win32:rootkit-gen [rtk] + pomalý start win XP
Napsal: 10 dub 2010 16:01
Zdravím,
dnes jsem někde chytl nějaký rootkit. Avast mi zahlásil pár souborů ze složky windows/system32/drivers, které jsem hodil do karantény. Poté jsem trochu googlil a hledal i na tomto fóru a zkusil projet pc Ccleanerem. Nyní po restartu mi PC po naběhnutí do windows (naběhne komplet systém, vše vypadá ok) asi na 3-5 minut zamrzne. Tedy nic nereaguje. Můžu poklepat na ikony na ploše a spustit nějaký program, nicméně PC nereaguje. Stejně tak nereaguje na ctrl-alt-del a lišta Start je úplně neaktivní.
Po těch pár minutách ale všechno naskočí a dokonce se ozve startovací zvuk woken. Stejně tak se spustí všechny programy, které jsem se pokusil na ploše spustit. Po chvíli mi také vyskočí hláška Avastu "Byl nalezen rootkit" v souboru "J:\WINDOWS\System32\Drivers\PCIDump.sys"...
Přikládám log z pravidel tohoto fóra...
Logfile of random's system information tool 1.06 (written by random/random)
Run by Kamil at 2010-04-10 16:54:14
WIN_XP Service Pack 2
System drive J: has 14 GB (9%) free of 153 GB
Total RAM: 2046 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:54:26, on 10.4.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
J:\WINDOWS\System32\smss.exe
J:\WINDOWS\system32\winlogon.exe
J:\WINDOWS\system32\services.exe
J:\WINDOWS\system32\lsass.exe
J:\WINDOWS\system32\svchost.exe
J:\WINDOWS\System32\svchost.exe
J:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
J:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
J:\Program Files\Alwil Software\Avast4\ashServ.exe
J:\WINDOWS\Explorer.EXE
J:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
J:\Program Files\TortoiseSVN\bin\TSVNCache.exe
J:\WINDOWS\RTHDCPL.EXE
J:\Program Files\HP\HP Software Update\HPWuSchd2.exe
J:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
J:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
J:\Program Files\Common Files\Java\Java Update\jusched.exe
J:\Program Files\Ad Muncher\AdMunch.exe
J:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
J:\Program Files\DAEMON Tools Lite\daemon.exe
J:\Program Files\Logitech\SetPoint\SetPoint.exe
J:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
J:\WINDOWS\system32\spoolsv.exe
J:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
J:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
J:\WINDOWS\system32\svchost.exe
J:\Program Files\Java\jre6\bin\jqs.exe
J:\Program Files\Common Files\LightScribe\LSSrvc.exe
J:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\system32\nvsvc32.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\system32\svchost.exe
J:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
J:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
J:\Program Files\Alwil Software\Avast4\ashWebSv.exe
J:\Program Files\Mozilla Firefox\firefox.exe
J:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
J:\Program Files\Common Files\Java\Java Update\jucheck.exe
J:\Documents and Settings\Kamil\Plocha\RSIT.exe
J:\Program Files\trend micro\Kamil.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: 77.93.209.79 abhdesign.cz
O1 - Hosts: 77.93.209.79 ftp.abhdesign.cz
O1 - Hosts: 95.168.205.187 ftp.gothicz.net
O1 - Hosts: 95.168.205.187 forum.gothicz.net
O1 - Hosts: 95.168.205.187 munin.gothicz.net
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - J:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - J:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - J:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - J:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - J:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - J:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE J:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE J:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GEST] m‘|\ü
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "J:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] J:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HP Software Update] J:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avast!] J:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "J:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [NeroFilterCheck] J:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [GrooveMonitor] "J:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "J:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "J:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Ad Muncher] J:\Program Files\Ad Muncher\AdMunch.exe /bt
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] J:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "J:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] J:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] J:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-21-1547161642-492894223-839522115-1003\..\Run: [CTFMON.EXE] J:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1547161642-492894223-839522115-1003\..\Run: [DAEMON Tools Lite] "J:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] J:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] J:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://J:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Kniha klipů HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - J:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Chytrý výběr - {700259D7-1666-479a-93B1-3250410481E8} - J:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - J:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - J:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - J:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - J:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - J:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - J:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - J:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - J:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - J:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - J:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - J:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - J:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - J:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - J:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - J:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - J:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - J:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 9083 bytes
======Scheduled tasks folder======
J:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
J:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
J:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
J:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
J:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - J:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll [2007-03-02 1298024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - J:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - J:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - J:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - J:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-19 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - J:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-19 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=J:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=J:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016]
"GEST"=m‘|\ü []
"Adobe Reader Speed Launcher"=J:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"WinFastDTV"=C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [2009-01-16 90112]
"ArcSoft Connection Service"=J:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-03-18 207360]
"RTHDCPL"=J:\WINDOWS\RTHDCPL.EXE [2009-03-24 17567744]
"HP Software Update"=J:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
"avast!"=J:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]
"AdobeCS4ServiceManager"=J:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"NeroFilterCheck"=J:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2007-03-01 153136]
"GrooveMonitor"=J:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Logitech Hardware Abstraction Layer"=J:\WINDOWS\KHALMNPR.EXE [2007-01-23 101136]
"Malwarebytes Anti-Malware (reboot)"=J:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]
"SunJavaUpdateSched"=J:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"Ad Muncher"=J:\Program Files\Ad Muncher\AdMunch.exe [2010-03-06 7168]
"KernelFaultCheck"=J:\WINDOWS\system32\dumprep 0 -k []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=J:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
"WinFast Schedule"=C:\Program Files\WinFast\WFDTV\WFWIZ.exe [2009-01-12 2908160]
"AdobeBridge"= []
"DAEMON Tools Lite"=J:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
J:\Documents and Settings\All Users\Nabídka Start\Programy\Po spu±tění
Logitech SetPoint.lnk - J:\Program Files\Logitech\SetPoint\SetPoint.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=J:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"J:\wincmd\WINCMD32.EXE"="J:\wincmd\WINCMD32.EXE:*:Enabled:Windows Commander 32 bit international version, file manager replacement for Windows"
"J:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="J:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
"J:\Program Files\Mozilla Firefox\firefox.exe"="J:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"J:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="J:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"J:\Program Files\VideoLAN\VLC\vlc.exe"="J:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"J:\Program Files\Java\jre6\bin\java.exe"="J:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"J:\Program Files\Java\jdk1.6.0_17\bin\java.exe"="J:\Program Files\Java\jdk1.6.0_17\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"J:\Program Files\Java\jre6\launch4j-tmp\frd.exe"="J:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary"
"J:\Program Files\Java\jre6\bin\javaw.exe"="J:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"J:\Program Files\Skype\Plugin Manager\skypePM.exe"="J:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"J:\Program Files\Skype\Phone\Skype.exe"="J:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"J:\Program Files\Ad Muncher\AdMunch.exe"="J:\Program Files\Ad Muncher\AdMunch.exe:*:Enabled:AdMunch"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{150a6712-2357-11de-8351-001fd02554db}]
shell\AutoRun\command - L:\AUTOSTARTER.EXE
======File associations======
.txt - open - "J:\Program Files\PSPad editor\PSPad.exe" "%1"
======List of files/folders created in the last 1 months======
2010-04-10 16:54:14 ----D---- J:\rsit
2010-04-10 16:54:14 ----D---- J:\Program Files\trend micro
2010-04-10 15:42:57 ----D---- J:\Program Files\CCleaner
2010-04-10 14:35:30 ----D---- J:\WINDOWS\pss
2010-03-27 13:08:02 ----D---- J:\Program Files\WinHugs
2010-03-23 21:16:52 ----D---- J:\jason
2010-03-23 14:29:48 ----D---- J:\Program Files\Sun
2010-03-23 14:23:28 ----D---- J:\Program Files\Common Files\Java
2010-03-23 14:23:28 ----D---- J:\Documents and Settings\All Users\Data aplikací\Sun
2010-03-23 14:23:15 ----A---- J:\WINDOWS\system32\javaws.exe
2010-03-23 14:23:15 ----A---- J:\WINDOWS\system32\javaw.exe
2010-03-23 14:23:15 ----A---- J:\WINDOWS\system32\java.exe
2010-03-19 18:12:41 ----A---- J:\WINDOWS\setup.INI
2010-03-19 18:10:11 ----D---- J:\Program Files\OUP
2010-03-15 10:16:43 ----A---- J:\WINDOWS\system32\wmpns.dll
2010-03-14 14:41:33 ----D---- J:\Documents and Settings\All Users\Data aplikací\FarmFrenzy3_Arctica
2010-03-14 11:50:31 ----D---- J:\Program Files\QuickTime
2010-03-14 11:50:28 ----D---- J:\Program Files\Xilisoft
2010-03-14 11:40:29 ----D---- J:\Program Files\AVI WMV MPEG Converter
2010-03-13 12:26:23 ----D---- J:\Program Files\Vitware
======List of files/folders modified in the last 1 months======
2010-04-10 16:54:14 ----RD---- J:\Program Files
2010-04-10 16:54:13 ----D---- J:\WINDOWS\system32\CatRoot2
2010-04-10 16:54:12 ----D---- J:\WINDOWS\Temp
2010-04-10 16:53:57 ----D---- J:\WINDOWS\Prefetch
2010-04-10 16:47:26 ----SD---- J:\WINDOWS\Tasks
2010-04-10 16:46:24 ----D---- J:\WINDOWS
2010-04-10 16:18:39 ----D---- J:\WINDOWS\system32
2010-04-10 16:15:40 ----D---- J:\WINDOWS\system32\drivers
2010-04-10 16:08:01 ----D---- J:\Program Files\Mozilla Thunderbird
2010-04-10 15:48:47 ----N---- J:\WINDOWS\SchedLgU.Txt
2010-04-10 15:46:49 ----D---- J:\WINDOWS\Minidump
2010-04-10 15:46:49 ----D---- J:\WINDOWS\Debug
2010-04-10 15:41:21 ----RSHDC---- J:\WINDOWS\system32\dllcache
2010-04-10 14:52:50 ----SHD---- J:\System Volume Information
2010-04-10 14:52:50 ----D---- J:\WINDOWS\system32\Restore
2010-04-10 14:42:58 ----D---- J:\Program Files\Internet Explorer
2010-04-10 13:48:04 ----AD---- J:\Documents and Settings\All Users\Data aplikací\TEMP
2010-04-10 00:06:09 ----A---- J:\WINDOWS\winamp.ini
2010-04-09 09:26:43 ----A---- J:\WINDOWS\NeroDigital.ini
2010-04-07 22:26:11 ----A---- J:\WINDOWS\wincmd.ini
2010-04-07 18:41:49 ----AD---- J:\JDownloader 0.9.310
2010-04-07 13:54:20 ----SHD---- J:\WINDOWS\Installer
2010-04-07 13:54:19 ----HD---- J:\Config.Msi
2010-04-07 13:44:48 ----HD---- J:\WINDOWS\inf
2010-04-07 13:44:48 ----D---- J:\WINDOWS\system32\DirectX
2010-04-07 13:44:40 ----RSD---- J:\WINDOWS\assembly
2010-04-07 13:44:15 ----D---- J:\Program Files\EA Sports
2010-04-07 13:10:46 ----A---- J:\WINDOWS\wcx_ftp.ini
2010-04-06 12:27:14 ----D---- J:\Documents and Settings\Kamil\Data aplikací\OpenOffice.org2
2010-04-06 12:01:19 ----D---- J:\Documents and Settings\Kamil\Data aplikací\vlc
2010-04-05 20:02:59 ----D---- J:\Program Files\Mozilla Firefox
2010-03-28 12:44:24 ----HD---- J:\Program Files\InstallShield Installation Information
2010-03-27 11:46:08 ----RSD---- J:\WINDOWS\Fonts
2010-03-23 14:28:28 ----D---- J:\Program Files\Java
2010-03-23 14:23:28 ----D---- J:\Program Files\Common Files
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; J:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 aswSP;avast! Self Protection; J:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; J:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 intelppm;Řadič procesoru Intel; J:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-17 39936]
R1 oreans32;oreans32; \??\J:\WINDOWS\system32\drivers\oreans32.sys []
R2 adfs;adfs; J:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
R2 aswFsBlk;aswFsBlk; J:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; J:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R2 atksgt;atksgt; J:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-09-30 281760]
R2 giveio;giveio; \??\J:\WINDOWS\giveio.sys []
R2 lirsgt;lirsgt; J:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-09-30 25888]
R2 XilinxPC4Driver;XilinxPC4Driver; J:\WINDOWS\System32\drivers\xpc4drvr.sys [2009-04-02 16000]
R3 aswRdr;aswRdr; J:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 gdrv;gdrv; \??\J:\WINDOWS\gdrv.sys []
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; J:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); J:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-03-24 5056000]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; J:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2007-01-23 20496]
R3 L8042mou;SetPoint PS/2 Mouse Filter Driver; J:\WINDOWS\system32\DRIVERS\L8042mou.Sys [2007-01-23 62992]
R3 LMouKE;SetPoint Mouse Filter Driver; J:\WINDOWS\system32\DRIVERS\LMouKE.Sys [2007-01-23 78864]
R3 nv;nv; J:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; J:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-01-03 105856]
R3 usbehci;Ovladač miniportu roz±ířeného radiče hostitele Microsoft USB 2.0; J:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umo·nující USB2; J:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbstor;Ovladač velkokapacitního pamě¶ového zařízení USB; J:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; J:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 WFLR6654;WinFast DTV1800 H (XC4000); J:\WINDOWS\system32\drivers\wfeaglxt.sys [2008-12-25 433792]
R3 WinDriver6;WinDriver6; J:\WINDOWS\system32\drivers\windrvr6.sys [2009-04-02 194362]
S3 aqvbe61m;aqvbe61m; J:\WINDOWS\system32\drivers\aqvbe61m.sys []
S3 MPE;Filtr MPE BDA; J:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; J:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; J:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; J:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NIC1394;1394 Net Driver; J:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
S3 SLIP;BDA Slip De-Framer; J:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; J:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; J:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; J:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; J:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WpdUsb;WpdUsb; J:\WINDOWS\System32\Drivers\wpdusb.sys [2004-08-11 18944]
S3 WSTCODEC;Dálnopisný kodek světového standardu; J:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 IntelIde;IntelIde; J:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; J:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 aswUpdSv;avast! iAVS4 Control Service; J:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; J:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 GEST Service;GEST Service for program management.; J:\Program Files\GIGABYTE\EnergySaver\GSvr.exe [2008-05-13 80392]
R2 hpqddsvc;Slu·ba HP CUE DeviceDiscovery; J:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
R2 JavaQuickStarterService;Java Quick Starter; J:\Program Files\Java\jre6\bin\jqs.exe [2009-12-17 153376]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; J:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-02-04 1181328]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; J:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-02-26 73728]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; J:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R2 Net Driver HPZ12;Net Driver HPZ12; J:\WINDOWS\System32\svchost.exe [2004-08-17 14336]
R2 NVSvc;NVIDIA Display Driver Service; J:\WINDOWS\system32\nvsvc32.exe [2008-10-07 163908]
R2 Pml Driver HPZ12;Pml Driver HPZ12; J:\WINDOWS\System32\svchost.exe [2004-08-17 14336]
R2 UleadBurningHelper;Ulead Burning Helper; J:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-12-13 49152]
R2 UMWdf;Windows User Mode Driver Framework; J:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R3 avast! Mail Scanner;avast! Mail Scanner; J:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; J:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
R3 hpqcxs08;hpqcxs08; J:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S3 aspnet_state;ASP.NET State Service; J:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; J:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; J:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-04-07 655624]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; J:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NMIndexingService;NMIndexingService; J:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-11-15 382248]
S3 odserv;Microsoft Office Diagnostics Service; J:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; J:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------
dnes jsem někde chytl nějaký rootkit. Avast mi zahlásil pár souborů ze složky windows/system32/drivers, které jsem hodil do karantény. Poté jsem trochu googlil a hledal i na tomto fóru a zkusil projet pc Ccleanerem. Nyní po restartu mi PC po naběhnutí do windows (naběhne komplet systém, vše vypadá ok) asi na 3-5 minut zamrzne. Tedy nic nereaguje. Můžu poklepat na ikony na ploše a spustit nějaký program, nicméně PC nereaguje. Stejně tak nereaguje na ctrl-alt-del a lišta Start je úplně neaktivní.
Po těch pár minutách ale všechno naskočí a dokonce se ozve startovací zvuk woken. Stejně tak se spustí všechny programy, které jsem se pokusil na ploše spustit. Po chvíli mi také vyskočí hláška Avastu "Byl nalezen rootkit" v souboru "J:\WINDOWS\System32\Drivers\PCIDump.sys"...
Přikládám log z pravidel tohoto fóra...
Logfile of random's system information tool 1.06 (written by random/random)
Run by Kamil at 2010-04-10 16:54:14
WIN_XP Service Pack 2
System drive J: has 14 GB (9%) free of 153 GB
Total RAM: 2046 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:54:26, on 10.4.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
J:\WINDOWS\System32\smss.exe
J:\WINDOWS\system32\winlogon.exe
J:\WINDOWS\system32\services.exe
J:\WINDOWS\system32\lsass.exe
J:\WINDOWS\system32\svchost.exe
J:\WINDOWS\System32\svchost.exe
J:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
J:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
J:\Program Files\Alwil Software\Avast4\ashServ.exe
J:\WINDOWS\Explorer.EXE
J:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
J:\Program Files\TortoiseSVN\bin\TSVNCache.exe
J:\WINDOWS\RTHDCPL.EXE
J:\Program Files\HP\HP Software Update\HPWuSchd2.exe
J:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
J:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
J:\Program Files\Common Files\Java\Java Update\jusched.exe
J:\Program Files\Ad Muncher\AdMunch.exe
J:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
J:\Program Files\DAEMON Tools Lite\daemon.exe
J:\Program Files\Logitech\SetPoint\SetPoint.exe
J:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
J:\WINDOWS\system32\spoolsv.exe
J:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
J:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
J:\WINDOWS\system32\svchost.exe
J:\Program Files\Java\jre6\bin\jqs.exe
J:\Program Files\Common Files\LightScribe\LSSrvc.exe
J:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\system32\nvsvc32.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\system32\svchost.exe
J:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
J:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
J:\Program Files\Alwil Software\Avast4\ashWebSv.exe
J:\Program Files\Mozilla Firefox\firefox.exe
J:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
J:\Program Files\Common Files\Java\Java Update\jucheck.exe
J:\Documents and Settings\Kamil\Plocha\RSIT.exe
J:\Program Files\trend micro\Kamil.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: 77.93.209.79 abhdesign.cz
O1 - Hosts: 77.93.209.79 ftp.abhdesign.cz
O1 - Hosts: 95.168.205.187 ftp.gothicz.net
O1 - Hosts: 95.168.205.187 forum.gothicz.net
O1 - Hosts: 95.168.205.187 munin.gothicz.net
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - J:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - J:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - J:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - J:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - J:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - J:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE J:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE J:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GEST] m‘|\ü
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "J:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] J:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HP Software Update] J:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avast!] J:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "J:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [NeroFilterCheck] J:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [GrooveMonitor] "J:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "J:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "J:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Ad Muncher] J:\Program Files\Ad Muncher\AdMunch.exe /bt
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] J:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "J:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] J:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] J:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-21-1547161642-492894223-839522115-1003\..\Run: [CTFMON.EXE] J:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1547161642-492894223-839522115-1003\..\Run: [DAEMON Tools Lite] "J:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] J:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] J:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://J:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Kniha klipů HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - J:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Chytrý výběr - {700259D7-1666-479a-93B1-3250410481E8} - J:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - J:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - J:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - J:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - J:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - J:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - J:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - J:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - J:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - J:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - J:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - J:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - J:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - J:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - J:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - J:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - J:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - J:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 9083 bytes
======Scheduled tasks folder======
J:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
J:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
J:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
J:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
J:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - J:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll [2007-03-02 1298024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - J:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - J:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - J:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - J:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-19 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - J:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-19 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=J:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=J:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016]
"GEST"=m‘|\ü []
"Adobe Reader Speed Launcher"=J:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"WinFastDTV"=C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [2009-01-16 90112]
"ArcSoft Connection Service"=J:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-03-18 207360]
"RTHDCPL"=J:\WINDOWS\RTHDCPL.EXE [2009-03-24 17567744]
"HP Software Update"=J:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
"avast!"=J:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]
"AdobeCS4ServiceManager"=J:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"NeroFilterCheck"=J:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2007-03-01 153136]
"GrooveMonitor"=J:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Logitech Hardware Abstraction Layer"=J:\WINDOWS\KHALMNPR.EXE [2007-01-23 101136]
"Malwarebytes Anti-Malware (reboot)"=J:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]
"SunJavaUpdateSched"=J:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"Ad Muncher"=J:\Program Files\Ad Muncher\AdMunch.exe [2010-03-06 7168]
"KernelFaultCheck"=J:\WINDOWS\system32\dumprep 0 -k []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=J:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
"WinFast Schedule"=C:\Program Files\WinFast\WFDTV\WFWIZ.exe [2009-01-12 2908160]
"AdobeBridge"= []
"DAEMON Tools Lite"=J:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
J:\Documents and Settings\All Users\Nabídka Start\Programy\Po spu±tění
Logitech SetPoint.lnk - J:\Program Files\Logitech\SetPoint\SetPoint.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=J:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"J:\wincmd\WINCMD32.EXE"="J:\wincmd\WINCMD32.EXE:*:Enabled:Windows Commander 32 bit international version, file manager replacement for Windows"
"J:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="J:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
"J:\Program Files\Mozilla Firefox\firefox.exe"="J:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"J:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="J:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"J:\Program Files\VideoLAN\VLC\vlc.exe"="J:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"J:\Program Files\Java\jre6\bin\java.exe"="J:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"J:\Program Files\Java\jdk1.6.0_17\bin\java.exe"="J:\Program Files\Java\jdk1.6.0_17\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"J:\Program Files\Java\jre6\launch4j-tmp\frd.exe"="J:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary"
"J:\Program Files\Java\jre6\bin\javaw.exe"="J:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"J:\Program Files\Skype\Plugin Manager\skypePM.exe"="J:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"J:\Program Files\Skype\Phone\Skype.exe"="J:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"J:\Program Files\Ad Muncher\AdMunch.exe"="J:\Program Files\Ad Muncher\AdMunch.exe:*:Enabled:AdMunch"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{150a6712-2357-11de-8351-001fd02554db}]
shell\AutoRun\command - L:\AUTOSTARTER.EXE
======File associations======
.txt - open - "J:\Program Files\PSPad editor\PSPad.exe" "%1"
======List of files/folders created in the last 1 months======
2010-04-10 16:54:14 ----D---- J:\rsit
2010-04-10 16:54:14 ----D---- J:\Program Files\trend micro
2010-04-10 15:42:57 ----D---- J:\Program Files\CCleaner
2010-04-10 14:35:30 ----D---- J:\WINDOWS\pss
2010-03-27 13:08:02 ----D---- J:\Program Files\WinHugs
2010-03-23 21:16:52 ----D---- J:\jason
2010-03-23 14:29:48 ----D---- J:\Program Files\Sun
2010-03-23 14:23:28 ----D---- J:\Program Files\Common Files\Java
2010-03-23 14:23:28 ----D---- J:\Documents and Settings\All Users\Data aplikací\Sun
2010-03-23 14:23:15 ----A---- J:\WINDOWS\system32\javaws.exe
2010-03-23 14:23:15 ----A---- J:\WINDOWS\system32\javaw.exe
2010-03-23 14:23:15 ----A---- J:\WINDOWS\system32\java.exe
2010-03-19 18:12:41 ----A---- J:\WINDOWS\setup.INI
2010-03-19 18:10:11 ----D---- J:\Program Files\OUP
2010-03-15 10:16:43 ----A---- J:\WINDOWS\system32\wmpns.dll
2010-03-14 14:41:33 ----D---- J:\Documents and Settings\All Users\Data aplikací\FarmFrenzy3_Arctica
2010-03-14 11:50:31 ----D---- J:\Program Files\QuickTime
2010-03-14 11:50:28 ----D---- J:\Program Files\Xilisoft
2010-03-14 11:40:29 ----D---- J:\Program Files\AVI WMV MPEG Converter
2010-03-13 12:26:23 ----D---- J:\Program Files\Vitware
======List of files/folders modified in the last 1 months======
2010-04-10 16:54:14 ----RD---- J:\Program Files
2010-04-10 16:54:13 ----D---- J:\WINDOWS\system32\CatRoot2
2010-04-10 16:54:12 ----D---- J:\WINDOWS\Temp
2010-04-10 16:53:57 ----D---- J:\WINDOWS\Prefetch
2010-04-10 16:47:26 ----SD---- J:\WINDOWS\Tasks
2010-04-10 16:46:24 ----D---- J:\WINDOWS
2010-04-10 16:18:39 ----D---- J:\WINDOWS\system32
2010-04-10 16:15:40 ----D---- J:\WINDOWS\system32\drivers
2010-04-10 16:08:01 ----D---- J:\Program Files\Mozilla Thunderbird
2010-04-10 15:48:47 ----N---- J:\WINDOWS\SchedLgU.Txt
2010-04-10 15:46:49 ----D---- J:\WINDOWS\Minidump
2010-04-10 15:46:49 ----D---- J:\WINDOWS\Debug
2010-04-10 15:41:21 ----RSHDC---- J:\WINDOWS\system32\dllcache
2010-04-10 14:52:50 ----SHD---- J:\System Volume Information
2010-04-10 14:52:50 ----D---- J:\WINDOWS\system32\Restore
2010-04-10 14:42:58 ----D---- J:\Program Files\Internet Explorer
2010-04-10 13:48:04 ----AD---- J:\Documents and Settings\All Users\Data aplikací\TEMP
2010-04-10 00:06:09 ----A---- J:\WINDOWS\winamp.ini
2010-04-09 09:26:43 ----A---- J:\WINDOWS\NeroDigital.ini
2010-04-07 22:26:11 ----A---- J:\WINDOWS\wincmd.ini
2010-04-07 18:41:49 ----AD---- J:\JDownloader 0.9.310
2010-04-07 13:54:20 ----SHD---- J:\WINDOWS\Installer
2010-04-07 13:54:19 ----HD---- J:\Config.Msi
2010-04-07 13:44:48 ----HD---- J:\WINDOWS\inf
2010-04-07 13:44:48 ----D---- J:\WINDOWS\system32\DirectX
2010-04-07 13:44:40 ----RSD---- J:\WINDOWS\assembly
2010-04-07 13:44:15 ----D---- J:\Program Files\EA Sports
2010-04-07 13:10:46 ----A---- J:\WINDOWS\wcx_ftp.ini
2010-04-06 12:27:14 ----D---- J:\Documents and Settings\Kamil\Data aplikací\OpenOffice.org2
2010-04-06 12:01:19 ----D---- J:\Documents and Settings\Kamil\Data aplikací\vlc
2010-04-05 20:02:59 ----D---- J:\Program Files\Mozilla Firefox
2010-03-28 12:44:24 ----HD---- J:\Program Files\InstallShield Installation Information
2010-03-27 11:46:08 ----RSD---- J:\WINDOWS\Fonts
2010-03-23 14:28:28 ----D---- J:\Program Files\Java
2010-03-23 14:23:28 ----D---- J:\Program Files\Common Files
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; J:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 aswSP;avast! Self Protection; J:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; J:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 intelppm;Řadič procesoru Intel; J:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-17 39936]
R1 oreans32;oreans32; \??\J:\WINDOWS\system32\drivers\oreans32.sys []
R2 adfs;adfs; J:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
R2 aswFsBlk;aswFsBlk; J:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; J:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R2 atksgt;atksgt; J:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-09-30 281760]
R2 giveio;giveio; \??\J:\WINDOWS\giveio.sys []
R2 lirsgt;lirsgt; J:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-09-30 25888]
R2 XilinxPC4Driver;XilinxPC4Driver; J:\WINDOWS\System32\drivers\xpc4drvr.sys [2009-04-02 16000]
R3 aswRdr;aswRdr; J:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 gdrv;gdrv; \??\J:\WINDOWS\gdrv.sys []
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; J:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); J:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-03-24 5056000]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; J:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2007-01-23 20496]
R3 L8042mou;SetPoint PS/2 Mouse Filter Driver; J:\WINDOWS\system32\DRIVERS\L8042mou.Sys [2007-01-23 62992]
R3 LMouKE;SetPoint Mouse Filter Driver; J:\WINDOWS\system32\DRIVERS\LMouKE.Sys [2007-01-23 78864]
R3 nv;nv; J:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; J:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-01-03 105856]
R3 usbehci;Ovladač miniportu roz±ířeného radiče hostitele Microsoft USB 2.0; J:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umo·nující USB2; J:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbstor;Ovladač velkokapacitního pamě¶ového zařízení USB; J:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; J:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 WFLR6654;WinFast DTV1800 H (XC4000); J:\WINDOWS\system32\drivers\wfeaglxt.sys [2008-12-25 433792]
R3 WinDriver6;WinDriver6; J:\WINDOWS\system32\drivers\windrvr6.sys [2009-04-02 194362]
S3 aqvbe61m;aqvbe61m; J:\WINDOWS\system32\drivers\aqvbe61m.sys []
S3 MPE;Filtr MPE BDA; J:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; J:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; J:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; J:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NIC1394;1394 Net Driver; J:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
S3 SLIP;BDA Slip De-Framer; J:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; J:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; J:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; J:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; J:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WpdUsb;WpdUsb; J:\WINDOWS\System32\Drivers\wpdusb.sys [2004-08-11 18944]
S3 WSTCODEC;Dálnopisný kodek světového standardu; J:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 IntelIde;IntelIde; J:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; J:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 aswUpdSv;avast! iAVS4 Control Service; J:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; J:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 GEST Service;GEST Service for program management.; J:\Program Files\GIGABYTE\EnergySaver\GSvr.exe [2008-05-13 80392]
R2 hpqddsvc;Slu·ba HP CUE DeviceDiscovery; J:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
R2 JavaQuickStarterService;Java Quick Starter; J:\Program Files\Java\jre6\bin\jqs.exe [2009-12-17 153376]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; J:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-02-04 1181328]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; J:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-02-26 73728]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; J:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R2 Net Driver HPZ12;Net Driver HPZ12; J:\WINDOWS\System32\svchost.exe [2004-08-17 14336]
R2 NVSvc;NVIDIA Display Driver Service; J:\WINDOWS\system32\nvsvc32.exe [2008-10-07 163908]
R2 Pml Driver HPZ12;Pml Driver HPZ12; J:\WINDOWS\System32\svchost.exe [2004-08-17 14336]
R2 UleadBurningHelper;Ulead Burning Helper; J:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-12-13 49152]
R2 UMWdf;Windows User Mode Driver Framework; J:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R3 avast! Mail Scanner;avast! Mail Scanner; J:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; J:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
R3 hpqcxs08;hpqcxs08; J:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S3 aspnet_state;ASP.NET State Service; J:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; J:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; J:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-04-07 655624]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; J:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NMIndexingService;NMIndexingService; J:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-11-15 382248]
S3 odserv;Microsoft Office Diagnostics Service; J:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; J:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------