sys [2007-07-27 26624]
R3 usbhub;USB2 Enabled Hub; C:\windows\system32\DRIVERS\usbhub.sys [2007-07-27 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\windows\system32\DRIVERS\usbohci.sys [2007-07-27 17024]
S1 kbdhid;Keyboard HID Driver; C:\windows\system32\DRIVERS\kbdhid.sys [2007-07-27 14848]
S3 ao3fksj3;ao3fksj3; C:\windows\system32\drivers\ao3fksj3.sys []
S3 Bridge;MAC Bridge; C:\windows\system32\DRIVERS\bridge.sys [2007-07-27 71552]
S3 BridgeMP;MAC Bridge Miniport; C:\windows\system32\DRIVERS\bridge.sys [2007-07-27 71552]
S3 Cardex;Cardex; \??\C:\WINDOWS\system32\drivers\TBPANEL.SYS []
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 mouhid;Mouse HID Driver; C:\windows\system32\DRIVERS\mouhid.sys [2007-07-27 12160]
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\windows\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
S3 usbprint;Microsoft USB PRINTER Class; C:\windows\system32\DRIVERS\usbprint.sys [2004-08-04 25856]
S3 USBSTOR;USB Mass Storage Driver; C:\windows\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S4 IntelIde;IntelIde; C:\windows\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 NOD32krn;NOD32 Kernel Service; C:\Program Files\Eset\nod32krn.exe [2005-11-15 495616]
R2 NVSvc;NVIDIA Display Driver Service; C:\windows\system32\nvsvc32.exe [2007-07-23 155716]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
-----------------EOF-----------------
Run by Daiw at 2010-04-10 12:35:28
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 13 GB (34%) free of 40 GB
Total RAM: 1023 MB (42% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:35:47, on 10. 4. 2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\Explorer.EXE
C:\WINDOWS\TBPanel.exe
C:\windows\system32\RUNDLL32.EXE
C:\Program Files\Eset\nod32kui.exe
C:\windows\RTHDCPL.EXE
C:\windows\system32\ctfmon.exe
C:\program files\steam\steam.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Eset\nod32krn.exe
C:\windows\system32\nvsvc32.exe
C:\Program Files\VentriloMIX\Ventrilo 2.1.4.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\TeamViewer\Version5\TeamViewer.exe
C:\Documents and Settings\Daiw\My Documents\Preberanie\RSIT.exe
C:\Documents and Settings\Daiw\My Documents\Preberanie\RSIT.exe
C:\Program Files\trend micro\Daiw.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = ${URL_SEARCHPAGE}
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
O2 - BHO: PHPNukeEN Toolbar - {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - C:\Program Files\PHPNukeEN\tbPHP0.dll
O3 - Toolbar: PHPNukeEN Toolbar - {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - C:\Program Files\PHPNukeEN\tbPHP0.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Gainward] C:\WINDOWS\TBPanel.exe /A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
--
End of file - 3363 bytes
======Scheduled tasks folder======
C:\windows\tasks\Ad-Aware Update (Weekly).job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}]
PHPNukeEN Toolbar - C:\Program Files\PHPNukeEN\tbPHP0.dll [2010-02-14 2349080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{dd02a4eb-4afd-4d60-99d8-e67f964ca813} - PHPNukeEN Toolbar - C:\Program Files\PHPNukeEN\tbPHP0.dll [2010-02-14 2349080]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SkyTel"=C:\windows\SkyTel.EXE [2006-05-16 2879488]
"Gainward"=C:\WINDOWS\TBPanel.exe [2007-06-26 2173480]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-07-23 8466432]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-07-23 81920]
"nod32kui"=C:\Program Files\Eset\nod32kui.exe [2005-11-15 921600]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"RTHDCPL"=C:\windows\RTHDCPL.EXE [2006-12-19 16062464]
"Alcmtr"=C:\windows\ALCMTR.EXE [2005-05-03 69632]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\windows\system32\ctfmon.exe [2007-07-27 15360]
"Steam"=c:\program files\steam\steam.exe [2010-03-24 1217872]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-03-09 26100520]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Steam\SteamApps\6daw6\counter-strike source\hl2.exe"="C:\Program Files\Steam\SteamApps\6daw6\counter-strike source\hl2.exe:*:Enabled:hl2"
"D:\Lord of the ring 2\game.dat"="D:\Lord of the ring 2\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"D:\Lord of the ring 2\patchget.dat"="D:\Lord of the ring 2\patchget.dat:*:Enabled:patchgrabber"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Steam\SteamApps\6daw6\half-life 2 deathmatch\hl2.exe"="C:\Program Files\Steam\SteamApps\6daw6\half-life 2 deathmatch\hl2.exe:*:Enabled:hl2"
"D:\Counter-Strike Source\hl2.exe"="D:\Counter-Strike Source\hl2.exe:*:Enabled:hl2"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"
"C:\Program Files\MotoRacer3\MotoRacer3.exe"="C:\Program Files\MotoRacer3\MotoRacer3.exe:*:Enabled:Moto Racer 3 PC"
"C:\Program Files\Atari\Test Drive Unlimited\TestDriveUnlimited.exe"="C:\Program Files\Atari\Test Drive Unlimited\TestDriveUnlimited.exe:*:Enabled:Test Drive Unlimited"
"C:\Program Files\EA SPORTS\NHL07\nhl2007pal.exe"="C:\Program Files\EA SPORTS\NHL07\nhl2007pal.exe:*:Enabled:nhl2007pal"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Steam\steamapps\daiw8\counter-strike source\hl2.exe"="C:\Program Files\Steam\steamapps\daiw8\counter-strike source\hl2.exe:*:Enabled:hl2"
"C:\Program Files\Steam\steamapps\common\zero gear\Server\ZeroGearServer.exe"="C:\Program Files\Steam\steamapps\common\zero gear\Server\ZeroGearServer.exe:*:Enabled:ZeroGearServer"
"C:\Program Files\EA SPORTS\FIFA 10\FIFA10.exe"="C:\Program Files\EA SPORTS\FIFA 10\FIFA10.exe:*:Enabled:FIFA10"
"C:\Program Files\Steam\steamapps\daiw8\insurgency\hl2.exe"="C:\Program Files\Steam\steamapps\daiw8\insurgency\hl2.exe:*:Enabled:hl2"
"C:\Program Files\Steam\steamapps\common\trackmania nations forever\TmForever.exe"="C:\Program Files\Steam\steamapps\common\trackmania nations forever\TmForever.exe:*:Enabled:TrackMania Nations Forever"
"C:\Program Files\Steam\steamapps\common\trackmania nations forever\TmForeverLauncher.exe"="C:\Program Files\Steam\steamapps\common\trackmania nations forever\TmForeverLauncher.exe:*:Enabled:TrackMania Nations Forever"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\TeamViewer\Version5\TeamViewer.exe"="C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-04-10 12:35:29 ----D---- C:\Program Files\trend micro
2010-04-10 12:35:28 ----D---- C:\rsit
2010-04-10 12:27:43 ----D---- C:\Documents and Settings\Daiw\Application Data\TeamViewer
2010-04-10 12:26:39 ----D---- C:\Program Files\TeamViewer
2010-04-07 15:49:55 ----A---- C:\windows\madagascar.ini
2010-04-07 15:37:35 ----D---- C:\Program Files\Activision
2010-03-27 20:48:26 ----D---- C:\Documents and Settings\Daiw\Application Data\Mumble
2010-03-27 20:47:48 ----D---- C:\Program Files\Mumble
2010-03-26 22:53:47 ----D---- C:\Documents and Settings\Daiw\Application Data\skypePM
2010-03-26 22:53:18 ----D---- C:\Documents and Settings\Daiw\Application Data\Skype
2010-03-26 22:53:07 ----D---- C:\Program Files\Common Files\Skype
2010-03-26 22:53:01 ----RD---- C:\Program Files\Skype
2010-03-25 12:22:37 ----A---- C:\windows\system32\XAudio2_6.dll
2010-03-25 12:22:37 ----A---- C:\windows\system32\XAPOFX1_4.dll
2010-03-25 12:22:36 ----A---- C:\windows\system32\xactengine3_6.dll
2010-03-25 12:22:35 ----A---- C:\windows\system32\X3DAudio1_7.dll
2010-03-25 12:21:59 ----D---- C:\Program Files\X-ray Anti-Cheat
2010-03-25 10:03:47 ----D---- C:\Documents and Settings\Daiw\Application Data\Ventrilo
2010-03-25 10:03:20 ----D---- C:\Program Files\VentriloMIX
2010-03-24 21:58:40 ----D---- C:\Documents and Settings\Daiw\Application Data\Ahead
2010-03-24 16:36:47 ----D---- C:\Program Files\Steam
2010-03-24 16:21:02 ----D---- C:\Documents and Settings\Daiw\Application Data\Macromedia
2010-03-24 16:21:02 ----D---- C:\Documents and Settings\Daiw\Application Data\Adobe
2010-03-24 16:20:17 ----D---- C:\Documents and Settings\Daiw\Application Data\Mozilla
2010-03-24 14:56:01 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2010-03-24 14:43:04 ----D---- C:\Documents and Settings\Daiw\Application Data\Identities
2010-03-24 14:42:53 ----ASH---- C:\Documents and Settings\Daiw\Application Data\desktop.ini
2010-03-24 14:42:52 ----SD---- C:\Documents and Settings\Daiw\Application Data\Microsoft
2010-03-20 13:25:52 ----D---- C:\Program Files\Hunting Unlimited 3
======List of files/folders modified in the last 1 months======
2010-04-10 12:35:29 ----RD---- C:\Program Files
2010-04-10 12:31:04 ----A---- C:\windows\DFC.INI
2010-04-10 12:30:33 ----D---- C:\Program Files\DAEMON Tools Toolbar
2010-04-10 12:30:11 ----D---- C:\windows\Prefetch
2010-04-10 11:56:09 ----D---- C:\windows\system32\CatRoot2
2010-04-10 11:42:14 ----D---- C:\windows\Temp
2010-04-10 08:45:30 ----A---- C:\windows\SchedLgU.Txt
2010-04-07 15:49:57 ----HD---- C:\Program Files\InstallShield Installation Information
2010-04-07 15:49:55 ----SHD---- C:\windows\Installer
2010-04-07 15:49:55 ----D---- C:\WINDOWS
2010-04-06 19:02:54 ----D---- C:\Program Files\Online Services
2010-04-06 12:26:34 ----A---- C:\windows\PhotoSnapViewer.INI
2010-04-06 12:06:54 ----D---- C:\Program Files\Mozilla Firefox
2010-04-02 18:07:50 ----A---- C:\windows\NeroDigital.ini
2010-03-31 16:44:26 ----HD---- C:\windows\inf
2010-03-28 07:46:20 ----D---- C:\windows\system32
2010-03-28 07:46:20 ----A---- C:\windows\system32\PerfStringBackup.INI
2010-03-26 22:53:07 ----D---- C:\Program Files\Common Files
2010-03-26 22:53:01 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2010-03-25 12:22:37 ----D---- C:\windows\system32\DirectX
2010-03-25 12:22:08 ----D---- C:\windows\WinSxS
2010-03-24 16:36:12 ----SHD---- C:\RECYCLER
2010-03-24 14:56:01 ----SD---- C:\windows\Tasks
2010-03-24 14:56:01 ----D---- C:\Program Files\Google
2010-03-24 14:51:10 ----D---- C:\Program Files\Lavasoft
2010-03-24 14:43:07 ----A---- C:\windows\OEWABLog.txt
2010-03-24 14:42:52 ----D---- C:\Documents and Settings
2010-03-14 09:53:45 ----A---- C:\windows\wininit.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\windows\System32\drivers\ws2ifsl.sys [2007-07-27 12032]
R2 AMON;AMON; \??\C:\WINDOWS\system32\drivers\amon.sys []
R2 TBPanel;TBPanel; C:\windows\system32\drivers\TBPanel.sys [2007-03-16 12256]
R3 hamachi;Hamachi Network Interface; C:\windows\system32\DRIVERS\hamachi.sys [2010-02-06 25280]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\windows\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Microsoft HID Class Driver; C:\windows\system32\DRIVERS\hidusb.sys [2007-07-27 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RtkHDAud.sys [2006-12-21 4405248]
R3 nv;nv; C:\windows\system32\DRIVERS\nv4_mini.sys [2007-07-23 6807328]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\windows\system32\DRIVERS\NVENETFD.sys [2006-07-11 57856]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\windows\system32\DRIVERS\nvnetbus.sys [2006-07-11 20480]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\windows\system32\DRIVERS\usbehci.sys [2007-07-27 26624]
R3 usbhub;USB2 Enabled Hub; C:\windows\system32\DRIVERS\usbhub.sys [2007-07-27 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\windows\system32\DRIVERS\usbohci.sys [2007-07-27 17024]
S1 kbdhid;Keyboard HID Driver; C:\windows\system32\DRIVERS\kbdhid.sys [2007-07-27 14848]
S3 ao3fksj3;ao3fksj3; C:\windows\system32\drivers\ao3fksj3.sys []
S3 Bridge;MAC Bridge; C:\windows\system32\DRIVERS\bridge.sys [2007-07-27 71552]
S3 BridgeMP;MAC Bridge Miniport; C:\windows\system32\DRIVERS\bridge.sys [2007-07-27 71552]
S3 Cardex;Cardex; \??\C:\WINDOWS\system32\drivers\TBPANEL.SYS []
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 mouhid;Mouse HID Driver; C:\windows\system32\DRIVERS\mouhid.sys [2007-07-27 12160]
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\windows\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
S3 usbprint;Microsoft USB PRINTER Class; C:\windows\system32\DRIVERS\usbprint.sys [2004-08-04 25856]
S3 USBSTOR;USB Mass Storage Driver; C:\windows\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S4 IntelIde;IntelIde; C:\windows\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 NOD32krn;NOD32 Kernel Service; C:\Program Files\Eset\nod32krn.exe [2005-11-15 495616]
R2 NVSvc;NVIDIA Display Driver Service; C:\windows\system32\nvsvc32.exe [2007-07-23 155716]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
-----------------EOF-----------------