Obsah fóra
PravidláRegistrovaťPrihlásenie




Odpovedať na tému [ Príspevkov: 36 ] Choď na stránku: 1, 2 ďalšia
AutorSpráva
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 04.07.08
Prihlásený: 31.10.09
Príspevky: 6
Témy: 1
Príspevok NapísalOffline : 04.07.2008 16:32

Zdravim, mozte mi prosim skontrolovat toto? Dik.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:31:11, on 4.7.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\KONICA~1\PAGESC~1\PSMain.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\KONICA MINOLTA\PageScope_Job_Spooler\jre\bin\javaw.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ICQ6\ICQ.exe
C:\Program Files\SEC\Natural Color Pro\NCProTray.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
C:\MrpWin\JedUc\mrpjus.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Pidgin\pidgin.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program
Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6\ICQ.exe" silent
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1085031214-162531612-725345543-1006\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'admin')
O4 - HKUS\S-1-5-21-1085031214-162531612-725345543-1006\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" (User 'admin')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
O4 - Global Startup: NCProTray.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: DirMngr - Unknown owner - C:\Program Files\GNU\GnuPG\dirmngr.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PageScope Job Spooler (PSJS) - ZeroG Software - C:\PROGRA~1\KONICA~1\PAGESC~1\PSMain.exe

--
End of file - 6378 bytes


Offline

Užívateľ
Užívateľ
kontrola hijack

Registrovaný: 02.09.07
Prihlásený: 19.01.20
Príspevky: 6373
Témy: 298
Bydlisko: Žilina
Príspevok NapísalOffline : 04.07.2008 16:55

O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll

O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)

O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)







_________________
NTB: Dell Vostro 5470 - Core i5-4200U, GT 740M, 8GB DDR3-1600, Crucial MX100 256GB, 14" 1366x768
Audio: KRK RoKit 5 G2 White, Lexicon Alpha, M-Audio Axiom 25 MKII, AKG Y55
Phone: Samsung Galaxy S8
Vozenie: Alfa Romeo 159 SW 1.9JTDm 110kW - DPF/EGR/SWIRL OFF, BOSE SOUND
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 04.07.08
Prihlásený: 31.10.09
Príspevky: 6
Témy: 1
Príspevok Napísal autor témyOffline : 05.07.2008 9:42

OK, dik, ale co s tym?


Offline

Užívateľ
Užívateľ
kontrola hijack

Registrovaný: 04.04.08
Prihlásený: 27.02.12
Príspevky: 531
Témy: 27
Bydlisko: Nitra
Príspevok NapísalOffline : 05.07.2008 9:50

Musíš to fix-núť







_________________
V príprave...
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 04.07.08
Prihlásený: 31.10.09
Príspevky: 6
Témy: 1
Príspevok Napísal autor témyOffline : 05.07.2008 10:28

OK. A moze mi niekto este vysvetlit, co to fixnutie konkretne robi? Resp. aspon odkazat na nejaky clanok na nete? Dik


Offline

Užívateľ
Užívateľ
kontrola hijack

Registrovaný: 02.09.07
Prihlásený: 19.01.20
Príspevky: 6373
Témy: 298
Bydlisko: Žilina
Príspevok NapísalOffline : 05.07.2008 12:17

http://www.pcforum.sk/cistime-napadnuty ... 27265.html
tam si pozri clanok o HJT. Vsetko tam mas vysvetlene







_________________
NTB: Dell Vostro 5470 - Core i5-4200U, GT 740M, 8GB DDR3-1600, Crucial MX100 256GB, 14" 1366x768
Audio: KRK RoKit 5 G2 White, Lexicon Alpha, M-Audio Axiom 25 MKII, AKG Y55
Phone: Samsung Galaxy S8
Vozenie: Alfa Romeo 159 SW 1.9JTDm 110kW - DPF/EGR/SWIRL OFF, BOSE SOUND
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 04.07.08
Prihlásený: 31.10.09
Príspevky: 6
Témy: 1
Príspevok Napísal autor témyOffline : 06.07.2008 19:29

ok, dik


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 04.07.08
Prihlásený: 31.10.09
Príspevky: 6
Témy: 1
Príspevok Napísal autor témyOffline : 13.07.2008 15:36

este jednu otazku:
chcel by som vediet, ci to icq (resp. jeho sucast, alebo co to bolo), mohlo sposobit stahovanie mrtne dat z netu... alebo to bol nejaky iny vir?

Dik.


Offline

Užívateľ
Užívateľ
kontrola hijack

Registrovaný: 02.09.07
Prihlásený: 19.01.20
Príspevky: 6373
Témy: 298
Bydlisko: Žilina
Príspevok NapísalOffline : 13.07.2008 15:37

ICQ toolbar mozes fixnut







_________________
NTB: Dell Vostro 5470 - Core i5-4200U, GT 740M, 8GB DDR3-1600, Crucial MX100 256GB, 14" 1366x768
Audio: KRK RoKit 5 G2 White, Lexicon Alpha, M-Audio Axiom 25 MKII, AKG Y55
Phone: Samsung Galaxy S8
Vozenie: Alfa Romeo 159 SW 1.9JTDm 110kW - DPF/EGR/SWIRL OFF, BOSE SOUND
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 04.07.08
Prihlásený: 31.10.09
Príspevky: 6
Témy: 1
Príspevok Napísal autor témyOffline : 13.07.2008 15:42

dik za dopoved, ale to uz som spravil, chcel som vediet, ci to moze robit nieco take - stahovanie dat (mrtne), alebo ci to robi nejaky iny vir...


Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 12.06.08
Prihlásený: 16.09.10
Príspevky: 440
Témy: 4
Príspevok NapísalOffline : 13.07.2008 18:33

Ahoj,

posli mi na mail log zo SysInspectorom. Pozriem to detailnejsie.


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 03.06.08
Prihlásený: 03.06.08
Príspevky: 3
Témy: 0
Príspevok NapísalOffline : 11.11.2008 21:17

Poprosim o nakuknutie sem


Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\ESRI\License\arcgis9x\lmgrd.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
C:\PROGRA~1\ESRI\License\arcgis9x\ARCGIS.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\QIP\qip.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Documents and Settings\Pedro\Plocha\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ArcGIS License Manager - Unknown owner - C:\PROGRA~1\ESRI\License\arcgis9x\lmgrd.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: SolidPDFConverterReadSpool (ScReadSpool) - VoyagerSoft, LLC - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 12.06.08
Prihlásený: 16.09.10
Príspevky: 440
Témy: 4
Príspevok NapísalOffline : 21.11.2008 16:48

Tento log je ok. Mozes fixnut:

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 18.06.08
Prihlásený: 04.05.13
Príspevky: 19
Témy: 1
Príspevok NapísalOffline : 26.12.2012 14:31

mam taky problem vzdy ked kliknem vpravo dole na ikonku zvuku tak zamrzne pocitac som zufalyy
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:38:49, on 26.12.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17115)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Lenovo\System Update\SUService.exe
C:\Program Files\COMODO\COMODO Internet Security\cis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\T8300\Desktop\hijackthis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Lenovo PM Service (IBMPMSVC) - Lenovo. - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

--
End of file - 6127 bytes


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 26.12.2012 15:12

vlož log z rsit je podrobnejší http://en.kioskea.net/download/download-11416-rsit


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 18.06.08
Prihlásený: 04.05.13
Príspevky: 19
Témy: 1
Príspevok NapísalOffline : 26.12.2012 15:30

Logfile of random's system information tool 1.09 (written by random/random)
Run by T8300 at 2012-12-26 14:27:18
Microsoft Windows XP Professional Service Pack 3
System drive C: has 45 GB (85%) free of 53 GB
Total RAM: 2006 MB (66% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:27:30, on 26.12.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17115)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Lenovo\System Update\SUService.exe
C:\Program Files\COMODO\COMODO Internet Security\cis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Analog Devices\SoundMAX\smax4.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\T8300\Desktop\RSIT.exe
C:\Program Files\trend micro\T8300.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Lenovo PM Service (IBMPMSVC) - Lenovo. - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

--
End of file - 6214 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\T8300\Application Data\Mozilla\Firefox\Profiles\6ld68es7.default

prefs.js - "browser.startup.homepage" - "google.sk"

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.10.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\WINDOWS\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
amazondotcom.xml
bing.xml
eBay.xml
google.xml
twitter.xml
wikipedia.xml
yahoo.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-12-25 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-12-25 170416]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2012-12-14 1426640]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2054360]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\CTFMON.EXE [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-12-29 687560]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe [2010-02-05 173592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe [2010-02-05 141336]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LenovoAutoScrollUtility]
C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe [2011-10-20 101440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPMailChecker]
C:\PROGRA~1\THINKV~1\PrdCtr\LPMLCHK.exe [2009-07-23 124248]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPManager]
C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe [2009-07-23 185688]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\WINDOWS\system32\igfxpers.exe [2010-02-05 142360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2007-12-12 884736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-12-19 1044480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TpShocks]
C:\WINDOWS\system32\TpShocks.exe [2012-09-20 186248]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrackPointSrv]
C:\Program Files\Lenovo\TrackPoint\tp4serv.exe [2011-11-01 95264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVT Scheduler Proxy]
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe [2008-03-04 487424]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\ThinkPad\BLUETO~1\BTTray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
C:\PROGRA~1\DIGITA~1\DLG.exe [2006-11-03 50688]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^T8300^Start Menu^Programs^Startup^Lingea Update Center.lnk]
C:\PROGRA~1\COMMON~1\LINGEA~1\luc.exe [2010-04-11 275736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2010-01-13 205824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-12-26 14:27:18 ----D---- C:\rsit
2012-12-26 14:27:18 ----D---- C:\Program Files\trend micro
2012-12-26 13:56:32 ----D---- C:\Program Files\PhotoshopPortable
2012-12-26 13:26:10 ----D---- C:\WINDOWS\LastGood
2012-12-26 09:18:54 ----D---- C:\Documents and Settings\T8300\Application Data\Skype
2012-12-26 09:18:45 ----D---- C:\Program Files\Common Files\Skype
2012-12-26 09:18:35 ----RD---- C:\Program Files\Skype
2012-12-26 09:18:26 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2012-12-26 09:11:41 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2012-12-26 09:11:34 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2012-12-26 09:11:26 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2012-12-26 09:11:18 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2012-12-26 09:11:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2012-12-26 09:11:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2712808$
2012-12-26 09:10:52 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2012-12-26 09:10:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2012-12-26 09:10:37 ----HDC---- C:\WINDOWS\$NtUninstallKB2659262$
2012-12-26 09:10:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2564958$
2012-12-26 09:10:21 ----HDC---- C:\WINDOWS\$NtUninstallKB2478971$
2012-12-26 09:10:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2758857$
2012-12-26 09:10:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893-v2$
2012-12-26 09:09:58 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2012-12-26 09:09:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2646524$
2012-12-26 09:09:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2779030$
2012-12-26 09:09:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2585542$
2012-12-26 09:09:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2631813$
2012-12-26 09:09:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2012-12-26 09:09:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2691442$
2012-12-26 09:08:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2012-12-26 09:08:48 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2012-12-26 09:08:41 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2012-12-26 09:08:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2779562$
2012-12-26 09:08:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2012-12-26 09:08:17 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2012-12-26 09:08:07 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2012-12-26 09:07:59 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2012-12-26 09:07:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2012-12-26 09:07:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2655992$
2012-12-26 09:07:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2724197$
2012-12-26 09:07:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2012-12-26 09:07:16 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2012-12-26 09:07:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2481109$
2012-12-26 09:06:59 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2012-12-26 09:06:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2012-12-26 09:06:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2598479$
2012-12-26 09:06:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2012-12-26 09:06:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2736233$
2012-12-26 09:06:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2686509$
2012-12-26 09:06:10 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2012-12-26 09:06:02 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2012-12-26 09:05:53 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2012-12-26 09:05:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2012-12-26 09:05:36 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2012-12-26 09:05:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2510581$
2012-12-26 09:05:20 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2012-12-26 09:05:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2476490$
2012-12-26 09:05:06 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2012-12-26 09:04:54 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2012-12-26 09:04:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2012-12-26 09:04:34 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2012-12-26 09:04:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2483185$
2012-12-26 09:04:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2624667$
2012-12-26 09:04:07 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2012-12-26 09:04:00 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2012-12-26 09:03:52 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2012-12-26 09:03:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2719985$
2012-12-26 09:03:33 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2012-12-26 09:03:25 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2012-12-26 09:03:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2592799$
2012-12-26 09:03:12 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2012-12-26 09:03:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2753842-v2$
2012-12-26 09:02:55 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2012-12-26 09:02:49 ----HDC---- C:\WINDOWS\$NtUninstallKB2770660$
2012-12-26 09:02:43 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2012-12-26 09:02:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2012-12-26 09:02:18 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2012-12-26 09:02:12 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2012-12-26 09:02:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2012-12-26 09:01:38 ----D---- C:\WINDOWS\ie7updates
2012-12-26 09:01:26 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2012-12-26 09:01:19 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2012-12-26 09:01:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2603381$
2012-12-26 09:01:06 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2012-12-26 09:01:03 ----A---- C:\WINDOWS\system32\wmpns.dll
2012-12-26 09:00:54 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2012-12-26 09:00:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2012-12-26 09:00:28 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2012-12-26 09:00:10 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2012-12-26 08:59:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2012-12-26 08:59:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2653956$
2012-12-26 08:59:34 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2012-12-26 08:59:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2749655$
2012-12-26 08:59:18 ----HDC---- C:\WINDOWS\$NtUninstallKB971029$
2012-12-26 08:59:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2012-12-26 08:59:05 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2012-12-26 08:58:59 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2012-12-26 08:58:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2698365$
2012-12-26 08:58:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2619339$
2012-12-26 08:58:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2705219-v2$
2012-12-26 08:58:34 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2012-12-26 08:58:28 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2012-12-26 08:58:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2727528$
2012-12-26 08:58:18 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2012-12-26 08:58:13 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2012-12-26 08:58:06 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2012-12-26 08:58:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2723135-v2$
2012-12-26 08:57:55 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2012-12-26 08:57:50 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2012-12-26 08:57:37 ----HDC---- C:\WINDOWS\$NtUninstallKB2618451$
2012-12-26 08:57:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2661254-v2$
2012-12-26 08:57:26 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2012-12-26 08:57:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2012-12-26 08:57:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2676562$
2012-12-26 08:56:57 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2012-12-26 08:56:52 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2012-12-26 08:56:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2478960$
2012-12-26 08:56:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2393802$
2012-12-26 08:56:23 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2012-12-26 08:56:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2620712$
2012-12-26 08:56:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2012-12-26 08:56:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2661637$
2012-12-26 08:56:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2584146$
2012-12-26 08:55:01 ----A---- C:\WINDOWS\system32\MRT.exe
2012-12-26 08:54:52 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2012-12-26 08:54:46 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2012-12-26 08:54:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2012-12-26 08:54:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2012-12-25 17:40:10 ----A---- C:\WINDOWS\ODBC.INI
2012-12-25 17:40:06 ----A---- C:\WINDOWS\system32\mdimon.dll
2012-12-25 17:39:35 ----D---- C:\Program Files\Common Files\DESIGNER
2012-12-25 17:39:26 ----D---- C:\WINDOWS\SHELLNEW
2012-12-25 17:39:26 ----D---- C:\Program Files\Microsoft.NET
2012-12-25 17:39:26 ----D---- C:\Program Files\Microsoft Office
2012-12-25 17:37:28 ----D---- C:\Documents and Settings\T8300\Application Data\DAEMON Tools Pro
2012-12-25 17:37:28 ----D---- C:\Documents and Settings\T8300\Application Data\DAEMON Tools
2012-12-25 17:34:14 ----D---- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
2012-12-25 17:34:09 ----D---- C:\Program Files\DAEMON Tools Lite
2012-12-25 17:31:34 ----A---- C:\WINDOWS\system32\drivers\sptd.sys
2012-12-25 17:31:32 ----D---- C:\Documents and Settings\T8300\Application Data\DAEMON Tools Lite
2012-12-25 17:17:01 ----D---- C:\Program Files\Common Files\Lingea Shared
2012-12-25 17:16:16 ----D---- C:\Program Files\Lingea
2012-12-25 17:07:35 ----N---- C:\WINDOWS\system32\wdmioctl.dll
2012-12-25 17:07:35 ----N---- C:\WINDOWS\system32\SMMedia.dll
2012-12-25 17:07:35 ----N---- C:\WINDOWS\system32\DSndUp.exe
2012-12-25 17:07:35 ----N---- C:\WINDOWS\system32\CleanUp.exe
2012-12-25 17:07:35 ----D---- C:\Program Files\Analog Devices
2012-12-25 17:07:19 ----A---- C:\WINDOWS\system32\PostProc.dll
2012-12-25 17:07:19 ----A---- C:\WINDOWS\system32\drivers\aeaudio.sys
2012-12-25 17:07:19 ----A---- C:\WINDOWS\system32\drivers\ADIHdAud.sys
2012-12-25 17:07:18 ----D---- C:\Drivers
2012-12-25 16:56:35 ----D---- C:\Documents and Settings\T8300\Application Data\Media Player Classic
2012-12-25 16:55:20 ----A---- C:\WINDOWS\system32\unrar.dll
2012-12-25 16:55:17 ----A---- C:\WINDOWS\avisplitter.ini
2012-12-25 16:55:14 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2012-12-25 16:55:13 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2012-12-25 16:55:13 ----A---- C:\WINDOWS\system32\xvidcore.dll


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 18.06.08
Prihlásený: 04.05.13
Príspevky: 19
Témy: 1
Príspevok NapísalOffline : 26.12.2012 15:31

2012-12-25 16:55:13 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2012-12-25 16:55:09 ----D---- C:\Program Files\K-Lite Codec Pack
2012-12-25 16:51:09 ----D---- C:\Program Files\Audio
2012-12-25 16:39:12 ----D---- C:\Documents and Settings\All Users\Application Data\Sun
2012-12-25 16:39:11 ----D---- C:\Program Files\Common Files\Java
2012-12-25 16:39:05 ----A---- C:\WINDOWS\system32\npDeployJava1.dll
2012-12-25 16:39:05 ----A---- C:\WINDOWS\system32\javaws.exe
2012-12-25 16:39:05 ----A---- C:\WINDOWS\system32\deployJava1.dll
2012-12-25 16:38:49 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2012-12-25 16:38:49 ----A---- C:\WINDOWS\system32\javaw.exe
2012-12-25 16:38:49 ----A---- C:\WINDOWS\system32\java.exe
2012-12-25 16:38:35 ----D---- C:\Program Files\Java
2012-12-25 16:37:28 ----D---- C:\Documents and Settings\T8300\Application Data\Sun
2012-12-25 16:23:58 ----N---- C:\WINDOWS\system32\drivers\bthport.sys
2012-12-25 16:18:10 ----N---- C:\WINDOWS\system32\browserchoice.exe
2012-12-25 16:15:40 ----D---- C:\Program Files\WinRAR
2012-12-25 16:12:54 ----N---- C:\WINDOWS\system32\iacenc.dll
2012-12-25 16:08:25 ----A---- C:\WINDOWS\system32\xpsp4res.dll
2012-12-25 16:07:42 ----D---- C:\WINDOWS\system32\PreInstall
2012-12-25 16:07:41 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2012-12-25 16:07:41 ----HD---- C:\WINDOWS\$hf_mig$
2012-12-25 14:44:59 ----A---- C:\WINDOWS\SMWizard.INI
2012-12-25 14:14:24 ----D---- C:\Program Files\partition magic
2012-12-25 12:31:37 ----D---- C:\Documents and Settings\T8300\Application Data\Help
2012-12-25 12:14:30 ----D---- C:\WINDOWS\system32\NtmsData
2012-12-25 11:56:23 ----SD---- C:\Documents and Settings\All Users\Application Data\Shared Space
2012-12-25 11:55:21 ----D---- C:\Program Files\COMODO
2012-12-25 11:55:09 ----D---- C:\Documents and Settings\All Users\Application Data\Comodo
2012-12-25 11:55:08 ----D---- C:\Documents and Settings\All Users\Application Data\Comodo Downloader
2012-12-25 11:21:34 ----D---- C:\Documents and Settings\T8300\Application Data\Mozilla
2012-12-25 11:21:17 ----D---- C:\Program Files\Mozilla Firefox
2012-12-25 10:46:31 ----D---- C:\Program Files\ESET
2012-12-25 10:41:56 ----D---- C:\WINDOWS\system32\appmgmt
2012-12-25 10:23:48 ----D---- C:\Documents and Settings\T8300\Application Data\ESET
2012-12-25 10:23:02 ----D---- C:\Documents and Settings\All Users\Application Data\ESET
2012-12-25 10:13:43 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2012-12-25 09:19:44 ----A---- C:\WINDOWS\system32\NETwLr32.dll
2012-12-25 09:19:44 ----A---- C:\WINDOWS\system32\NETwLc32.dll
2012-12-25 09:19:44 ----A---- C:\WINDOWS\system32\drivers\NETwLx32.sys
2012-12-25 08:15:32 ----D---- C:\WINDOWS\pss
2012-12-25 07:55:32 ----D---- C:\Program Files\totalcmd
2012-12-25 07:55:32 ----A---- C:\WINDOWS\wincmd.ini
2012-12-25 07:55:32 ----A---- C:\WINDOWS\UC.PIF
2012-12-25 07:55:32 ----A---- C:\WINDOWS\RAR.PIF
2012-12-25 07:55:32 ----A---- C:\WINDOWS\PKZIP.PIF
2012-12-25 07:55:32 ----A---- C:\WINDOWS\PKUNZIP.PIF
2012-12-25 07:55:32 ----A---- C:\WINDOWS\NOCLOSE.PIF
2012-12-25 07:55:32 ----A---- C:\WINDOWS\LHA.PIF
2012-12-25 07:55:32 ----A---- C:\WINDOWS\ARJ.PIF
2012-12-25 07:40:30 ----A---- C:\WINDOWS\system32\drivers\mouhid.sys
2012-12-25 07:38:23 ----A---- C:\WINDOWS\system32\drivers\hidusb.sys
2012-12-21 09:49:17 ----SHD---- C:\RECYCLER
2012-12-20 21:21:16 ----D---- C:\Documents and Settings\T8300\Application Data\Lenovo
2012-12-20 21:19:11 ----A---- C:\WINDOWS\system32\MFC71.DLL
2012-12-20 21:19:10 ----D---- C:\Documents and Settings\All Users\Application Data\Lenovo
2012-12-20 21:19:09 ----D---- C:\Program Files\ThinkVantage
2012-12-20 21:18:44 ----D---- C:\Program Files\Digital Line Detect
2012-12-20 21:18:34 ----D---- C:\Program Files\NetWaiting
2012-12-20 21:18:33 ----D---- C:\Documents and Settings\T8300\Application Data\InstallShield
2012-12-20 21:18:13 ----D---- C:\Program Files\CONEXANT
2012-12-20 21:17:29 ----A---- C:\WINDOWS\system32\UCI32M57.dll
2012-12-20 21:17:29 ----A---- C:\WINDOWS\system32\mdmxsdk.dll
2012-12-20 21:17:29 ----A---- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2012-12-20 21:17:29 ----A---- C:\WINDOWS\system32\drivers\HSFHWAZL.sys
2012-12-20 21:17:29 ----A---- C:\WINDOWS\system32\drivers\HSF_DPV.sys
2012-12-20 21:17:29 ----A---- C:\WINDOWS\system32\drivers\HSF_CNXT.sys
2012-12-20 21:17:13 ----N---- C:\WINDOWS\system32\spmsgXP_2k3.dll
2012-12-20 21:17:09 ----HDC---- C:\WINDOWS\$NtUninstallWdf01009$
2012-12-20 21:17:03 ----A---- C:\WINDOWS\system32\wdfcoinstaller01009.dll
2012-12-20 21:17:03 ----A---- C:\WINDOWS\system32\tp4coin3.dll
2012-12-20 21:17:03 ----A---- C:\WINDOWS\system32\drivers\tp4track.sys
2012-12-20 21:16:42 ----A---- C:\WINDOWS\system32\drivers\splitter.sys
2012-12-20 21:16:41 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys
2012-12-20 21:16:39 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys
2012-12-20 21:16:38 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys
2012-12-20 21:16:36 ----A---- C:\WINDOWS\system32\drivers\aec.sys
2012-12-20 21:16:35 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys
2012-12-20 21:16:34 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys
2012-12-20 21:16:33 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys
2012-12-20 21:16:31 ----A---- C:\WINDOWS\system32\drivers\MSKSSRV.sys
2012-12-20 21:16:30 ----A---- C:\WINDOWS\system32\drivers\MSPQM.sys
2012-12-20 21:16:28 ----A---- C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2012-12-20 21:16:23 ----A---- C:\WINDOWS\system32\ksuser.dll
2012-12-20 21:16:23 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2012-12-20 21:16:23 ----A---- C:\WINDOWS\system32\drivers\drmk.sys
2012-12-20 21:15:50 ----HDC---- C:\WINDOWS\$NtUninstallKB970685$
2012-12-20 21:15:09 ----D---- C:\WINDOWS\system32\ReinstallBackups
2012-12-20 21:14:17 ----A---- C:\WINDOWS\system32\drivers\btwsecfl.sys
2012-12-20 21:13:11 ----A---- C:\WINDOWS\system32\drivers\smiif32.sys
2012-12-20 21:12:50 ----D---- C:\Program Files\Common Files\InstallShield
2012-12-20 21:12:50 ----A---- C:\WINDOWS\system32\tpinspm.dll
2012-12-20 21:12:50 ----A---- C:\WINDOWS\system32\ibmpmsvc.exe
2012-12-20 21:12:50 ----A---- C:\WINDOWS\system32\drivers\ibmpmdrv.sys
2012-12-20 21:12:38 ----A---- C:\WINDOWS\system32\PROUnstl.exe
2012-12-20 21:12:29 ----A---- C:\WINDOWS\system32\NicInstE.dll
2012-12-20 21:12:29 ----A---- C:\WINDOWS\system32\NicCo2.dll
2012-12-20 21:12:29 ----A---- C:\WINDOWS\system32\e1000msg.dll
2012-12-20 21:12:29 ----A---- C:\WINDOWS\system32\drivers\e1e5132.sys
2012-12-20 21:11:55 ----A---- C:\WINDOWS\system32\igxprd32.dll
2012-12-20 21:11:55 ----A---- C:\WINDOWS\system32\igxpdv32.dll
2012-12-20 21:11:55 ----A---- C:\WINDOWS\system32\igfxtray.exe
2012-12-20 21:11:55 ----A---- C:\WINDOWS\system32\igfxsrvc.dll
2012-12-20 21:11:55 ----A---- C:\WINDOWS\system32\igfxpers.exe
2012-12-20 21:11:55 ----A---- C:\WINDOWS\system32\igfxext.exe
2012-12-20 21:11:55 ----A---- C:\WINDOWS\system32\igfxexps.dll
2012-12-20 21:11:55 ----A---- C:\WINDOWS\system32\hccutils.dll
2012-12-20 21:11:55 ----A---- C:\WINDOWS\system32\drivers\igxpmp32.sys
2012-12-20 21:11:54 ----A---- C:\WINDOWS\system32\oemdspif.dll
2012-12-20 21:11:54 ----A---- C:\WINDOWS\system32\igxpgd32.dll
2012-12-20 21:11:54 ----A---- C:\WINDOWS\system32\igxpdx32.dll
2012-12-20 21:11:54 ----A---- C:\WINDOWS\system32\igfxsrvc.exe
2012-12-20 21:11:54 ----A---- C:\WINDOWS\system32\igfxress.dll
2012-12-20 21:11:54 ----A---- C:\WINDOWS\system32\igfxpph.dll
2012-12-20 21:11:54 ----A---- C:\WINDOWS\system32\igfxdo.dll
2012-12-20 21:11:54 ----A---- C:\WINDOWS\system32\igfxdev.dll
2012-12-20 21:11:54 ----A---- C:\WINDOWS\system32\igfxCoIn_v5218.dll
2012-12-20 21:11:54 ----A---- C:\WINDOWS\system32\igfxcfg.exe
2012-12-20 21:11:54 ----A---- C:\WINDOWS\system32\ig4icd32.dll
2012-12-20 21:11:54 ----A---- C:\WINDOWS\system32\ig4dev32.dll
2012-12-20 21:11:54 ----A---- C:\WINDOWS\system32\hkcmd.exe
2012-12-20 21:11:52 ----D---- C:\WINDOWS\system32\Lang
2012-12-20 21:11:52 ----A---- C:\WINDOWS\system32\igxpun.exe
2012-12-20 21:11:52 ----A---- C:\WINDOWS\system32\difxapi.dll
2012-12-20 21:11:51 ----D---- C:\Intel
2012-12-20 21:11:31 ----D---- C:\Program Files\ThinkPad
2012-12-20 20:54:03 ----A---- C:\WINDOWS\system32\wpa.bak
2012-12-20 20:53:43 ----D---- C:\WINDOWS\system32\(null)
2012-12-20 20:53:34 ----D---- C:\Program Files\Lenovo
2012-12-20 20:53:34 ----D---- C:\Program Files\Common Files\Lenovo
2012-12-20 20:53:23 ----A---- C:\WINDOWS\system32\drivers\psadd.sys
2012-12-20 20:51:41 ----RSD---- C:\WINDOWS\assembly
2012-12-20 20:51:19 ----D---- C:\WINDOWS\Microsoft.NET
2012-12-20 20:39:42 ----A---- C:\WINDOWS\system32\d3d9caps.dat
2012-12-20 20:33:05 ----D---- C:\Program Files\Google
2012-12-20 18:11:08 ----A---- C:\WINDOWS\system32\results.txt
2012-12-20 18:11:00 ----A---- C:\WINDOWS\system32\drivers\AegisP.sys
2012-12-20 18:11:00 ----A---- C:\WINDOWS\system32\AegisI5Installer.exe
2012-12-20 18:11:00 ----A---- C:\WINDOWS\AegisP.sys
2012-12-20 18:10:37 ----D---- C:\Documents and Settings\All Users\Application Data\Intel
2012-12-20 18:10:17 ----A---- C:\WINDOWS\system32\NETw4r32.dll
2012-12-20 18:10:17 ----A---- C:\WINDOWS\system32\NETw4c32.dll
2012-12-20 18:10:17 ----A---- C:\WINDOWS\system32\drivers\NETw4x32.sys
2012-12-20 18:10:16 ----DC---- C:\WINDOWS\system32\DRVSTORE
2012-12-20 18:10:14 ----D---- C:\Program Files\Intel
2012-12-20 18:04:46 ----D---- C:\Program Files\Mobile Partner
2012-12-20 17:56:30 ----A---- C:\WINDOWS\ModemLog_ZTE Proprietary USB Modem.txt
2012-12-20 17:55:55 ----D---- C:\Documents and Settings\T8300\Application Data\Tatara Systems
2012-12-20 17:55:54 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys
2012-12-20 17:55:31 ----A---- C:\WINDOWS\system32\drivers\ZTEusbser6k.sys
2012-12-20 17:55:31 ----A---- C:\WINDOWS\system32\drivers\ZTEusbnmea.sys
2012-12-20 17:55:31 ----A---- C:\WINDOWS\system32\drivers\ZTEusbnet.sys
2012-12-20 17:55:31 ----A---- C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys
2012-12-20 17:55:31 ----A---- C:\WINDOWS\system32\drivers\ZTEusbccid.sys
2012-12-20 17:55:31 ----A---- C:\WINDOWS\system32\drivers\massfilter.sys
2012-12-20 17:55:28 ----HD---- C:\Program Files\InstallShield Installation Information
2012-12-20 17:55:28 ----D---- C:\WINDOWS\massfilter
2012-12-20 17:55:17 ----D---- C:\Program Files\O2CM-CE
2012-12-20 17:55:17 ----D---- C:\Documents and Settings\All Users\Application Data\O2CM-CE
2012-12-20 17:53:52 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2012-12-20 17:49:41 ----D---- C:\Documents and Settings\T8300\Application Data\Identities
2012-12-20 17:49:39 ----HD---- C:\Program Files\Uninstall Information
2012-12-20 17:49:35 ----SD---- C:\Documents and Settings\T8300\Application Data\Microsoft
2012-12-20 17:49:35 ----ASH---- C:\Documents and Settings\T8300\Application Data\desktop.ini
2012-12-20 17:48:47 ----D---- C:\WINDOWS\SoftwareDistribution
2012-12-20 17:48:44 ----SD---- C:\WINDOWS\system32\Microsoft
2012-12-20 17:48:44 ----D---- C:\WINDOWS\Prefetch
2012-12-20 17:48:43 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-12-20 17:47:33 ----AS---- C:\WINDOWS\bootstat.dat
2012-12-20 17:44:56 ----D---- C:\WINDOWS\system32\xircom
2012-12-20 17:44:56 ----D---- C:\Program Files\xerox
2012-12-20 17:44:56 ----D---- C:\Program Files\microsoft frontpage
2012-12-20 17:44:44 ----D---- C:\WINDOWS\system32\LogFiles
2012-12-20 17:44:36 ----N---- C:\WINDOWS\system32\spmsg.dll
2012-12-20 17:44:29 ----D---- C:\WINDOWS\system32\drivers\umdf
2012-12-20 17:44:11 ----D---- C:\Program Files\Windows Media Connect 2
2012-12-20 17:44:11 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2012-12-20 17:43:48 ----RASH---- C:\MSDOS.SYS
2012-12-20 17:43:48 ----RASH---- C:\IO.SYS
2012-12-20 17:43:48 ----A---- C:\WINDOWS\control.ini
2012-12-20 17:43:48 ----A---- C:\CONFIG.SYS
2012-12-20 17:43:48 ----A---- C:\AUTOEXEC.BAT
2012-12-20 17:43:38 ----A---- C:\WINDOWS\OEWABLog.txt
2012-12-20 17:43:33 ----A---- C:\WINDOWS\system32\mapi32.dll
2012-12-20 17:42:39 ----HD---- C:\Program Files\WindowsUpdate
2012-12-20 17:42:18 ----D---- C:\WINDOWS\system32\DirectX
2012-12-20 17:42:10 ----A---- C:\WINDOWS\system32\atrace.dll
2012-12-20 17:42:08 ----A---- C:\WINDOWS\system32\desktop.ini
2012-12-20 17:42:08 ----A---- C:\WINDOWS\desktop.ini
2012-12-20 17:42:02 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2012-12-20 17:42:00 ----D---- C:\Program Files\Common Files\Services
2012-12-20 17:42:00 ----A---- C:\WINDOWS\system32\acctres.dll
2012-12-20 17:41:57 ----SD---- C:\WINDOWS\Tasks
2012-12-20 17:41:57 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2012-12-20 17:41:56 ----D---- C:\Program Files\Common Files\MSSoap
2012-12-20 17:41:51 ----D---- C:\WINDOWS\srchasst
2012-12-20 17:41:50 ----D---- C:\WINDOWS\system32\Macromed
2012-12-20 17:41:47 ----A---- C:\WINDOWS\system32\wuweb.dll
2012-12-20 17:41:47 ----A---- C:\WINDOWS\system32\wucltui.dll
2012-12-20 17:41:47 ----A---- C:\WINDOWS\system32\wuauserv.dll
2012-12-20 17:41:47 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2012-12-20 17:41:46 ----A---- C:\WINDOWS\system32\wups.dll
2012-12-20 17:41:46 ----A---- C:\WINDOWS\system32\wuaueng.dll
2012-12-20 17:41:46 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2012-12-20 17:41:46 ----A---- C:\WINDOWS\system32\wuauclt.exe
2012-12-20 17:41:46 ----A---- C:\WINDOWS\system32\wuapi.dll
2012-12-20 17:41:46 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2012-12-20 17:41:46 ----A---- C:\WINDOWS\system32\qmgr.dll
2012-12-20 17:41:46 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2012-12-20 17:41:46 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2012-12-20 17:41:46 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2012-12-20 17:41:42 ----D---- C:\Program Files\Movie Maker
2012-12-20 17:41:24 ----A---- C:\WINDOWS\system32\safrslv.dll
2012-12-20 17:41:24 ----A---- C:\WINDOWS\system32\safrdm.dll
2012-12-20 17:41:24 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2012-12-20 17:41:24 ----A---- C:\WINDOWS\system32\racpldlg.dll
2012-12-20 17:41:20 ----D---- C:\WINDOWS\system32\Restore
2012-12-20 17:41:20 ----A---- C:\WINDOWS\system32\srrstr.dll
2012-12-20 17:41:20 ----A---- C:\WINDOWS\system32\fltMc.exe
2012-12-20 17:41:20 ----A---- C:\WINDOWS\system32\fltlib.dll
2012-12-20 17:41:20 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys
2012-12-20 17:41:19 ----A---- C:\WINDOWS\system32\srsvc.dll
2012-12-20 17:41:19 ----A---- C:\WINDOWS\system32\srclient.dll
2012-12-20 17:41:19 ----A---- C:\WINDOWS\system32\mnmdd.dll
2012-12-20 17:41:19 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2012-12-20 17:41:19 ----A---- C:\WINDOWS\system32\ils.dll
2012-12-20 17:41:19 ----A---- C:\WINDOWS\system32\drivers\sr.sys
2012-12-20 17:41:18 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2012-12-20 17:41:18 ----A---- C:\WINDOWS\system32\msconf.dll
2012-12-20 17:41:18 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2012-12-20 17:41:16 ----D---- C:\Program Files\NetMeeting
2012-12-20 17:41:15 ----A---- C:\WINDOWS\system32\msoert2.dll
2012-12-20 17:41:15 ----A---- C:\WINDOWS\system32\msoeacct.dll
2012-12-20 17:41:14 ----A---- C:\WINDOWS\system32\inetres.dll
2012-12-20 17:41:14 ----A---- C:\WINDOWS\system32\inetcomm.dll
2012-12-20 17:41:12 ----D---- C:\Program Files\Outlook Express
2012-12-20 17:41:12 ----A---- C:\WINDOWS\system32\schedsvc.dll
2012-12-20 17:41:12 ----A---- C:\WINDOWS\system32\mstinit.exe
2012-12-20 17:41:12 ----A---- C:\WINDOWS\system32\mstask.dll
2012-12-20 17:41:11 ----A---- C:\WINDOWS\system32\isign32.dll
2012-12-20 17:41:11 ----A---- C:\WINDOWS\system32\inetcfg.dll
2012-12-20 17:41:11 ----A---- C:\WINDOWS\system32\icwphbk.dll
2012-12-20 17:41:11 ----A---- C:\WINDOWS\system32\icwdial.dll
2012-12-20 17:41:05 ----D---- C:\Program Files\Common Files\System
2012-12-20 17:41:02 ----D---- C:\Program Files\Internet Explorer
2012-12-20 17:40:37 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2012-12-20 17:40:24 ----D---- C:\Program Files\ComPlus Applications
2012-12-20 17:40:22 ----A---- C:\WINDOWS\vbaddin.ini
2012-12-20 17:40:22 ----A---- C:\WINDOWS\vb.ini
2012-12-20 17:40:17 ----D---- C:\WINDOWS\Registration
2012-12-20 17:40:08 ----D---- C:\Program Files\Windows Media Player
2012-12-20 17:40:08 ----D---- C:\Program Files\Online Services
2012-12-20 17:39:59 ----D---- C:\Program Files\Messenger
2012-12-20 17:39:55 ----D---- C:\Program Files\MSN Gaming Zone
2012-12-20 17:39:55 ----A---- C:\WINDOWS\system32\write.exe
2012-12-20 17:39:47 ----A---- C:\WINDOWS\system32\sndvol32.exe
2012-12-20 17:39:47 ----A---- C:\WINDOWS\system32\hticons.dll
2012-12-20 17:39:46 ----A---- C:\WINDOWS\system32\winchat.exe
2012-12-20 17:39:46 ----A---- C:\WINDOWS\system32\avwav.dll
2012-12-20 17:39:46 ----A---- C:\WINDOWS\system32\avtapi.dll
2012-12-20 17:39:46 ----A---- C:\WINDOWS\system32\avmeter.dll
2012-12-20 17:39:39 ----A---- C:\WINDOWS\system32\charmap.exe
2012-12-20 17:39:39 ----A---- C:\WINDOWS\system32\getuname.dll
2012-12-20 17:39:39 ----A---- C:\WINDOWS\system32\calc.exe
2012-12-20 17:39:38 ----A---- C:\WINDOWS\system32\winmine.exe
2012-12-20 17:39:38 ----A---- C:\WINDOWS\system32\sol.exe
2012-12-20 17:39:38 ----A---- C:\WINDOWS\system32\mshearts.exe
2012-12-20 17:39:38 ----A---- C:\WINDOWS\system32\freecell.exe
2012-12-20 17:39:37 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2012-12-20 17:39:37 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2012-12-20 17:39:37 ----A---- C:\WINDOWS\system32\tslabels.ini
2012-12-20 17:39:37 ----A---- C:\WINDOWS\system32\tskill.exe
2012-12-20 17:39:37 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2012-12-20 17:39:37 ----A---- C:\WINDOWS\system32\tscon.exe
2012-12-20 17:39:37 ----A---- C:\WINDOWS\system32\shadow.exe
2012-12-20 17:39:37 ----A---- C:\WINDOWS\system32\rwinsta.exe
2012-12-20 17:39:37 ----A---- C:\WINDOWS\system32\reset.exe
2012-12-20 17:39:37 ----A---- C:\WINDOWS\system32\regini.exe
2012-12-20 17:39:37 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2012-12-20 17:39:37 ----A---- C:\WINDOWS\system32\qwinsta.exe
2012-12-20 17:39:36 ----A---- C:\WINDOWS\system32\qappsrv.exe
2012-12-20 17:39:36 ----A---- C:\WINDOWS\system32\msg.exe
2012-12-20 17:39:36 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2012-12-20 17:39:36 ----A---- C:\WINDOWS\system32\logoff.exe
2012-12-20 17:39:36 ----A---- C:\WINDOWS\system32\cdmodem.dll
2012-12-20 17:39:30 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2012-12-20 17:39:19 ----D---- C:\Program Files\MSN
2012-12-20 17:39:18 ----A---- C:\WINDOWS\system32\sndrec32.exe
2012-12-20 17:39:18 ----A---- C:\WINDOWS\system32\mplay32.exe
2012-12-20 17:39:18 ----A---- C:\WINDOWS\system32\hypertrm.dll
2012-12-20 17:39:18 ----A---- C:\WINDOWS\system32\accwiz.exe
2012-12-20 17:39:17 ----D---- C:\Program Files\Windows NT
2012-12-20 17:39:17 ----A---- C:\WINDOWS\system32\spider.exe
2012-12-20 17:39:17 ----A---- C:\WINDOWS\system32\mspaint.exe
2012-12-20 17:39:17 ----A---- C:\WINDOWS\system32\clipbrd.exe
2012-12-20 17:39:16 ----A---- C:\WINDOWS\system32\tsgqec.dll
2012-12-20 17:39:16 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2012-12-20 17:39:16 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys
2012-12-20 17:39:16 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys
2012-12-20 17:39:16 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys
2012-12-20 17:39:15 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2012-12-20 17:39:15 ----A---- C:\WINDOWS\system32\mstscax.dll
2012-12-20 17:39:15 ----A---- C:\WINDOWS\system32\mstsc.exe
2012-12-20 17:39:15 ----A---- C:\WINDOWS\system32\aaclient.dll
2012-12-20 17:39:14 ----A---- C:\WINDOWS\system32\termsrv.dll
2012-12-20 17:39:14 ----A---- C:\WINDOWS\system32\sessmgr.exe
2012-12-20 17:39:14 ----A---- C:\WINDOWS\system32\remotepg.dll
2012-12-20 17:39:14 ----A---- C:\WINDOWS\system32\rdshost.exe
2012-12-20 17:39:14 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2012-12-20 17:39:14 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2012-12-20 17:39:14 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2012-12-20 17:39:14 ----A---- C:\WINDOWS\system32\rdpclip.exe
2012-12-20 17:39:14 ----A---- C:\WINDOWS\system32\rdchost.dll
2012-12-20 17:39:14 ----A---- C:\WINDOWS\system32\qprocess.exe
2012-12-20 17:39:14 ----A---- C:\WINDOWS\system32\icaapi.dll
2012-12-20 17:39:13 ----D---- C:\WINDOWS\system32\MsDtc
2012-12-20 17:39:13 ----A---- C:\WINDOWS\system32\mtxoci.dll
2012-12-20 17:39:13 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2012-12-20 17:39:13 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2012-12-20 17:39:13 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2012-12-20 17:39:12 ----A---- C:\WINDOWS\system32\xolehlp.dll
2012-12-20 17:39:12 ----A---- C:\WINDOWS\system32\msdtctm.dll
2012-12-20 17:39:12 ----A---- C:\WINDOWS\system32\msdtclog.dll
2012-12-20 17:39:12 ----A---- C:\WINDOWS\system32\msdtc.exe
2012-12-20 17:39:11 ----D---- C:\WINDOWS\system32\Com
2012-12-20 17:39:11 ----A---- C:\WINDOWS\system32\stclient.dll
2012-12-20 17:39:11 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2012-12-20 17:39:11 ----A---- C:\WINDOWS\system32\mtxex.dll
2012-12-20 17:39:11 ----A---- C:\WINDOWS\system32\mtxdm.dll
2012-12-20 17:39:11 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2012-12-20 17:39:11 ----A---- C:\WINDOWS\system32\comrepl.dll
2012-12-20 17:39:11 ----A---- C:\WINDOWS\system32\comaddin.dll
2012-12-20 17:39:11 ----A---- C:\WINDOWS\system32\colbact.dll
2012-12-20 17:39:10 ----A---- C:\WINDOWS\system32\comsvcs.dll
2012-12-20 17:39:10 ----A---- C:\WINDOWS\system32\clbcatex.dll
2012-12-20 17:39:10 ----A---- C:\WINDOWS\system32\catsrvut.dll
2012-12-20 17:39:10 ----A---- C:\WINDOWS\system32\catsrvps.dll
2012-12-20 17:39:10 ----A---- C:\WINDOWS\system32\catsrv.dll
2012-12-20 17:39:09 ----A---- C:\WINDOWS\system32\comuid.dll
2012-12-20 17:39:09 ----A---- C:\WINDOWS\system32\comsnap.dll
2012-12-20 17:39:09 ----A---- C:\WINDOWS\system32\clbcatq.dll
2012-12-20 17:39:03 ----A---- C:\WINDOWS\system32\servdeps.dll
2012-12-20 17:39:03 ----A---- C:\WINDOWS\system32\mmfutil.dll
2012-12-20 17:39:03 ----A---- C:\WINDOWS\system32\licwmi.dll
2012-12-20 17:39:02 ----A---- C:\WINDOWS\system32\cmprops.dll
2012-12-20 17:39:00 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys
2012-12-20 17:38:59 ----A---- C:\WINDOWS\system32\drivers\termdd.sys
2012-12-20 17:37:41 ----A---- C:\WINDOWS\system32\h323log.txt
2012-12-20 17:35:08 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2012-12-20 17:34:29 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2012-12-20 17:34:26 ----A---- C:\WINDOWS\system32\drivers\compbatt.sys
2012-12-20 17:34:25 ----A---- C:\WINDOWS\system32\drivers\CmBatt.sys
2012-12-20 17:34:25 ----A---- C:\WINDOWS\system32\drivers\battc.sys
2012-12-20 17:34:23 ----A---- C:\WINDOWS\system32\tp4res.dll
2012-12-20 17:34:23 ----A---- C:\WINDOWS\system32\drivers\TwoTrack.sys
2012-12-20 17:34:21 ----A---- C:\WINDOWS\system32\tp4.dll
2012-12-20 17:34:20 ----A---- C:\WINDOWS\system32\tp4mon.exe
2012-12-20 17:33:41 ----A---- C:\WINDOWS\system32\drivers\enum1394.sys
2012-12-20 17:33:26 ----A---- C:\WINDOWS\system32\usbui.dll
2012-12-20 17:32:24 ----A---- C:\WINDOWS\imsins.BAK
2012-12-20 17:32:22 ----SHD---- C:\WINDOWS\Installer
2012-12-20 17:32:22 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-12-20 17:32:21 ----D---- C:\Program Files\Common Files\ODBC
2012-12-20 17:32:21 ----A---- C:\WINDOWS\ODBCINST.INI
2012-12-20 17:32:18 ----D---- C:\Program Files\Common Files\SpeechEngines
2012-12-20 17:32:17 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-12-20 17:32:17 ----D---- C:\Program Files\Common Files
2012-12-20 17:32:17 ----D---- C:\Program Files
2012-12-20 17:32:09 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2012-12-20 17:32:09 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2012-12-20 17:32:09 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2012-12-20 17:32:07 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2012-12-20 17:32:07 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2012-12-20 17:32:07 ----RA---- C:\WINDOWS\system32\kbdur.dll
2012-12-20 17:32:07 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2012-12-20 17:32:07 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2012-12-20 17:32:07 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2012-12-20 17:32:07 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2012-12-20 17:32:07 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2012-12-20 17:32:06 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2012-12-20 17:32:06 ----RA---- C:\WINDOWS\system32\kbdru.dll
2012-12-20 17:32:06 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2012-12-20 17:32:06 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2012-12-20 17:32:05 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2012-12-20 17:32:05 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2012-12-20 17:32:05 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2012-12-20 17:32:05 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2012-12-20 17:32:05 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2012-12-20 17:32:05 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2012-12-20 17:32:05 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2012-12-20 17:32:03 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2012-12-20 17:32:03 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2012-12-20 17:32:03 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2012-12-20 17:32:03 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2012-12-20 17:32:03 ----RA---- C:\WINDOWS\system32\kbdest.dll
2012-12-20 17:32:02 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2012-12-20 17:32:02 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2012-12-20 17:32:02 ----RA---- C:\WINDOWS\system32\kbdro.dll
2012-12-20 17:32:02 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2012-12-20 17:32:02 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2012-12-20 17:32:02 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2012-12-20 17:32:02 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2012-12-20 17:32:02 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2012-12-20 17:32:02 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2012-12-20 17:32:02 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2012-12-20 17:32:02 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2012-12-20 17:32:02 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2012-12-20 17:32:01 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2012-12-20 17:31:57 ----A---- C:\WINDOWS\system32\spxcoins.dll
2012-12-20 17:31:57 ----A---- C:\WINDOWS\system32\irclass.dll
2012-12-20 17:31:57 ----A---- C:\WINDOWS\system32\dgsetup.dll
2012-12-20 17:31:57 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2012-12-20 17:31:56 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2012-12-20 17:31:54 ----A---- C:\WINDOWS\TASKMAN.EXE
2012-12-20 17:31:54 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2012-12-20 17:31:54 ----A---- C:\WINDOWS\system32\batt.dll
2012-12-20 17:31:54 -------- C:\WINDOWS\system32\CONFIG.TMP
2012-12-20 17:31:53 ----A---- C:\WINDOWS\system32\storprop.dll
2012-12-20 17:31:53 ----A---- C:\WINDOWS\NOTEPAD.EXE
2012-12-20 17:31:43 ----RA---- C:\WINDOWS\SET2C.tmp
2012-12-20 17:31:43 ----RA---- C:\WINDOWS\SET2B.tmp
2012-12-20 17:31:43 ----RA---- C:\WINDOWS\SET2A.tmp
2012-12-20 17:31:43 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2012-12-20 17:31:42 ----RA---- C:\WINDOWS\SET29.tmp
2012-12-20 17:31:39 ----RA---- C:\WINDOWS\SET8.tmp
2012-12-20 17:31:37 ----RA---- C:\WINDOWS\SET4.tmp
2012-12-20 17:31:35 ----RA---- C:\WINDOWS\SET3.tmp
2012-12-20 17:31:30 ----D---- C:\WINDOWS\system32\CatRoot2
2012-12-20 17:31:30 ----D---- C:\WINDOWS\system32\CatRoot
2012-12-20 17:31:25 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2012-12-20 17:31:06 ----A---- C:\WINDOWS\setuplog.txt
2012-12-20 17:31:02 ----D---- C:\Documents and Settings
2012-12-20 17:31:01 ----SHD---- C:\System Volume Information
2012-12-20 17:31:01 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2012-12-20 17:30:07 ----SH---- C:\boot.ini
2012-12-20 17:25:00 ----SD---- C:\WINDOWS\Downloaded Program Files
2012-12-20 17:25:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-12-20 17:25:00 ----RSD---- C:\WINDOWS\Fonts
2012-12-20 17:25:00 ----RD---- C:\WINDOWS\Web
2012-12-20 17:25:00 ----HD---- C:\WINDOWS\inf
2012-12-20 17:25:00 ----D---- C:\WINDOWS\WinSxS
2012-12-20 17:25:00 ----D---- C:\WINDOWS\WBEM
2012-12-20 17:25:00 ----D---- C:\WINDOWS\twain_32
2012-12-20 17:25:00 ----D---- C:\WINDOWS\Temp
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\wins
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\wbem
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\usmt
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\spool
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\ShellExt
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\Setup
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\scripting
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\ras
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\oobe
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\npp
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\mui
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\inetsrv
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\IME
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\icsxml
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\ias
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\export
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\en-US
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\en
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\drivers\etc
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\drivers\disdn
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\drivers
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\dhcp
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\config
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\3com_dmi
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\3076
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\2052
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\1054
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\1042
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\1041
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\1037
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\1033
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\1031
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\1028
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32\1025
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system32
2012-12-20 17:25:00 ----D---- C:\WINDOWS\system
2012-12-20 17:25:00 ----D---- C:\WINDOWS\security
2012-12-20 17:25:00 ----D---- C:\WINDOWS\Resources
2012-12-20 17:25:00 ----D---- C:\WINDOWS\repair
2012-12-20 17:25:00 ----D---- C:\WINDOWS\Provisioning
2012-12-20 17:25:00 ----D---- C:\WINDOWS\pchealth
2012-12-20 17:25:00 ----D---- C:\WINDOWS\PeerNet
2012-12-20 17:25:00 ----D---- C:\WINDOWS\Offline Web Pages
2012-12-20 17:25:00 ----D---- C:\WINDOWS\Network Diagnostic
2012-12-20 17:25:00 ----D---- C:\WINDOWS\mui
2012-12-20 17:25:00 ----D---- C:\WINDOWS\msapps
2012-12-20 17:25:00 ----D---- C:\WINDOWS\msagent
2012-12-20 17:25:00 ----D---- C:\WINDOWS\Media
2012-12-20 17:25:00 ----D---- C:\WINDOWS\L2Schemas
2012-12-20 17:25:00 ----D---- C:\WINDOWS\java
2012-12-20 17:25:00 ----D---- C:\WINDOWS\ime
2012-12-20 17:25:00 ----D---- C:\WINDOWS\Help
2012-12-20 17:25:00 ----D---- C:\WINDOWS\ehome
2012-12-20 17:25:00 ----D---- C:\WINDOWS\Driver Cache
2012-12-20 17:25:00 ----D---- C:\WINDOWS\Debug
2012-12-20 17:25:00 ----D---- C:\WINDOWS\Cursors
2012-12-20 17:25:00 ----D---- C:\WINDOWS\Connection Wizard
2012-12-20 17:25:00 ----D---- C:\WINDOWS\Config
2012-12-20 17:25:00 ----D---- C:\WINDOWS\AppPatch
2012-12-20 17:25:00 ----D---- C:\WINDOWS\addins
2012-12-20 17:25:00 ----D---- C:\WINDOWS
2012-12-20 17:24:59 ----ASH---- C:\pagefile.sys
2012-12-14 20:45:52 ----A---- C:\WINDOWS\system32\drivers\inspect.sys
2012-12-14 20:45:52 ----A---- C:\WINDOWS\system32\drivers\cmdhlp.sys
2012-12-14 20:45:50 ----A---- C:\WINDOWS\system32\drivers\cmdGuard.sys
2012-12-14 20:45:50 ----A---- C:\WINDOWS\system32\drivers\cmderd.sys
2012-12-14 20:45:32 ----A---- C:\WINDOWS\system32\cmdcsr.dll
2012-12-14 20:45:30 ----A---- C:\WINDOWS\system32\guard32.dll
2012-12-14 20:45:14 ----A---- C:\WINDOWS\system32\cmdvrt32.dll

======List of files/folders modified in the last 1 month======

2012-12-26 14:25:39 ----A---- C:\WINDOWS\system.ini
2012-12-25 17:34:54 ----N---- C:\WINDOWS\win.ini
2012-12-20 17:43:22 ----ASH---- C:\WINDOWS\fonts\desktop.ini
2012-12-16 12:23:59 ----A---- C:\WINDOWS\system32\atmfd.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 Inspect;COMODO Internet Security Firewall Driver; C:\WINDOWS\System32\DRIVERS\inspect.sys [2012-12-14 98904]
R0 ohci1394;OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 Shockprf;Shockprf; C:\WINDOWS\System32\DRIVERS\Apsx86.sys [2012-07-23 129384]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2012-12-25 717296]
R0 TPDIGIMN;TPDIGIMN; C:\WINDOWS\System32\DRIVERS\ApsHM86.sys [2012-09-06 20328]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\WINDOWS\System32\DRIVERS\cmderd.sys [2012-12-14 18688]
R1 cmdGuard;COMODO Internet Security Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2012-12-14 583912]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2012-12-14 32976]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2009-11-16 96408]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 lenovo.smi;Lenovo System Interface Driver; C:\WINDOWS\system32\DRIVERS\smiif32.sys [2010-09-07 13680]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.7.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2012-12-20 21361]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2010-06-02 19384]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2007-11-20 12288]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2008-01-10 334848]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2007-07-13 94976]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2010-06-02 993464]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2010-06-02 217016]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2010-01-13 1730272]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2012-04-11 35240]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NETwLx32; Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETwLx32.sys [2010-10-07 6609920]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\WINDOWS\system32\DRIVERS\psadd.sys [2007-02-19 21376]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2009-05-14 80384]
R3 Tp4Track;PS/2 TrackPoint Driver; C:\WINDOWS\system32\DRIVERS\tp4track.sys [2011-11-01 24872]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2010-06-02 738360]
S3 a9rm0kq1;a9rm0kq1; C:\WINDOWS\system32\drivers\a9rm0kq1.sys []
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys []
S3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys []
S3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys []
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys []
S3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2009-06-18 234496]
S3 massfilter;ZTE Mass Storage Filter Driver; C:\WINDOWS\system32\drivers\massfilter.sys [2009-04-27 9728]
S3 NETw4x32;Intel(R) Wireless WiFi Link Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw4x32.sys [2007-11-26 2236544]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 TwoTrack;IBM PS/2 TrackPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\TwoTrack.sys [2001-08-17 11520]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 ZTEusbmdm6k;ZTE Proprietary USB Driver; C:\WINDOWS\system32\DRIVERS\ZTEusbmdm6k.sys [2009-07-21 105088]
S3 ZTEusbnet;ZTE USB-NDIS miniport; C:\WINDOWS\system32\DRIVERS\ZTEusbnet.sys [2009-07-21 114688]
S3 ZTEusbnmea;ZTE NMEA Port; C:\WINDOWS\system32\DRIVERS\ZTEusbnmea.sys [2009-07-21 105088]
S3 ZTEusbser6k;ZTE Diagnostic Port; C:\WINDOWS\system32\DRIVERS\ZTEusbser6k.sys [2009-07-21 105088]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2012-12-14 2259392]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-11-16 735960]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2007-11-19 794624]
R2 IBMPMSVC;Lenovo PM Service; C:\WINDOWS\system32\ibmpmsvc.exe [2012-04-11 39248]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2012-12-25 170408]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2007-11-19 483328]
R2 S24EventMonitor;Intel(R) PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2007-11-19 1183744]
R2 SUService;System Update; C:\Program Files\Lenovo\System Update\SUService.exe [2011-07-25 28672]
R2 ThinkVantage Registry Monitor Service;ThinkVantage Registry Monitor Service; C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe [2007-09-26 644408]
R2 TVT Scheduler;TVT Scheduler; C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe [2008-03-04 1122304]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2012-12-14 127184]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 20680]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 TPHDEXLGSVC;ThinkPad HDD APS Logging Service; C:\WINDOWS\System32\TPHDEXLG.exe [2012-09-06 39304]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]

-----------------EOF-----------------


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 26.12.2012 15:48

vidím že si aktualizoval systém použi
sprav scan combofixom http://www.bleepingcomputer.com/download/combofix/ spusť dávaj yes ok agree ako ťa combofix vyzve keď skonči vybehne poznámkový blok vlož ho sem budeš ho mať na C:combofix.txt


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 18.06.08
Prihlásený: 04.05.13
Príspevky: 19
Témy: 1
Príspevok NapísalOffline : 20.04.2013 1:18

Logfile of random's system information tool 1.08 (written by random/random)
Run by T8300 at 2013-04-20 00:15:11
Microsoft Windows XP Professional Service Pack 3
System drive C: has 42 GB (81%) free of 53 GB
Total RAM: 2006 MB (65% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:15:16, on 20.4.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17115)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\IObit\IObit Malware Fighter\IMF.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\T8300\Desktop\RSIT-1.06.exe
C:\Program Files\trend micro\T8300.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.search.yahoo.com?type=800236&fr=spigot-yhp-ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files\IObit Apps Toolbar\IE\7.0\iobitappsToolbarIE.dll
O2 - BHO: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files\IObit Apps Toolbar\IE\7.0\iobitappsToolbarIE.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files\IObit Apps Toolbar\IE\7.0\iobitappsToolbarIE.dll
O4 - HKLM\..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
O4 - HKLM\..\Run: [IObit Malware Fighter] "C:\Program Files\IObit\IObit Malware Fighter\IMF.exe" /autostart
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

--
End of file - 7732 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]
IObit Apps Toolbar - C:\Program Files\IObit Apps Toolbar\IE\7.0\iobitappsToolbarIE.dll [2013-02-23 1352512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2012-09-23 72336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-12-25 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-12-25 170416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]
{03EB0E9C-7A91-4381-A220-9B52B641CDB1} - IObit Apps Toolbar - C:\Program Files\IObit Apps Toolbar\IE\7.0\iobitappsToolbarIE.dll [2013-02-23 1352512]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2013-04-15 3012816]
""= []
"IObit Malware Fighter"=C:\Program Files\IObit\IObit Malware Fighter\IMF.exe [2012-12-25 4474832]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2008-04-23 483328]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23 926896]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare Ultimate]
C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe /AutoStart []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-12-29 687560]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe /hide /waitservice []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe [2010-02-05 173592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe [2010-02-05 141336]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LenovoAutoScrollUtility]
C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe [2011-10-20 101440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPMailChecker]
C:\PROGRA~1\THINKV~1\PrdCtr\LPMLCHK.exe [2009-07-23 124248]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPManager]
C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe [2009-07-23 185688]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\WINDOWS\system32\igfxpers.exe [2010-02-05 142360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2007-08-08 831488]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
C:\Program Files\Analog Devices\Core\smax4pnp.exe [2008-04-24 1036288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPKMAPHELPER]
C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe [2007-01-09 868352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPKMAPMN]
C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe [2007-09-21 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TpShocks]
C:\WINDOWS\system32\TpShocks.exe [2012-09-20 186248]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrackPointSrv]
C:\Program Files\Lenovo\TrackPoint\tp4serv.exe [2011-11-01 95264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVT Scheduler Proxy]
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe [2008-03-04 487424]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2013-01-05 25214]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
C:\PROGRA~1\COMMON~1\AUTODE~1\ACSTAR~1.EXE [2006-03-05 11000]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\ThinkPad\BLUETO~1\BTTray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
C:\PROGRA~1\DIGITA~1\DLG.exe [2006-11-03 50688]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^T8300^Start Menu^Programs^Startup^Lingea Update Center.lnk]
C:\PROGRA~1\COMMON~1\LINGEA~1\luc.exe [2010-04-11 275736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3
"TVT Scheduler"=2
"TpKmpSVC"=2
"TPHKSVC"=2
"TPHKLOAD"=2
"TPHDEXLGSVC"=3
"ThinkVantage Registry Monitor Service"=2
"SUService"=2
"SkypeUpdate"=2
"ose"=3
"LENOVO.MICMUTE"=2
"JavaQuickStarterService"=2
"IBMPMSVC"=2
"ekrn"=2
"EhttpSrv"=3
"UPS"=3
"Themes"=2
"TermService"=3
"LmHosts"=2
"srservice"=2
"SCardSvr"=3
"RemoteRegistry"=2
"RDSessMgr"=3
"mnmsrvc"=3
"Netlogon"=3
"CiSvc"=3
"ImapiService"=3
"helpsvc"=2
"FastUserSwitchingCompatibility"=3
"ERSvc"=2
"MSDTC"=3
"CryptSvc"=3
"Browser"=2
"BITS"=3
"wuauserv"=2
"ALG"=3

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2010-01-13 205824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======File associations======

.scr - open - "C:\WINDOWS\system32\NOTEPAD.EXE" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2013-04-20 00:15:11 ----D---- C:\rsit
2013-04-19 23:16:50 ----D---- C:\Documents and Settings\All Users\Application Data\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-04-18 19:58:20 ----D---- C:\Documents and Settings\All Users\Application Data\{D76294E6-03B8-4971-AF2E-3F846161A690}
2013-04-18 19:58:18 ----D---- C:\Documents and Settings\T8300\Application Data\Apple Computer
2013-04-18 19:58:16 ----D---- C:\Documents and Settings\All Users\Application Data\{5A85B23A-4B58-47D1-9B9C-DFBD7866099F}
2013-04-18 19:57:04 ----D---- C:\Documents and Settings\T8300\Application Data\Search Settings
2013-04-18 19:56:58 ----D---- C:\Program Files\IObit Apps Toolbar
2013-04-18 19:56:58 ----D---- C:\Program Files\Common Files\Spigot
2013-04-18 19:56:58 ----D---- C:\Program Files\Application Updater
2013-04-18 19:51:27 ----D---- C:\Documents and Settings\All Users\Application Data\IObit
2013-04-18 19:51:26 ----D---- C:\Documents and Settings\T8300\Application Data\IObit
2013-04-18 19:51:22 ----D---- C:\Program Files\IObit
2013-04-12 19:04:17 ----D---- C:\Program Files\Mozilla Firefox
2013-03-24 12:40:50 ----D---- C:\Program Files\AnswerWorks 4.0
2013-03-24 12:38:51 ----D---- C:\Program Files\AutoCAD 2007
2013-03-24 12:38:51 ----D---- C:\Documents and Settings\T8300\Application Data\Autodesk
2013-03-24 12:38:51 ----D---- C:\Documents and Settings\All Users\Application Data\Autodesk
2013-03-24 12:36:32 ----D---- C:\Program Files\Common Files\Autodesk Shared
2013-03-24 12:36:29 ----D---- C:\Program Files\Autodesk
2013-03-24 12:36:26 ----A---- C:\WINDOWS\system32\d3dx9_27.dll

======List of files/folders modified in the last 1 months======

2013-04-20 00:15:15 ----D---- C:\Program Files\trend micro
2013-04-19 23:26:40 ----D---- C:\WINDOWS\system32\CatRoot2
2013-04-19 23:25:53 ----SHD---- C:\WINDOWS\Installer
2013-04-19 23:16:54 ----SHD---- C:\System Volume Information
2013-04-19 23:16:54 ----D---- C:\WINDOWS\system32\Restore
2013-04-19 23:16:34 ----SD---- C:\WINDOWS\Tasks
2013-04-19 23:16:03 ----D---- C:\WINDOWS\Temp
2013-04-18 21:58:25 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-04-18 21:10:58 ----N---- C:\boot.ini
2013-04-18 21:10:58 ----A---- C:\WINDOWS\win.ini
2013-04-18 21:10:58 ----A---- C:\WINDOWS\system.ini
2013-04-18 19:56:58 ----D---- C:\Program Files\Common Files
2013-04-18 19:56:58 ----D---- C:\Program Files
2013-04-18 19:51:23 ----D---- C:\WINDOWS\Prefetch
2013-04-18 19:40:21 ----A---- C:\WINDOWS\wincmd.ini
2013-04-18 19:29:33 ----D---- C:\WINDOWS
2013-04-18 19:23:54 ----D---- C:\Documents and Settings\All Users\Application Data\ESET
2013-04-18 19:23:48 ----A---- C:\WINDOWS\ntbtlog.txt
2013-04-18 19:23:47 ----HD---- C:\WINDOWS\inf
2013-04-18 19:04:53 ----D---- C:\WINDOWS\pss
2013-04-18 18:50:37 ----D---- C:\WINDOWS\system32
2013-04-17 20:21:02 ----D---- C:\Documents and Settings\T8300\Application Data\Skype
2013-04-15 18:38:37 ----A---- C:\WINDOWS\system32\guard32.dll
2013-04-15 18:38:37 ----A---- C:\WINDOWS\system32\cmdcsr.dll
2013-04-15 18:38:25 ----A---- C:\WINDOWS\system32\cmdvrt32.dll
2013-04-15 18:38:24 ----A---- C:\WINDOWS\system32\cmdkbd32.dll
2013-04-13 07:04:29 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-03-31 07:24:13 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2013-03-24 12:41:29 ----RSD---- C:\WINDOWS\assembly
2013-03-24 12:41:29 ----D---- C:\WINDOWS\WinSxS
2013-03-24 12:40:58 ----D---- C:\Program Files\Microsoft Office
2013-03-24 12:40:51 ----RSD---- C:\WINDOWS\Fonts
2013-03-24 12:40:48 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-03-24 12:40:17 ----D---- C:\WINDOWS\Help
2013-03-24 12:40:05 ----SD---- C:\WINDOWS\Downloaded Program Files
2013-03-24 12:36:28 ----D---- C:\WINDOWS\system32\DirectX
2013-03-24 12:36:27 ----D---- C:\WINDOWS\Microsoft.NET

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 Inspect;COMODO Internet Security Firewall Driver; C:\WINDOWS\System32\DRIVERS\inspect.sys [2013-04-18 99392]
R0 ohci1394;OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 Shockprf;Shockprf; C:\WINDOWS\System32\DRIVERS\Apsx86.sys [2012-07-23 129384]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2012-12-25 717296]
R0 TPDIGIMN;TPDIGIMN; C:\WINDOWS\System32\DRIVERS\ApsHM86.sys [2012-09-06 20328]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\WINDOWS\System32\DRIVERS\cmderd.sys [2013-04-15 18528]
R1 cmdGuard;COMODO Internet Security Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2013-04-15 592384]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2013-04-15 32816]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 lenovo.smi;Lenovo System Interface Driver; C:\WINDOWS\system32\DRIVERS\smiif32.sys [2010-09-07 13680]
R1 Smapint;Smapint; C:\WINDOWS\System32\drivers\Smapint.sys [2006-10-02 14848]
R1 TDSMAPI;TDSMAPI; C:\WINDOWS\System32\drivers\TDSMAPI.SYS [2006-10-02 9343]
R1 TPHKDRV;TPHKDRV; C:\WINDOWS\system32\DRIVERS\TPHKDRV.sys [2008-05-12 17844]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.7.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2012-12-20 21361]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2010-06-02 19384]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2007-11-20 12288]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2008-04-24 308736]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2008-04-24 103424]
R3 FileMonitor;FileMonitor; \??\C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys []
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2010-06-02 993464]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2010-06-02 217016]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2010-01-13 1730272]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2012-04-11 35240]
R3 NETwLx32; Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETwLx32.sys [2010-10-07 6609920]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\WINDOWS\system32\DRIVERS\psadd.sys [2007-02-19 21376]
R3 RegFilter;RegFilter; \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\regfilter.sys []
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2009-05-14 80384]
R3 Tp4Track;PS/2 TrackPoint Driver; C:\WINDOWS\system32\DRIVERS\tp4track.sys [2011-11-01 24872]
R3 UrlFilter;UrlFilter; \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\UrlFilter.sys []
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2010-06-02 738360]
S3 a5466hx6;a5466hx6; C:\WINDOWS\system32\drivers\a5466hx6.sys []
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys []
S3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys []
S3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys []
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys []
S3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2009-06-18 234496]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 massfilter;ZTE Mass Storage Filter Driver; C:\WINDOWS\system32\drivers\massfilter.sys [2009-04-27 9728]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 NETw4x32;Intel(R) Wireless WiFi Link Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw4x32.sys [2007-11-27 2236544]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 TwoTrack;IBM PS/2 TrackPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\TwoTrack.sys [2001-08-17 11520]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 ZTEusbmdm6k;ZTE Proprietary USB Driver; C:\WINDOWS\system32\DRIVERS\ZTEusbmdm6k.sys [2009-07-21 105088]
S3 ZTEusbnet;ZTE USB-NDIS miniport; C:\WINDOWS\system32\DRIVERS\ZTEusbnet.sys [2009-07-21 114688]
S3 ZTEusbnmea;ZTE NMEA Port; C:\WINDOWS\system32\DRIVERS\ZTEusbnmea.sys [2009-07-21 105088]
S3 ZTEusbser6k;ZTE Diagnostic Port; C:\WINDOWS\system32\DRIVERS\ZTEusbser6k.sys [2009-07-21 105088]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2013-02-23 805752]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2013-04-15 4443912]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2007-11-19 794624]
R2 IMFservice;IMF Service; C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe [2012-01-09 821592]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2007-11-19 483328]
R2 S24EventMonitor;Intel(R) PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2007-11-19 1183744]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2012-12-26 69632]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2013-03-24 77944]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2013-04-15 127184]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-04-12 115608]
S4 IBMPMSVC;Lenovo PM Service; C:\WINDOWS\system32\ibmpmsvc.exe [2012-04-11 39248]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2012-12-25 170408]
S4 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2011-07-12 101736]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-01-08 161536]
S4 SUService;System Update; C:\Program Files\Lenovo\System Update\SUService.exe [2011-07-26 28672]
S4 ThinkVantage Registry Monitor Service;ThinkVantage Registry Monitor Service; C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe [2007-09-26 644408]
S4 TPHDEXLGSVC;ThinkPad HDD APS Logging Service; C:\WINDOWS\System32\TPHDEXLG.exe [2012-09-06 39304]
S4 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2011-07-12 131432]
S4 TPHKSVC;On Screen Display; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2011-07-12 142696]
S4 TpKmpSVC;IBM KCU Service; C:\WINDOWS\system32\TpKmpSVC.exe [2006-06-29 32768]
S4 TVT Scheduler;TVT Scheduler; C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe [2008-03-04 1122304]
S4 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]

-----------------EOF-----------------


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 18.06.08
Prihlásený: 04.05.13
Príspevky: 19
Témy: 1
Príspevok NapísalOffline : 20.04.2013 8:34

ComboFix 13-04-20.01 - T8300 20.04.2013 7:00.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2006.1396 [GMT 1:00]
Running from: c:\documents and settings\T8300\Desktop\ComboFix.exe
FW: COMODO Firewall *Disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\_000009_.tmp.dll
.
.
((((((((((((((((((((((((( Files Created from 2013-03-20 to 2013-04-20 )))))))))))))))))))))))))))))))
.
.
2013-04-19 22:25 . 2013-04-19 22:25 388096 ----a-r- c:\documents and settings\T8300\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-04-18 18:15 . 2013-04-18 18:15 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2013-03-24 11:40 . 2013-03-24 11:40 -------- d-----w- c:\program files\AnswerWorks 4.0
2013-03-24 11:38 . 2013-03-24 11:48 -------- d-----w- c:\documents and settings\T8300\Application Data\Autodesk
2013-03-24 11:38 . 2013-03-24 11:41 -------- d-----w- c:\program files\AutoCAD 2007
2013-03-24 11:38 . 2013-03-24 11:38 -------- d-----w- c:\documents and settings\T8300\Local Settings\Application Data\Autodesk
2013-03-24 11:38 . 2013-03-24 11:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk
2013-03-24 11:36 . 2013-03-24 11:41 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2013-03-24 11:36 . 2013-03-24 11:36 -------- d-----w- c:\program files\Autodesk
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-18 17:02 . 2012-12-14 20:45 99392 ----a-w- c:\windows\system32\drivers\inspect.sys
2013-04-15 17:38 . 2012-12-14 20:45 32816 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2013-04-15 17:38 . 2012-12-14 20:45 592384 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2013-04-15 17:38 . 2012-12-14 20:45 18528 ----a-w- c:\windows\system32\drivers\cmderd.sys
2013-04-15 17:38 . 2012-12-14 20:45 35488 ----a-w- c:\windows\system32\cmdcsr.dll
2013-04-15 17:38 . 2012-12-14 20:45 348584 ----a-w- c:\windows\system32\guard32.dll
2013-04-15 17:38 . 2012-12-14 20:45 276688 ----a-w- c:\windows\system32\cmdvrt32.dll
2013-04-15 17:38 . 2012-09-04 19:07 40656 ----a-w- c:\windows\system32\cmdkbd32.dll
2013-04-12 18:04 . 2013-04-12 18:04 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-07-18 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{03EB0E9C-7A91-4381-A220-9B52B641CDB1}"= "c:\program files\IObit Apps Toolbar\IE\7.0\iobitappsToolbarIE.dll" [2013-02-23 1352512]
.
[HKEY_CLASSES_ROOT\clsid\{03eb0e9c-7a91-4381-a220-9b52b641cdb1}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]
2013-02-23 18:17 1352512 ----a-w- c:\program files\IObit Apps Toolbar\IE\7.0\iobitappsToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{03EB0E9C-7A91-4381-A220-9B52B641CDB1}"= "c:\program files\IObit Apps Toolbar\IE\7.0\iobitappsToolbarIE.dll" [2013-02-23 1352512]
.
[HKEY_CLASSES_ROOT\clsid\{03eb0e9c-7a91-4381-a220-9b52b641cdb1}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cistray.exe" [2013-04-15 3012816]
"IObit Malware Fighter"="c:\program files\IObit\IObit Malware Fighter\IMF.exe" [2012-12-25 4474832]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /k:D *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^T8300^Start Menu^Programs^Startup^Lingea Update Center.lnk]
path=c:\documents and settings\T8300\Start Menu\Programs\Startup\Lingea Update Center.lnk
backup=c:\windows\pss\Lingea Update Center.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2008-04-23 02:08 483328 ----a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-09-23 20:43 926896 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 04:42 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2008-12-29 10:40 687560 ----a-w- c:\program files\DAEMON Tools Lite\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2010-02-05 16:13 173592 ----a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2010-02-05 16:13 141336 ----a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LenovoAutoScrollUtility]
2011-10-20 10:58 101440 ----a-w- c:\program files\Lenovo\VIRTSCRL\virtscrl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPMailChecker]
2009-07-23 03:11 124248 ------w- c:\progra~1\THINKV~1\PrdCtr\LPMLCHK.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPManager]
2009-07-23 03:11 185688 ------w- c:\progra~1\THINKV~1\PrdCtr\LPMGR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2010-02-05 16:13 142360 ----a-w- c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
2007-08-08 09:13 831488 ----a-w- c:\program files\Analog Devices\SoundMAX\SMax4.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2008-04-24 17:53 1036288 ----a-w- c:\program files\Analog Devices\Core\smax4pnp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-07-03 09:04 252848 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPKMAPHELPER]
2007-01-09 16:28 868352 ----a-w- c:\program files\ThinkPad\Utilities\TpKmapAp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPKMAPMN]
2007-09-21 15:45 49152 ----a-w- c:\program files\ThinkPad\Utilities\TpKmapMn.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TpShocks]
2012-09-20 19:44 186248 ----a-w- c:\windows\system32\TpShocks.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrackPointSrv]
2011-11-01 11:29 95264 ----a-w- c:\program files\Lenovo\TrackPoint\tp4serv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVT Scheduler Proxy]
2008-03-04 10:34 487424 ----a-w- c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"TVT Scheduler"=2 (0x2)
"TpKmpSVC"=2 (0x2)
"TPHKSVC"=2 (0x2)
"TPHKLOAD"=2 (0x2)
"TPHDEXLGSVC"=3 (0x3)
"ThinkVantage Registry Monitor Service"=2 (0x2)
"SUService"=2 (0x2)
"SkypeUpdate"=2 (0x2)
"ose"=3 (0x3)
"LENOVO.MICMUTE"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"IBMPMSVC"=2 (0x2)
"ekrn"=2 (0x2)
"EhttpSrv"=3 (0x3)
"UPS"=3 (0x3)
"Themes"=2 (0x2)
"TermService"=3 (0x3)
"LmHosts"=2 (0x2)
"srservice"=2 (0x2)
"SCardSvr"=3 (0x3)
"RemoteRegistry"=2 (0x2)
"RDSessMgr"=3 (0x3)
"mnmsrvc"=3 (0x3)
"Netlogon"=3 (0x3)
"CiSvc"=3 (0x3)
"ImapiService"=3 (0x3)
"helpsvc"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"ERSvc"=2 (0x2)
"MSDTC"=3 (0x3)
"CryptSvc"=3 (0x3)
"Browser"=2 (0x2)
"BITS"=3 (0x3)
"wuauserv"=2 (0x2)
"ALG"=3 (0x3)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [25.12.2012 18:31 717296]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [6.9.2012 11:49 20328]
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [14.12.2012 21:45 18528]
R1 cmdGuard;COMODO Internet Security Driver;c:\windows\system32\drivers\cmdGuard.sys [14.12.2012 21:45 592384]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [14.12.2012 21:45 32816]
R1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\drivers\smiif32.sys [20.12.2012 22:13 13680]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [23.2.2013 16:54 805752]
R2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [18.4.2013 19:51 821592]
R3 FileMonitor;FileMonitor;c:\program files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys [18.4.2013 19:56 246816]
R3 NETwLx32; Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [25.12.2012 10:19 6609920]
R3 RegFilter;RegFilter;c:\program files\IObit\IObit Malware Fighter\Drivers\wxp_x86\RegFilter.sys [18.4.2013 19:56 30408]
R3 Tp4Track;PS/2 TrackPoint Driver;c:\windows\system32\drivers\tp4track.sys [20.12.2012 22:17 24872]
R3 UrlFilter;UrlFilter;c:\program files\IObit\IObit Malware Fighter\Drivers\wxp_x86\UrlFilter.sys [18.4.2013 19:56 16248]
S3 cmdvirth;COMODO Virtual Service Manager;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe [14.12.2012 21:45 127184]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [20.12.2012 18:55 9728]
S3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\drivers\ZTEusbnet.sys [20.12.2012 18:55 114688]
S4 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\Lenovo\HOTKEY\micmute.exe [26.12.2012 19:51 101736]
S4 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [8.1.2013 13:55 161536]
S4 TPHKLOAD;Lenovo Hotkey Client Loader;c:\program files\Lenovo\HOTKEY\tphkload.exe [26.12.2012 19:51 131432]
S4 TPHKSVC;On Screen Display;c:\program files\Lenovo\HOTKEY\TPHKSVC.exe [26.12.2012 19:51 142696]
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-20 c:\windows\Tasks\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}.job
- c:\program files\COMODO\COMODO Internet Security\cfpconfg.exe [2012-12-14 17:38]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://uk.search.yahoo.com?type=800236&fr=spigot-yhp-ie
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\T8300\Application Data\Mozilla\Firefox\Profiles\6ld68es7.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://google.sk/
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=gr ... =800236&p=
FF - ExtSQL: 2013-04-18 19:57; iobitapps@mybrowserbar.com; c:\program files\IObit Apps Toolbar\FF
.
.
------- File Associations -------
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-Advanced SystemCare Ultimate - c:\program files\IObit\Advanced SystemCare Ultimate\ASCTray.exe
MSConfigStartUp-egui - c:\program files\ESET\ESET NOD32 Antivirus\egui.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-20 07:12
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(748)
c:\windows\system32\netprovcredman.dll
.
- - - - - - - > 'lsass.exe'(804)
c:\windows\system32\guard32.dll
c:\windows\system32\mswsock.dll
c:\windows\System32\wshtcpip.dll
.
- - - - - - - > 'csrss.exe'(720)
c:\windows\system32\cmdcsr.dll
.
Completion time: 2013-04-20 07:17:38
ComboFix-quarantined-files.txt 2013-04-20 06:17
.
Pre-Run: 44 464 381 952 bytes free
Post-Run: 44 566 790 144 bytes free
.
- - End Of File - - 3D60B8679FAE9E4824D3ACE61BBB04EE


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 20.04.2013 13:16

odinštaluj všetko od IObit

Keď nemáš combofix tak ho presuň na plochu
Spusť poznámkový blok
skopíruj script do poznámkového bloku

Kód:
killall::
registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}"=-
"{03EB0E9C-7A91-4381-A220-9B52B641CDB1}"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
""=-
"IObit Malware Fighter"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare Ultimate]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LenovoAutoScrollUtility]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPMailChecker]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPManager]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPKMAPHELPER]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPKMAPMN]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TpShocks]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrackPointSrv]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVT Scheduler Proxy]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^T8300^Start Menu^Programs^Startup^Lingea Update Center.lnk]
[-HKEY_CLASSES_ROOT\clsid\{03eb0e9c-7a91-4381-a220-9b52b641cdb1}]
[-HKEY_CLASSES_ROOT\clsid\{03eb0e9c-7a91-4381-a220-9b52b641cdb1}]
driver::
SkypeUpdate

DDS::
uStart Page = hxxp://uk.search.yahoo.com?type=800236&fr=spigot-yhp-ie
firefox::
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=gr ... =800236&p=
FF - ExtSQL: 2013-04-18 19:57; iobitapps@mybrowserbar.com; c:\program files\IObit Apps Toolbar\FF

atjob::
ClearJavaCache::
Reboot::


Ulož vytvorený TXT súbor ako CFScript
Pretiahni cfscript cez combofix aplikuje sa script
Po aplikovaný scriptu a možnom reštarte pc vlož log sem


Stiahni si SecurityCheck - http://screen317.spywareinfoforum.org/SecurityCheck.exe
Ulož ho na plochu spusť stlač ľubovľnu klavesu
Po skončení skenu sa vytvori log vlož ho sem.


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 18.06.08
Prihlásený: 04.05.13
Príspevky: 19
Témy: 1
Príspevok NapísalOffline : 20.04.2013 15:47

ComboFix 13-04-20.01 - T8300 20.04.2013 14:19:40.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2006.1610 [GMT 1:00]
Running from: c:\documents and settings\T8300\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\T8300\Desktop\CFScript.txt
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_SKYPEUPDATE
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Files Created from 2013-03-20 to 2013-04-20 )))))))))))))))))))))))))))))))
.
.
2013-04-19 22:25 . 2013-04-19 22:25 388096 ----a-r- c:\documents and settings\T8300\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-04-18 18:15 . 2013-04-18 18:15 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2013-03-24 11:40 . 2013-03-24 11:40 -------- d-----w- c:\program files\AnswerWorks 4.0
2013-03-24 11:38 . 2013-03-24 11:48 -------- d-----w- c:\documents and settings\T8300\Application Data\Autodesk
2013-03-24 11:38 . 2013-03-24 11:41 -------- d-----w- c:\program files\AutoCAD 2007
2013-03-24 11:38 . 2013-03-24 11:38 -------- d-----w- c:\documents and settings\T8300\Local Settings\Application Data\Autodesk
2013-03-24 11:38 . 2013-03-24 11:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk
2013-03-24 11:36 . 2013-03-24 11:41 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2013-03-24 11:36 . 2013-03-24 11:36 -------- d-----w- c:\program files\Autodesk
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-18 17:02 . 2012-12-14 20:45 99392 ----a-w- c:\windows\system32\drivers\inspect.sys
2013-04-15 17:38 . 2012-12-14 20:45 32816 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2013-04-15 17:38 . 2012-12-14 20:45 592384 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2013-04-15 17:38 . 2012-12-14 20:45 18528 ----a-w- c:\windows\system32\drivers\cmderd.sys
2013-04-15 17:38 . 2012-12-14 20:45 35488 ----a-w- c:\windows\system32\cmdcsr.dll
2013-04-15 17:38 . 2012-12-14 20:45 348584 ----a-w- c:\windows\system32\guard32.dll
2013-04-15 17:38 . 2012-12-14 20:45 276688 ----a-w- c:\windows\system32\cmdvrt32.dll
2013-04-15 17:38 . 2012-09-04 19:07 40656 ----a-w- c:\windows\system32\cmdkbd32.dll
2013-04-12 18:04 . 2013-04-12 18:04 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-07-18 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cistray.exe" [2013-04-15 3012816]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /k:D *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"TVT Scheduler"=2 (0x2)
"TpKmpSVC"=2 (0x2)
"TPHKSVC"=2 (0x2)
"TPHKLOAD"=2 (0x2)
"TPHDEXLGSVC"=3 (0x3)
"ThinkVantage Registry Monitor Service"=2 (0x2)
"SUService"=2 (0x2)
"SkypeUpdate"=2 (0x2)
"ose"=3 (0x3)
"LENOVO.MICMUTE"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"IBMPMSVC"=2 (0x2)
"ekrn"=2 (0x2)
"EhttpSrv"=3 (0x3)
"UPS"=3 (0x3)
"Themes"=2 (0x2)
"TermService"=3 (0x3)
"LmHosts"=2 (0x2)
"srservice"=2 (0x2)
"SCardSvr"=3 (0x3)
"RemoteRegistry"=2 (0x2)
"RDSessMgr"=3 (0x3)
"mnmsrvc"=3 (0x3)
"Netlogon"=3 (0x3)
"CiSvc"=3 (0x3)
"ImapiService"=3 (0x3)
"helpsvc"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"ERSvc"=2 (0x2)
"MSDTC"=3 (0x3)
"CryptSvc"=3 (0x3)
"Browser"=2 (0x2)
"BITS"=3 (0x3)
"wuauserv"=2 (0x2)
"ALG"=3 (0x3)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [25.12.2012 18:31 717296]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [6.9.2012 11:49 20328]
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [14.12.2012 21:45 18528]
R1 cmdGuard;COMODO Internet Security Driver;c:\windows\system32\drivers\cmdGuard.sys [14.12.2012 21:45 592384]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [14.12.2012 21:45 32816]
R1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\drivers\smiif32.sys [20.12.2012 22:13 13680]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [23.2.2013 16:54 805752]
R3 NETwLx32; Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [25.12.2012 10:19 6609920]
R3 Tp4Track;PS/2 TrackPoint Driver;c:\windows\system32\drivers\tp4track.sys [20.12.2012 22:17 24872]
S3 cmdvirth;COMODO Virtual Service Manager;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe [14.12.2012 21:45 127184]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [20.12.2012 18:55 9728]
S3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\drivers\ZTEusbnet.sys [20.12.2012 18:55 114688]
S4 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\Lenovo\HOTKEY\micmute.exe [26.12.2012 19:51 101736]
S4 TPHKLOAD;Lenovo Hotkey Client Loader;c:\program files\Lenovo\HOTKEY\tphkload.exe [26.12.2012 19:51 131432]
S4 TPHKSVC;On Screen Display;c:\program files\Lenovo\HOTKEY\TPHKSVC.exe [26.12.2012 19:51 142696]
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-20 c:\windows\Tasks\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}.job
- c:\program files\COMODO\COMODO Internet Security\cfpconfg.exe [2012-12-14 17:38]
.
.
------- Supplementary Scan -------
.
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\T8300\Application Data\Mozilla\Firefox\Profiles\6ld68es7.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://google.sk/
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=gr ... =800236&p=
FF - ExtSQL: 2013-04-18 19:57; iobitapps@mybrowserbar.com; c:\program files\IObit Apps Toolbar\FF
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{03EB0E9C-7A91-4381-A220-9B52B641CDB1} - (no file)
BHO-{03EB0E9C-7A91-4381-A220-9B52B641CDB1} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-20 14:30
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(748)
c:\windows\system32\netprovcredman.dll
.
- - - - - - - > 'lsass.exe'(804)
c:\windows\system32\guard32.dll
c:\windows\system32\mswsock.dll
c:\windows\System32\wshtcpip.dll
.
- - - - - - - > 'explorer.exe'(2316)
c:\windows\system32\WININET.dll
c:\windows\system32\guard32.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\WS2HELP.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
- - - - - - - > 'csrss.exe'(720)
c:\windows\system32\cmdcsr.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\COMODO\COMODO Internet Security\cavwp.exe
c:\program files\COMODO\COMODO Internet Security\cis.exe
.
**************************************************************************
.
Completion time: 2013-04-20 14:32:27 - machine was rebooted
ComboFix-quarantined-files.txt 2013-04-20 13:32
.
Pre-Run: 45 670 354 944 bytes free
Post-Run: 45 594 103 808 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /noguiboot
.
- - End Of File - - 5EFF9E26585C760E20F53CC8DFF709A2

mal som problem stiahnut security check..z tej stranky screeen 317.spyware....
inak uz ide pocitac normalne...velmi moc pekne dakujem..aky antispyware odporucate?
a inak ako to viete registre su zle a treba odstranit.....


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 20.04.2013 15:57

tak si stiahni securitycheck z tadiaľ http://leteckaposta.cz/528967492
Stiahni si avast http://www.avast.com/cs-cz/download-tha ... cale=cs-cz

Stiahni si AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
ulož ho na plochu Spusť program stlač tlačidlo search
Po skene sa objaví log budeš ho mať na systémovom disku ako AdwCleaner[R?].txt cely obsah vlož sem


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 18.06.08
Prihlásený: 04.05.13
Príspevky: 19
Témy: 1
Príspevok NapísalOffline : 20.04.2013 18:51

Results of screen317's Security Check version 0.99.60
Windows XP Service Pack 3 x86
Internet Explorer 7 Out of date!
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
Please wait while WMIC compiles updated MOF files.
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 10
Java version out of Date!
Adobe Flash Player 11.5.502.135
Adobe Reader XI
Mozilla Firefox (20.0.1)
````````Process Check: objlist.exe by Laurent````````
Comodo Firewall cmdagent.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 15% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 18.06.08
Prihlásený: 04.05.13
Príspevky: 19
Témy: 1
Príspevok NapísalOffline : 20.04.2013 18:54

# AdwCleaner v2.200 - Logfile created 04/20/2013 at 17:54:24
# Updated 02/04/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : T8300 - T8300-738CAB805
# Boot Mode : Normal
# Running from : C:\Documents and Settings\T8300\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****

Found : Application Updater

***** [Files / Folders] *****

Folder Found : C:\Documents and Settings\T8300\Application Data\Search Settings
Folder Found : C:\Program Files\Application Updater
Folder Found : C:\Program Files\Common Files\spigot

***** [Registry] *****

Key Found : HKCU\Software\AppDataLow\Software\Search Settings
Key Found : HKCU\Software\Search Settings
Key Found : HKLM\Software\Application Updater
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1CAE30F47D14B41B5FC8FA53658044
Key Found : HKLM\Software\Search Settings

***** [Internet Browsers] *****

-\\ Internet Explorer v7.0.6000.17115

[OK] Registry is clean.

-\\ Mozilla Firefox v20.0.1 (en-US)

File : C:\Documents and Settings\T8300\Application Data\Mozilla\Firefox\Profiles\6ld68es7.default\prefs.js

[OK] File is clean.

File : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0qdqief1.default\prefs.js

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [1394 octets] - [20/04/2013 17:54:24]

########## EOF - C:\AdwCleaner[R1].txt - [1454 octets] ##########


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 20.04.2013 18:58

Spusť adwcleaner stlač tlačidlo delete pre odsúhlasenie stlač OK počítač sa reštartuje
log budeš ho mať na systémovom disku ako AdwCleaner[S?].txt cely obsah vlož sem

Stiahni si RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe ulož ho na plochu a spusť ako spravca
Prebehne test keď skonči stlač tlačidlo prehľadať
Keď to skonči stlač tlačidlo sprava log vlož sem

Aktualizuj OS


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 18.06.08
Prihlásený: 04.05.13
Príspevky: 19
Témy: 1
Príspevok NapísalOffline : 20.04.2013 19:18

potom zase sa startuje 5 az 10 minutttt
Logfile of random's system information tool 1.08 (written by random/random)
Run by T8300 at 2013-04-20 18:17:29
Microsoft Windows XP Professional Service Pack 3
System drive C: has 43 GB (82%) free of 53 GB
Total RAM: 2006 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:17:43, on 20.4.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17115)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cis.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\T8300\Desktop\RSIT-1.06.exe
C:\Program Files\trend micro\T8300.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

--
End of file - 6837 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\avast! Emergency Update.job
C:\WINDOWS\tasks\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2012-09-23 72336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-12-25 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-03-06 1224568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-12-25 170416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-03-06 1224568]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2013-04-15 3012816]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-03-06 4767304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3
"TVT Scheduler"=2
"TpKmpSVC"=2
"TPHKSVC"=2
"TPHKLOAD"=2
"TPHDEXLGSVC"=3
"ThinkVantage Registry Monitor Service"=2
"SUService"=2
"SkypeUpdate"=2
"ose"=3
"LENOVO.MICMUTE"=2
"JavaQuickStarterService"=2
"IBMPMSVC"=2
"ekrn"=2
"EhttpSrv"=3
"UPS"=3
"Themes"=2
"TermService"=3
"LmHosts"=2
"srservice"=2
"SCardSvr"=3
"RemoteRegistry"=2
"RDSessMgr"=3
"mnmsrvc"=3
"Netlogon"=3
"CiSvc"=3
"ImapiService"=3
"helpsvc"=2
"FastUserSwitchingCompatibility"=3
"ERSvc"=2
"MSDTC"=3
"CryptSvc"=3
"Browser"=2
"BITS"=3
"wuauserv"=2
"ALG"=3

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2010-01-13 205824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======File associations======

.scr - open - "C:\WINDOWS\system32\NOTEPAD.EXE" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2013-04-20 18:17:29 ----D---- C:\rsit
2013-04-20 18:10:14 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2013-04-20 18:10:14 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2013-04-20 18:10:12 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2013-04-20 18:10:12 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2013-04-20 18:10:12 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2013-04-20 18:10:11 ----A---- C:\WINDOWS\system32\drivers\aswVmm.sys
2013-04-20 18:10:11 ----A---- C:\WINDOWS\system32\drivers\aswRvrt.sys
2013-04-20 18:10:10 ----A---- C:\WINDOWS\system32\drivers\aswMonFlt.sys
2013-04-20 18:10:09 ----A---- C:\WINDOWS\system32\aswBoot.exe
2013-04-20 18:09:27 ----D---- C:\Program Files\AVAST Software
2013-04-20 18:07:06 ----D---- C:\Documents and Settings\All Users\Application Data\AVAST Software
2013-04-20 14:33:28 ----SHD---- C:\RECYCLER
2013-04-20 14:32:31 ----D---- C:\WINDOWS\temp
2013-04-20 14:17:38 ----A---- C:\Boot.bak
2013-04-20 14:17:32 ----RASHD---- C:\cmdcons
2013-04-20 06:57:20 ----A---- C:\WINDOWS\zip.exe
2013-04-20 06:57:20 ----A---- C:\WINDOWS\SWXCACLS.exe
2013-04-20 06:57:20 ----A---- C:\WINDOWS\SWSC.exe
2013-04-20 06:57:20 ----A---- C:\WINDOWS\SWREG.exe
2013-04-20 06:57:20 ----A---- C:\WINDOWS\sed.exe
2013-04-20 06:57:20 ----A---- C:\WINDOWS\PEV.exe
2013-04-20 06:57:20 ----A---- C:\WINDOWS\NIRCMD.exe
2013-04-20 06:57:20 ----A---- C:\WINDOWS\MBR.exe
2013-04-20 06:57:20 ----A---- C:\WINDOWS\grep.exe
2013-04-20 06:56:53 ----D---- C:\Qoobox
2013-04-20 06:56:13 ----D---- C:\WINDOWS\erdnt
2013-04-19 23:16:50 ----D---- C:\Documents and Settings\All Users\Application Data\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-04-18 19:58:20 ----D---- C:\Documents and Settings\All Users\Application Data\{D76294E6-03B8-4971-AF2E-3F846161A690}
2013-04-18 19:58:18 ----D---- C:\Documents and Settings\T8300\Application Data\Apple Computer
2013-04-18 19:58:16 ----D---- C:\Documents and Settings\All Users\Application Data\{5A85B23A-4B58-47D1-9B9C-DFBD7866099F}
2013-04-18 19:57:04 ----D---- C:\Documents and Settings\T8300\Application Data\Search Settings
2013-04-18 19:56:58 ----D---- C:\Program Files\IObit Apps Toolbar
2013-04-18 19:56:58 ----D---- C:\Program Files\Common Files\Spigot
2013-04-18 19:56:58 ----D---- C:\Program Files\Application Updater
2013-04-18 19:51:27 ----D---- C:\Documents and Settings\All Users\Application Data\IObit
2013-04-18 19:51:26 ----D---- C:\Documents and Settings\T8300\Application Data\IObit
2013-04-18 19:51:22 ----D---- C:\Program Files\IObit
2013-04-12 19:04:17 ----D---- C:\Program Files\Mozilla Firefox
2013-03-24 12:40:50 ----D---- C:\Program Files\AnswerWorks 4.0
2013-03-24 12:38:51 ----D---- C:\Program Files\AutoCAD 2007
2013-03-24 12:38:51 ----D---- C:\Documents and Settings\T8300\Application Data\Autodesk
2013-03-24 12:38:51 ----D---- C:\Documents and Settings\All Users\Application Data\Autodesk
2013-03-24 12:36:32 ----D---- C:\Program Files\Common Files\Autodesk Shared
2013-03-24 12:36:29 ----D---- C:\Program Files\Autodesk
2013-03-24 12:36:26 ----A---- C:\WINDOWS\system32\d3dx9_27.dll

======List of files/folders modified in the last 1 months======

2013-04-20 18:17:32 ----D---- C:\Program Files\trend micro
2013-04-20 18:15:25 ----D---- C:\Documents and Settings\T8300\Application Data\Skype
2013-04-20 18:10:14 ----D---- C:\WINDOWS\system32\drivers
2013-04-20 18:10:10 ----SD---- C:\WINDOWS\Tasks
2013-04-20 18:10:09 ----D---- C:\WINDOWS\system32
2013-04-20 18:10:02 ----SHD---- C:\WINDOWS\Installer
2013-04-20 18:10:02 ----D---- C:\WINDOWS\WinSxS
2013-04-20 18:10:02 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-04-20 18:09:46 ----D---- C:\WINDOWS
2013-04-20 18:09:27 ----D---- C:\Program Files
2013-04-20 18:01:07 ----A---- C:\WINDOWS\wincmd.ini
2013-04-20 17:57:28 ----D---- C:\WINDOWS\system32\Restore
2013-04-20 17:54:11 ----D---- C:\WINDOWS\system32\CatRoot2
2013-04-20 14:47:55 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-04-20 14:30:11 ----N---- C:\WINDOWS\system.ini
2013-04-20 14:29:55 ----D---- C:\WINDOWS\system32\drivers\etc
2013-04-20 14:28:09 ----D---- C:\WINDOWS\system32\config
2013-04-20 14:24:08 ----D---- C:\WINDOWS\AppPatch
2013-04-20 14:24:04 ----D---- C:\Program Files\Common Files
2013-04-20 14:17:39 ----RASH---- C:\boot.ini
2013-04-20 14:09:58 ----SHD---- C:\System Volume Information
2013-04-18 21:10:58 ----A---- C:\WINDOWS\win.ini
2013-04-18 19:51:23 ----D---- C:\WINDOWS\Prefetch
2013-04-18 19:23:54 ----D---- C:\Documents and Settings\All Users\Application Data\ESET
2013-04-18 19:23:48 ----A---- C:\WINDOWS\ntbtlog.txt
2013-04-18 19:23:47 ----HD---- C:\WINDOWS\inf
2013-04-18 19:04:53 ----D---- C:\WINDOWS\pss
2013-04-15 18:38:37 ----A---- C:\WINDOWS\system32\guard32.dll
2013-04-15 18:38:37 ----A---- C:\WINDOWS\system32\cmdcsr.dll
2013-04-15 18:38:25 ----A---- C:\WINDOWS\system32\cmdvrt32.dll
2013-04-15 18:38:24 ----A---- C:\WINDOWS\system32\cmdkbd32.dll
2013-04-13 07:04:29 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-03-31 07:24:13 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2013-03-24 12:41:29 ----RSD---- C:\WINDOWS\assembly
2013-03-24 12:40:58 ----D---- C:\Program Files\Microsoft Office
2013-03-24 12:40:51 ----RSD---- C:\WINDOWS\Fonts
2013-03-24 12:40:17 ----D---- C:\WINDOWS\Help
2013-03-24 12:40:05 ----SD---- C:\WINDOWS\Downloaded Program Files
2013-03-24 12:36:28 ----D---- C:\WINDOWS\system32\DirectX
2013-03-24 12:36:27 ----D---- C:\WINDOWS\Microsoft.NET

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 Inspect;COMODO Internet Security Firewall Driver; C:\WINDOWS\System32\DRIVERS\inspect.sys [2013-04-18 99392]
R0 ohci1394;OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 Shockprf;Shockprf; C:\WINDOWS\System32\DRIVERS\Apsx86.sys [2012-07-23 129384]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2012-12-25 717296]
R0 TPDIGIMN;TPDIGIMN; C:\WINDOWS\System32\DRIVERS\ApsHM86.sys [2012-09-06 20328]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 AswRdr;aswRdr; C:\WINDOWS\system32\drivers\AswRdr.sys [2013-03-06 49760]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2013-03-06 368176]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2013-03-06 62376]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\WINDOWS\System32\DRIVERS\cmderd.sys [2013-04-15 18528]
R1 cmdGuard;COMODO Internet Security Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2013-04-15 592384]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2013-04-15 32816]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 lenovo.smi;Lenovo System Interface Driver; C:\WINDOWS\system32\DRIVERS\smiif32.sys [2010-09-07 13680]
R1 Smapint;Smapint; C:\WINDOWS\System32\drivers\Smapint.sys [2006-10-02 14848]
R1 TDSMAPI;TDSMAPI; C:\WINDOWS\System32\drivers\TDSMAPI.SYS [2006-10-02 9343]
R1 TPHKDRV;TPHKDRV; C:\WINDOWS\system32\DRIVERS\TPHKDRV.sys [2008-05-12 17844]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.7.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2012-12-20 21361]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2013-03-06 29816]
R2 aswMonFlt;aswMonFlt; \??\C:\WINDOWS\system32\drivers\aswMonFlt.sys []
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2010-06-02 19384]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2007-11-20 12288]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2008-04-24 308736]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2008-04-24 103424]
R3 aswVmm;aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [2013-03-06 164736]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2010-06-02 993464]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2010-06-02 217016]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2010-01-13 1730272]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2012-04-11 35240]
R3 NETwLx32; Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETwLx32.sys [2010-10-07 6609920]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\WINDOWS\system32\DRIVERS\psadd.sys [2007-02-19 21376]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2009-05-14 80384]
R3 Tp4Track;PS/2 TrackPoint Driver; C:\WINDOWS\system32\DRIVERS\tp4track.sys [2011-11-01 24872]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2010-06-02 738360]
S0 aswRvrt;aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [2013-03-06 49248]
S1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2013-03-06 765736]
S3 a82qyd15;a82qyd15; C:\WINDOWS\system32\drivers\a82qyd15.sys []
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys []
S3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys []
S3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys []
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2009-06-18 234496]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 massfilter;ZTE Mass Storage Filter Driver; C:\WINDOWS\system32\drivers\massfilter.sys [2009-04-27 9728]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 NETw4x32;Intel(R) Wireless WiFi Link Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw4x32.sys [2007-11-27 2236544]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 TwoTrack;IBM PS/2 TrackPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\TwoTrack.sys [2001-08-17 11520]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 ZTEusbmdm6k;ZTE Proprietary USB Driver; C:\WINDOWS\system32\DRIVERS\ZTEusbmdm6k.sys [2009-07-21 105088]
S3 ZTEusbnet;ZTE USB-NDIS miniport; C:\WINDOWS\system32\DRIVERS\ZTEusbnet.sys [2009-07-21 114688]
S3 ZTEusbnmea;ZTE NMEA Port; C:\WINDOWS\system32\DRIVERS\ZTEusbnmea.sys [2009-07-21 105088]
S3 ZTEusbser6k;ZTE Diagnostic Port; C:\WINDOWS\system32\DRIVERS\ZTEusbser6k.sys [2009-07-21 105088]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2013-02-23 805752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-03-06 45248]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2013-04-15 4443912]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2007-11-19 794624]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2007-11-19 483328]
R2 S24EventMonitor;Intel(R) PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2007-11-19 1183744]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2012-12-26 69632]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2013-03-24 77944]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2013-04-15 127184]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-04-12 115608]
S4 IBMPMSVC;Lenovo PM Service; C:\WINDOWS\system32\ibmpmsvc.exe [2012-04-11 39248]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2012-12-25 170408]
S4 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2011-07-12 101736]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 SUService;System Update; C:\Program Files\Lenovo\System Update\SUService.exe [2011-07-26 28672]
S4 ThinkVantage Registry Monitor Service;ThinkVantage Registry Monitor Service; C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe [2007-09-26 644408]
S4 TPHDEXLGSVC;ThinkPad HDD APS Logging Service; C:\WINDOWS\System32\TPHDEXLG.exe [2012-09-06 39304]
S4 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2011-07-12 131432]
S4 TPHKSVC;On Screen Display; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2011-07-12 142696]
S4 TpKmpSVC;IBM KCU Service; C:\WINDOWS\system32\TpKmpSVC.exe [2006-06-29 32768]
S4 TVT Scheduler;TVT Scheduler; C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe [2008-03-04 1122304]
S4 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]

-----------------EOF-----------------


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 09.05.11
Prihlásený: 20.12.18
Príspevky: 618
Témy: 2
Príspevok NapísalOffline : 20.04.2013 19:26

ale ja som nechcel log z rsit
zmaž
C:\Program Files\IObit
C:\Program Files\IObit Apps Toolbar
C:\Documents and Settings\All Users\Application Data\ESET


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 18.06.08
Prihlásený: 04.05.13
Príspevky: 19
Témy: 1
Príspevok NapísalOffline : 20.04.2013 19:43

RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo.com/forum/files/fi ... guekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : T8300 [Admin rights]
Mode : Remove -- Date : 04/20/2013 18:42:49
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: ST9160824AS +++++
--- User ---
[MBR] a68fcb5d322df6046d5bdb3fd6d1711d
[BSP] 5658cec539e4199782c49e1b8f8d1c7c : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 52624 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 107775360 | Size: 100000 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[3]_D_04202013_02d1842.txt >>
RKreport[1]_S_04202013_02d1841.txt ; RKreport[2]_D_04202013_02d1842.txt ; RKreport[3]_D_04202013_02d1842.txt


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 18.06.08
Prihlásený: 04.05.13
Príspevky: 19
Témy: 1
Príspevok NapísalOffline : 21.04.2013 7:21

dobry pekny den, inak ked som vtedy pretiahol cez combofix tak on tam daco odstranilo a start bol normalny...takze jedna ztych peknych viet tam to urcite blokuje..ale horsie je ze sa znova spusti ..treba tam hladat asi chybu


Odpovedať na tému [ Príspevkov: 36 ] Choď na stránku: 1, 2 ďalšia


Podobné témy

 Témy  Odpovede  Zobrazenia  Posledný príspevok 
V tomto fóre nie sú ďalšie neprečítané témy. kontrola hijack

v Antivíry a antispywary

1

452

13.11.2007 15:22

Rbot Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Kontrola Hijack logu

v Antivíry a antispywary

15

900

25.06.2008 3:15

Roberbo Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. pls kontrola hijack logu

v Antivíry a antispywary

1

1109

16.11.2007 18:37

Rbot Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Prosím o pomoc pri odvírení - kontrola Hijack a wmav

v Bezpečnosť a firewally

18

1587

26.06.2008 7:37

pistabaci Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. hijack this

v Antivíry a antispywary

3

536

06.11.2010 20:13

Pistuk_14 Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. hijack this

v Antivíry a antispywary

12

775

30.11.2009 19:35

pitimir Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Hijack log-pls

v Antivíry a antispywary

13

650

17.07.2008 21:38

McDog Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. kluci help..... hijack

v Antivíry a antispywary

3

542

01.04.2008 20:33

br4n0 Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Log z hijack

v Antivíry a antispywary

3

591

04.06.2008 18:53

Qpkqkma Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Moj Hijack log

v Antivíry a antispywary

0

511

05.02.2008 20:50

Larliand Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Problem s USB, Hijack

v Antivíry a antispywary

14

1067

27.05.2008 22:18

majso Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. hijack - poprosim o kontrolu

v Bezpečnosť a firewally

1

1376

13.07.2008 18:32

Kosak Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Zkontrolujte moj log z Hijack

v Antivíry a antispywary

5

647

17.10.2007 22:07

Rbot Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Prosim o kontrolu Hijack log

v Antivíry a antispywary

0

645

15.02.2008 21:24

alan Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Prosim o kontrolu HiJack logu

v Bezpečnosť a firewally

6

408

05.03.2013 13:55

personal compuper Zobrazenie posledných príspevkov

V tomto fóre nie sú ďalšie neprečítané témy. Hijack - mam virus a neviem co s nim

v Bezpečnosť a firewally

2

1429

19.02.2009 9:50

bayo15 Zobrazenie posledných príspevkov


Nemôžete zakladať nové témy v tomto fóre
Nemôžete odpovedať na témy v tomto fóre
Nemôžete upravovať svoje príspevky v tomto fóre
Nemôžete mazať svoje príspevky v tomto fóre

Skočiť na:  

Powered by phpBB Jarvis © 2005 - 2024 PCforum, webhosting by WebSupport, secured by GeoTrust, edited by JanoF
Ako väčšina webových stránok aj my používame cookies. Zotrvaním na webovej stránke súhlasíte, že ich môžeme používať.
Všeobecné podmienky, spracovanie osobných údajov a pravidlá fóra