prosim o kontrolu logu
Logfile of random's system information tool 1.09 (written by random/random)
Run by Thomas at 2011-10-24 19:16:55
Systém Microsoft Windows XP Professional
System drive C: has 127 GB (97%) free of 131 GB
Total RAM: 3327 MB (90% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:17:00, on 24.10.2011
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Thomas\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\Thomas.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
--
End of file - 2042 bytes
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Thomas\Data aplikací\Mozilla\Firefox\Profiles\cc9n5gay.default
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E718888-423F-11D2-876E-00A0C9082467} - &Rádio - C:\WINDOWS\System32\msdxm.ocx [2001-10-25 846364]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-09-06 3722416]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\System32\ctfmon.exe [2001-10-25 13312]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2001-08-02 1077277]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\System32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\System32\l3codeca.acm
======List of files/folders created in the last 1 month======
2011-10-24 19:16:55 ----D---- C:\rsit
2011-10-24 19:16:55 ----D---- C:\Program Files\trend micro
2011-10-24 18:57:47 ----ASH---- C:\pagefile.sys
2011-10-24 17:42:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\ParetoLogic
2011-10-24 16:40:20 ----A---- C:\WINDOWS\System32\drivers\usbprint.sys
2011-10-24 16:10:00 ----SHD---- C:\WINDOWS\CSC
2011-10-24 16:09:56 ----A---- C:\WINDOWS\ntbtlog.txt
2011-10-24 15:24:26 ----A---- C:\WINDOWS\System32\drivers\aswSP.sys
2011-10-24 15:24:25 ----A---- C:\WINDOWS\System32\drivers\aswTdi.sys
2011-10-24 15:24:25 ----A---- C:\WINDOWS\System32\drivers\aswRdr.sys
2011-10-24 15:24:25 ----A---- C:\WINDOWS\System32\drivers\aswmon2.sys
2011-10-24 15:24:25 ----A---- C:\WINDOWS\System32\drivers\aswmon.sys
2011-10-24 15:24:24 ----A---- C:\WINDOWS\System32\drivers\aavmker4.sys
2011-10-24 15:24:13 ----A---- C:\WINDOWS\System32\aswBoot.exe
2011-10-24 15:24:13 ----A---- C:\WINDOWS\avastSS.scr
2011-10-24 15:23:58 ----SHD---- C:\RECYCLER
2011-10-24 15:20:31 ----D---- C:\Program Files\CCleaner
2011-10-24 15:19:26 ----D---- C:\Documents and Settings\Thomas\Data aplikací\Mozilla
2011-10-24 15:19:19 ----D---- C:\Program Files\Mozilla Firefox
2011-10-24 15:12:05 ----RA---- C:\WINDOWS\System32\RtNicProp32.dll
2011-10-24 15:12:05 ----RA---- C:\WINDOWS\System32\drivers\Rtenicxp.sys
2011-10-24 15:12:05 ----D---- C:\WINDOWS\LastGood
2011-10-23 19:32:38 ----A---- C:\WINDOWS\System32\h323log.txt
2011-10-23 19:28:50 ----A---- C:\WINDOWS\System32\drivers\audstub.sys
2011-10-23 19:28:38 ----A---- C:\WINDOWS\System32\hidserv.dll
2011-10-23 19:28:23 ----A---- C:\WINDOWS\System32\drivers\redbook.sys
2011-10-23 19:27:38 ----A---- C:\WINDOWS\System32\usbui.dll
2011-10-23 19:27:32 ----A---- C:\WINDOWS\System32\drivers\wmiacpi.sys
2011-10-23 19:26:57 ----D---- C:\Program Files\Common Files\ODBC
2011-10-23 19:26:57 ----A---- C:\WINDOWS\System32\PerfStringBackup.INI
2011-10-23 19:26:57 ----A---- C:\WINDOWS\ODBCINST.INI
2011-10-23 19:26:54 ----D---- C:\Program Files\Common Files\SpeechEngines
2011-10-23 19:26:53 ----RD---- C:\Program Files
2011-10-23 19:26:53 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-10-23 19:26:53 ----D---- C:\Program Files\Common Files
2011-10-23 19:26:51 ----RA---- C:\WINDOWS\System32\kbdtuq.dll
2011-10-23 19:26:51 ----RA---- C:\WINDOWS\System32\kbdtuf.dll
2011-10-23 19:26:51 ----RA---- C:\WINDOWS\System32\kbdazel.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdycc.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbduzb.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdur.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdtat.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdru1.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdru.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdmon.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdkyr.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdkaz.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdbu.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdblr.dll
2011-10-23 19:26:49 ----RA---- C:\WINDOWS\System32\kbdaze.dll
2011-10-23 19:26:47 ----RA---- C:\WINDOWS\System32\kbdhept.dll
2011-10-23 19:26:47 ----RA---- C:\WINDOWS\System32\kbdhela3.dll
2011-10-23 19:26:47 ----RA---- C:\WINDOWS\System32\kbdhela2.dll
2011-10-23 19:26:47 ----RA---- C:\WINDOWS\System32\kbdhe319.dll
2011-10-23 19:26:47 ----RA---- C:\WINDOWS\System32\kbdhe220.dll
2011-10-23 19:26:47 ----RA---- C:\WINDOWS\System32\kbdhe.dll
2011-10-23 19:26:47 ----RA---- C:\WINDOWS\System32\kbdgkl.dll
2011-10-23 19:26:46 ----RA---- C:\WINDOWS\System32\kbdlv1.dll
2011-10-23 19:26:46 ----RA---- C:\WINDOWS\System32\kbdlv.dll
2011-10-23 19:26:46 ----RA---- C:\WINDOWS\System32\kbdlt1.dll
2011-10-23 19:26:46 ----RA---- C:\WINDOWS\System32\kbdlt.dll
2011-10-23 19:26:45 ----RA---- C:\WINDOWS\System32\kbdest.dll
2011-10-23 19:26:43 ----A---- C:\WINDOWS\System32\kbdsl1.dll
2011-10-23 19:26:43 ----A---- C:\WINDOWS\System32\kbdsl.dll
2011-10-23 19:26:43 ----A---- C:\WINDOWS\System32\kbdro.dll
2011-10-23 19:26:43 ----A---- C:\WINDOWS\System32\kbdpl1.dll
2011-10-23 19:26:43 ----A---- C:\WINDOWS\System32\kbdpl.dll
2011-10-23 19:26:43 ----A---- C:\WINDOWS\System32\kbdhu1.dll
2011-10-23 19:26:43 ----A---- C:\WINDOWS\System32\kbdhu.dll
2011-10-23 19:26:42 ----A---- C:\WINDOWS\System32\kbdycl.dll
2011-10-23 19:26:42 ----A---- C:\WINDOWS\System32\kbdcr.dll
2011-10-23 19:26:42 ----A---- C:\WINDOWS\System32\KBDAL.DLL
2011-10-23 19:26:41 ----A---- C:\WINDOWS\System32\spxcoins.dll
2011-10-23 19:26:41 ----A---- C:\WINDOWS\System32\irclass.dll
2011-10-23 19:26:41 ----A---- C:\WINDOWS\System32\EqnClass.Dll
2011-10-23 19:26:41 ----A---- C:\WINDOWS\System32\drivers\irenum.sys
2011-10-23 19:26:41 ----A---- C:\WINDOWS\System32\dgsetup.dll
2011-10-23 19:26:41 ----A---- C:\WINDOWS\System32\dgrpsetu.dll
2011-10-23 19:26:41 ----A---- C:\WINDOWS\System32\batt.dll
2011-10-23 19:26:38 ----N---- C:\WINDOWS\System32\CONFIG.TMP
2011-10-23 19:26:38 ----A---- C:\WINDOWS\TASKMAN.EXE
2011-10-23 19:26:38 ----A---- C:\WINDOWS\System32\storprop.dll
2011-10-23 19:26:38 ----A---- C:\WINDOWS\NOTEPAD.EXE
2011-10-23 19:26:32 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\desktop.ini
2011-10-23 19:26:31 ----RA---- C:\WINDOWS\SET7.tmp
2011-10-23 19:26:29 ----RA---- C:\WINDOWS\SET3.tmp
2011-10-23 19:26:25 ----D---- C:\WINDOWS\System32\CatRoot2
2011-10-23 19:26:25 ----D---- C:\WINDOWS\System32\CatRoot
2011-10-23 19:26:19 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-10-23 19:26:07 ----D---- C:\Documents and Settings
2011-10-23 19:26:07 ----A---- C:\WINDOWS\System32\FNTCACHE.DAT
2011-10-23 19:25:24 ----SH---- C:\boot.ini
2011-10-23 19:21:30 ----RSHDC---- C:\WINDOWS\System32\dllcache
2011-10-23 19:21:30 ----RSD---- C:\WINDOWS\Fonts
2011-10-23 19:21:30 ----RD---- C:\WINDOWS\Web
2011-10-23 19:21:30 ----HD---- C:\WINDOWS\inf
2011-10-23 19:21:30 ----D---- C:\WINDOWS\WinSxS
2011-10-23 19:21:30 ----D---- C:\WINDOWS\twain_32
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Temp
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\wins
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\wbem
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\usmt
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\spool
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\ShellExt
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\Setup
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\ras
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\oobe
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\npp
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\mui
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\inetsrv
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\IME
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\icsxml
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\ias
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\export
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\drivers\etc
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\drivers\disdn
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\drivers
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\dhcp
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\config
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\3com_dmi
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\3076
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\2052
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1054
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1042
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1041
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1037
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1033
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1031
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1029
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1028
2011-10-23 19:21:30 ----D---- C:\WINDOWS\System32\1025
2011-10-23 19:21:30 ----D---- C:\WINDOWS\system32
2011-10-23 19:21:30 ----D---- C:\WINDOWS\system
2011-10-23 19:21:30 ----D---- C:\WINDOWS\security
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Resources
2011-10-23 19:21:30 ----D---- C:\WINDOWS\repair
2011-10-23 19:21:30 ----D---- C:\WINDOWS\mui
2011-10-23 19:21:30 ----D---- C:\WINDOWS\msapps
2011-10-23 19:21:30 ----D---- C:\WINDOWS\msagent
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Media
2011-10-23 19:21:30 ----D---- C:\WINDOWS\java
2011-10-23 19:21:30 ----D---- C:\WINDOWS\ime
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Help
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Driver Cache
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Debug
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Cursors
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Connection Wizard
2011-10-23 19:21:30 ----D---- C:\WINDOWS\Config
2011-10-23 19:21:30 ----D---- C:\WINDOWS\AppPatch
2011-10-23 19:21:30 ----D---- C:\WINDOWS\addins
2011-10-23 19:21:30 ----D---- C:\WINDOWS
2011-10-23 17:56:26 ----D---- C:\Program Files\AVAST Software
2011-10-23 17:56:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2011-10-23 17:49:56 ----D---- C:\WINDOWS\System32\ReinstallBackups
2011-10-23 17:49:55 ----DC---- C:\WINDOWS\System32\DRVSTORE
2011-10-23 17:49:55 ----A---- C:\WINDOWS\System32\drivers\AmdPPM.sys
2011-10-23 17:49:54 ----D---- C:\Program Files\AMD
2011-10-23 17:49:41 ----D---- C:\Documents and Settings\Thomas\Data aplikací\InstallShield
2011-10-23 17:49:19 ----D---- C:\WINDOWS\LastGood.Tmp
2011-10-23 17:49:12 ----D---- C:\Program Files\Realtek
2011-10-23 17:47:56 ----D---- C:\Program Files\ATI Technologies
2011-10-23 17:47:55 ----HD---- C:\Program Files\InstallShield Installation Information
2011-10-23 17:47:31 ----D---- C:\Program Files\Common Files\InstallShield
2011-10-23 17:40:39 ----SHD---- C:\WINDOWS\Installer
2011-10-23 17:40:38 ----D---- C:\Documents and Settings\Thomas\Data aplikací\Identities
2011-10-23 17:40:36 ----HD---- C:\Program Files\Uninstall Information
2011-10-23 17:40:34 ----SD---- C:\Documents and Settings\Thomas\Data aplikací\Microsoft
2011-10-23 17:40:34 ----ASH---- C:\Documents and Settings\Thomas\Data aplikací\desktop.ini
2011-10-23 17:39:17 ----SHD---- C:\System Volume Information
2011-10-23 17:39:17 ----D---- C:\WINDOWS\Prefetch
2011-10-23 17:39:17 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-10-23 17:38:27 ----AS---- C:\WINDOWS\bootstat.dat
2011-10-23 17:37:17 ----D---- C:\WINDOWS\System32\xircom
2011-10-23 17:37:17 ----D---- C:\Program Files\xerox
2011-10-23 17:37:17 ----D---- C:\Program Files\microsoft frontpage
2011-10-23 17:37:05 ----RASH---- C:\MSDOS.SYS
2011-10-23 17:37:05 ----RASH---- C:\IO.SYS
2011-10-23 17:37:05 ----A---- C:\WINDOWS\control.ini
2011-10-23 17:37:05 ----A---- C:\CONFIG.SYS
2011-10-23 17:37:05 ----A---- C:\AUTOEXEC.BAT
2011-10-23 17:36:58 ----A---- C:\WINDOWS\System32\mapi32.dll
2011-10-23 17:36:27 ----SD---- C:\WINDOWS\Downloaded Program Files
2011-10-23 17:36:27 ----RD---- C:\WINDOWS\Offline Web Pages
2011-10-23 17:36:11 ----D---- C:\WINDOWS\srchasst
2011-10-23 17:36:03 ----D---- C:\WINDOWS\System32\Macromed
2011-10-23 17:36:03 ----D---- C:\WINDOWS\System32\DirectX
2011-10-23 17:35:50 ----A---- C:\WINDOWS\System32\qmgrprxy.dll
2011-10-23 17:35:50 ----A---- C:\WINDOWS\System32\qmgr.dll
2011-10-23 17:35:48 ----D---- C:\Program Files\Movie Maker
2011-10-23 17:35:32 ----A---- C:\WINDOWS\System32\safrslv.dll
2011-10-23 17:35:31 ----A---- C:\WINDOWS\System32\safrdm.dll
2011-10-23 17:35:31 ----A---- C:\WINDOWS\System32\safrcdlg.dll
2011-10-23 17:35:31 ----A---- C:\WINDOWS\System32\racpldlg.dll
2011-10-23 17:35:31 ----A---- C:\WINDOWS\System32\atrace.dll
2011-10-23 17:35:26 ----A---- C:\WINDOWS\System32\desktop.ini
2011-10-23 17:35:26 ----A---- C:\WINDOWS\desktop.ini
2011-10-23 17:35:20 ----D---- C:\WINDOWS\System32\Restore
2011-10-23 17:35:20 ----A---- C:\WINDOWS\System32\srsvc.dll
2011-10-23 17:35:20 ----A---- C:\WINDOWS\System32\srrstr.dll
2011-10-23 17:35:20 ----A---- C:\WINDOWS\System32\srclient.dll
2011-10-23 17:35:19 ----D---- C:\Program Files\Windows Media Player
2011-10-23 17:35:19 ----A---- C:\WINDOWS\System32\drivers\sr.sys
2011-10-23 17:35:18 ----A---- C:\WINDOWS\System32\nmmkcert.dll
2011-10-23 17:35:18 ----A---- C:\WINDOWS\System32\nmevtmsg.dll
2011-10-23 17:35:18 ----A---- C:\WINDOWS\System32\mnmsrvc.exe
2011-10-23 17:35:18 ----A---- C:\WINDOWS\System32\mnmdd.dll
2011-10-23 17:35:18 ----A---- C:\WINDOWS\System32\isrdbg32.dll
2011-10-23 17:35:18 ----A---- C:\WINDOWS\System32\ils.dll
2011-10-23 17:35:17 ----A---- C:\WINDOWS\System32\msconf.dll
2011-10-23 17:35:14 ----D---- C:\WINDOWS\PCHEALTH
2011-10-23 17:35:14 ----D---- C:\Program Files\NetMeeting
2011-10-23 17:35:14 ----A---- C:\WINDOWS\System32\msoert2.dll
2011-10-23 17:35:14 ----A---- C:\WINDOWS\System32\msoeacct.dll
2011-10-23 17:35:14 ----A---- C:\WINDOWS\System32\acctres.dll
2011-10-23 17:35:13 ----D---- C:\Program Files\Common Files\Services
2011-10-23 17:35:12 ----A---- C:\WINDOWS\System32\inetres.dll
2011-10-23 17:35:11 ----A---- C:\WINDOWS\System32\inetcomm.dll
2011-10-23 17:35:07 ----SD---- C:\WINDOWS\Tasks
2011-10-23 17:35:07 ----D---- C:\Program Files\Outlook Express
2011-10-23 17:35:07 ----A---- C:\WINDOWS\System32\schedsvc.dll
2011-10-23 17:35:07 ----A---- C:\WINDOWS\System32\mstinit.exe
2011-10-23 17:35:07 ----A---- C:\WINDOWS\System32\mstask.dll
2011-10-23 17:35:07 ----A---- C:\WINDOWS\System32\icwphbk.dll
2011-10-23 17:35:07 ----A---- C:\WINDOWS\System32\icwdial.dll
2011-10-23 17:35:06 ----A---- C:\WINDOWS\System32\isign32.dll
2011-10-23 17:35:06 ----A---- C:\WINDOWS\System32\inetcfg.dll
2011-10-23 17:35:06 ----A---- C:\WINDOWS\System32\icfgnt5.dll
2011-10-23 17:35:04 ----D---- C:\Program Files\Common Files\MSSoap
2011-10-23 17:34:59 ----D---- C:\Program Files\Common Files\System
2011-10-23 17:34:58 ----D---- C:\Program Files\Internet Explorer
2011-10-23 17:34:45 ----A---- C:\WINDOWS\System32\emptyregdb.dat
2011-10-23 17:34:33 ----D---- C:\Program Files\ComPlus Applications
2011-10-23 17:34:31 ----A---- C:\WINDOWS\vbaddin.ini
2011-10-23 17:34:31 ----A---- C:\WINDOWS\vb.ini
2011-10-23 17:34:27 ----D---- C:\WINDOWS\Registration
2011-10-23 17:34:22 ----HD---- C:\Program Files\WindowsUpdate
2011-10-23 17:34:22 ----D---- C:\Program Files\Online Services
2011-10-23 17:34:18 ----D---- C:\Program Files\Messenger
2011-10-23 17:34:12 ----D---- C:\Program Files\MSN
2011-10-23 17:34:09 ----D---- C:\Program Files\MSN Gaming Zone
2011-10-23 17:34:09 ----A---- C:\WINDOWS\System32\write.exe
2011-10-23 17:33:59 ----A---- C:\WINDOWS\System32\sndvol32.exe
2011-10-23 17:33:59 ----A---- C:\WINDOWS\System32\accwiz.exe
2011-10-23 17:33:58 ----A---- C:\WINDOWS\System32\sndrec32.exe
2011-10-23 17:33:58 ----A---- C:\WINDOWS\System32\mplay32.exe
2011-10-23 17:33:58 ----A---- C:\WINDOWS\System32\hypertrm.dll
2011-10-23 17:33:58 ----A---- C:\WINDOWS\System32\hticons.dll
2011-10-23 17:33:58 ----A---- C:\WINDOWS\System32\avwav.dll
2011-10-23 17:33:58 ----A---- C:\WINDOWS\System32\avtapi.dll
2011-10-23 17:33:58 ----A---- C:\WINDOWS\System32\avmeter.dll
2011-10-23 17:33:57 ----D---- C:\Program Files\Windows NT
2011-10-23 17:33:57 ----A---- C:\WINDOWS\System32\winchat.exe
2011-10-23 17:33:56 ----A---- C:\WINDOWS\System32\mspaint.exe
2011-10-23 17:33:51 ----A---- C:\WINDOWS\System32\clipbrd.exe
2011-10-23 17:33:50 ----A---- C:\WINDOWS\System32\charmap.exe
2011-10-23 17:33:50 ----A---- C:\WINDOWS\System32\getuname.dll
2011-10-23 17:33:50 ----A---- C:\WINDOWS\System32\calc.exe
2011-10-23 17:33:49 ----A---- C:\WINDOWS\System32\winmine.exe
2011-10-23 17:33:49 ----A---- C:\WINDOWS\System32\spider.exe
2011-10-23 17:33:49 ----A---- C:\WINDOWS\System32\sol.exe
2011-10-23 17:33:49 ----A---- C:\WINDOWS\System32\mshearts.exe
2011-10-23 17:33:48 ----A---- C:\WINDOWS\System32\wuauserv.dll
2011-10-23 17:33:48 ----A---- C:\WINDOWS\System32\wuaueng.dll
2011-10-23 17:33:48 ----A---- C:\WINDOWS\System32\wuauclt.exe
2011-10-23 17:33:48 ----A---- C:\WINDOWS\System32\tscfgwmi.dll
2011-10-23 17:33:48 ----A---- C:\WINDOWS\System32\freecell.exe
2011-10-23 17:33:48 ----A---- C:\WINDOWS\System32\drivers\tdtcp.sys
2011-10-23 17:33:48 ----A---- C:\WINDOWS\System32\drivers\tdpipe.sys
2011-10-23 17:33:48 ----A---- C:\WINDOWS\System32\drivers\rdpwd.sys
2011-10-23 17:33:47 ----A---- C:\WINDOWS\System32\sessmgr.exe
2011-10-23 17:33:47 ----A---- C:\WINDOWS\System32\reset.exe
2011-10-23 17:33:47 ----A---- C:\WINDOWS\System32\remotepg.dll
2011-10-23 17:33:47 ----A---- C:\WINDOWS\System32\rdshost.exe
2011-10-23 17:33:47 ----A---- C:\WINDOWS\System32\rdsaddin.exe
2011-10-23 17:33:47 ----A---- C:\WINDOWS\System32\rdchost.dll
2011-10-23 17:33:47 ----A---- C:\WINDOWS\System32\mstscax.dll
2011-10-23 17:33:47 ----A---- C:\WINDOWS\System32\mstsc.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\usrlogon.cmd
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\tsshutdn.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\tslabels.ini
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\tskill.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\tsdiscon.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\tscupgrd.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\tscon.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\termsrv.dll
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\shadow.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\rwinsta.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\regini.exe
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\rdpwsx.dll
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\rdpsnd.dll
2011-10-23 17:33:46 ----A---- C:\WINDOWS\System32\rdpclip.exe
2011-10-23 17:33:45 ----D---- C:\WINDOWS\System32\MsDtc
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\rdpcfgex.dll
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\qwinsta.exe
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\qprocess.exe
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\qappsrv.exe
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\msg.exe
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\msdtcuiu.dll
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\logoff.exe
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\icaapi.dll
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\cfgbkend.dll
2011-10-23 17:33:45 ----A---- C:\WINDOWS\System32\cdmodem.dll
2011-10-23 17:33:44 ----A---- C:\WINDOWS\System32\xolehlp.dll
2011-10-23 17:33:44 ----A---- C:\WINDOWS\System32\mtxoci.dll
2011-10-23 17:33:44 ----A---- C:\WINDOWS\System32\msdtctm.dll
2011-10-23 17:33:44 ----A---- C:\WINDOWS\System32\msdtcprx.dll
2011-10-23 17:33:44 ----A---- C:\WINDOWS\System32\msdtcprf.ini
2011-10-23 17:33:44 ----A---- C:\WINDOWS\System32\msdtclog.dll
2011-10-23 17:33:44 ----A---- C:\WINDOWS\System32\msdtc.exe
2011-10-23 17:33:42 ----D---- C:\WINDOWS\System32\Com
2011-10-23 17:33:42 ----A---- C:\WINDOWS\System32\stclient.dll
2011-10-23 17:33:42 ----A---- C:\WINDOWS\System32\mtxlegih.dll
2011-10-23 17:33:42 ----A---- C:\WINDOWS\System32\mtxex.dll
2011-10-23 17:33:42 ----A---- C:\WINDOWS\System32\mtxdm.dll
2011-10-23 17:33:42 ----A---- C:\WINDOWS\System32\dcomcnfg.exe
2011-10-23 17:33:42 ----A---- C:\WINDOWS\System32\comrepl.dll
2011-10-23 17:33:42 ----A---- C:\WINDOWS\System32\comaddin.dll
2011-10-23 17:33:42 ----A---- C:\WINDOWS\System32\colbact.dll
2011-10-23 17:33:41 ----A---- C:\WINDOWS\System32\clbcatex.dll
2011-10-23 17:33:41 ----A---- C:\WINDOWS\System32\catsrvut.dll
2011-10-23 17:33:41 ----A---- C:\WINDOWS\System32\catsrvps.dll
2011-10-23 17:33:41 ----A---- C:\WINDOWS\System32\catsrv.dll
2011-10-23 17:33:40 ----A---- C:\WINDOWS\System32\comuid.dll
2011-10-23 17:33:40 ----A---- C:\WINDOWS\System32\comsvcs.dll
2011-10-23 17:33:40 ----A---- C:\WINDOWS\System32\comsnap.dll
2011-10-23 17:33:40 ----A---- C:\WINDOWS\System32\clbcatq.dll
2011-10-23 17:33:29 ----A---- C:\WINDOWS\System32\wmimgmt.msc
2011-10-23 17:33:29 ----A---- C:\WINDOWS\System32\servdeps.dll
2011-10-23 17:33:29 ----A---- C:\WINDOWS\System32\mmfutil.dll
2011-10-23 17:33:29 ----A---- C:\WINDOWS\System32\licwmi.dll
2011-10-23 17:33:29 ----A---- C:\WINDOWS\System32\cmprops.dll
2011-10-23 17:33:28 ----A---- C:\WINDOWS\System32\drivers\termdd.sys
2011-10-23 17:33:28 ----A---- C:\WINDOWS\System32\drivers\rdpdr.sys
======List of files/folders modified in the last 1 month======
2011-10-23 19:26:53 ----A---- C:\WINDOWS\system.ini
2011-10-23 17:37:05 ----A---- C:\WINDOWS\win.ini
2011-10-23 17:36:51 ----ASH---- C:\WINDOWS\fonts\desktop.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 aswRdr;aswRdr; C:\WINDOWS\System32\drivers\aswRdr.sys [2011-09-06 34392]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2001-10-25 13952]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\System32\DRIVERS\wmiacpi.sys [2001-08-17 8064]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtenicxp.sys [2009-05-25 142336]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2001-10-25 24960]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2001-10-25 21760]
S1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\System32\drivers\Aavmker4.sys [2011-09-06 30808]
S1 aswSP;aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [2011-09-06 320856]
S1 aswTdi;avast! Network Shield Support; C:\WINDOWS\System32\drivers\aswTdi.sys [2011-09-06 52568]
S2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\System32\drivers\aswMon2.sys [2011-09-06 110552]
S3 usbprint;Třída USB Printer; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2001-08-17 24832]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
S2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-09-06 44768]
-----------------EOF-----------------

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Kontrola logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- Rudy
- Site Admin
- Příspěvky: 119359
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Kontrola logu
Dvouklikem na soubor C:\Program Files\trend micro\Thomas.exe spusťte HiajckThis. V otevřeném okně vlevo ve čtverečku zaškrtněte:
a klikněte na >Fix checked<. Restartujte PC. Jinak čisto.O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.