vyslo mi toto.. toto uz je na mna moc hard
Deckard's System Scanner v20071014.68
Run by hadus on 2007-11-20 22:51:46
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
14: 2007-11-20 21:51:49 UTC - RP66 - Deckard's System Scanner Restore Point
13: 2007-11-20 18:37:24 UTC - RP65 - Installed PC Booster
12: 2007-11-20 18:34:37 UTC - RP64 - Eliminado PC Booster
11: 2007-11-20 18:19:23 UTC - RP63 - Instalado PC Booster
10: 2007-11-20 17:50:38 UTC - RP62 - Removed STOPzilla. Available with Windows Installer version 1.2 and later.
-- First Restore Point --
1: 2007-11-07 15:41:38 UTC - RP53 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as hadus.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:52:52, on 20. 11. 2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20661)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\PC Booster\PCBooster.exe
C:\Program Files\Miranda IM\miranda32.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\hadus\My Documents\Downloads\Programs\dss.exe
C:\PROGRA~1\HIJACK~1\hadus.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [RAM Booster Expert] "C:\Program Files\RAM Booster Expert\RAMBooster.exe" /start
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O8 - Extra context menu item: Append to existing PDF -
res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF -
res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF -
res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF -
res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Unknown owner - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 9702 bytes
-- File Associations -----------------------------------------------------------
.js - JSFile - shell\open\command - NOTEPAD.EXE %1
.reg - regfile - shell\open\command - NOTEPAD.EXE %1
.scr - scrfile - shell\open\command - NOTEPAD.EXE %1
.vbs - VBSFile - shell\open\command - NOTEPAD.EXE %1
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 sp_rsdrv2 (Spyware Terminator Driver 2) - c:\windows\system32\drivers\sp_rsdrv2.sys
R3 ADIHdAudAddService (ADI UAA Function Driver for High Definition Audio Service) - c:\windows\system32\drivers\adihdaud.sys <Not Verified; Analog Devices, Inc.; SoundMAX Digital HD Audio Driver>
R3 AEAudio (AE Audio Service) - c:\windows\system32\drivers\aeaudio.sys <Not Verified; Andrea Electronics Corporation; Andrea Audio Driver>
S3 AMDPCI - c:\docume~1\hadus\locals~1\temp\amdpci.sys (file missing)
S3 SBAPIFS - c:\windows\system32\drivers\sbapifs.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 aawservice (Ad-Aware 2007 Service) - "c:\program files\lavasoft\ad-aware 2007\aawservice.exe" <Not Verified; Lavasoft AB; Ad-Aware 2007 Service>
R2 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>
R2 Nero BackItUp Scheduler 3 - c:\program files\nero\nero8\nero backitup\nbservice.exe
R2 sp_rssrv (Spyware Terminator Realtime Shield Service) - "c:\program files\spyware terminator\sp_rsser.exe" <Not Verified; Crawler.com; Crawler Spyware Terminator>
R2 StarWindServiceAE (StarWind AE Service) - c:\program files\alcohol soft\alcohol 120\starwind\starwindserviceae.exe <Not Verified; Rocket Division Software; StarWind Alcohol Edition>
S2 SBCSSvc (Sunbelt CounterSpy Antispyware) - "c:\program files\sunbelt software\counterspy\sbcssvc.exe" (file missing)
S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2007-11-10 13:23:06 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2007-10-20 and 2007-11-20 -----------------------------
2007-11-20 21:10:43 138624 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-11-20 21:10:11 0 d-------- C:\Documents and Settings\hadus\Application Data\Spyware Terminator
2007-11-20 21:10:11 0 d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2007-11-20 21:10:09 0 d-------- C:\Program Files\Spyware Terminator
2007-11-20 19:37:20 0 d-------- C:\Program Files\PC Booster
2007-11-20 19:28:26 0 d-------- C:\Program Files\RAM Booster Expert
2007-11-20 00:03:07 0 d-------- C:\Program Files\Common Files\iS3
2007-11-20 00:03:07 0 d-------- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2007-11-11 16:32:56 0 d--hs---- C:\Diskeeper
2007-11-11 14:46:02 0 d-------- C:\Documents and Settings\All Users\Application Data\Diskeeper Corporation
2007-11-11 14:46:01 0 d-------- C:\Program Files\Diskeeper Corporation
2007-11-08 23:49:54 0 d-------- C:\Documents and Settings\hadus\Application Data\IrfanView
2007-11-03 14:19:02 0 d-------- C:\Program Files\Common Files\Blizzard Entertainment
2007-10-23 15:22:38 0 d-------- C:\WINDOWS\Caps
2007-10-23 14:21:07 0 --a------ C:\WINDOWS\system32\SBRC.dat
2007-10-23 14:21:07 0 --a------ C:\WINDOWS\system32\SBFC.dat
2007-10-22 16:03:28 0 d-------- C:\Documents and Settings\hadus\Application Data\CyberLink
-- Find3M Report ---------------------------------------------------------------
2007-11-20 22:52:56 0 d-------- C:\Documents and Settings\hadus\Application Data\uTorrent
2007-11-20 19:37:24 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-11-20 19:24:39 0 d-------- C:\Documents and Settings\hadus\Application Data\DMCache
2007-11-20 00:03:07 0 d-------- C:\Program Files\Common Files
2007-11-18 22:56:53 0 d-------- C:\Documents and Settings\hadus\Application Data\BitTorrent DNA
2007-11-03 13:55:29 0 d-------- C:\Documents and Settings\hadus\Application Data\Miranda
2007-10-23 15:13:08 0 d-------- C:\Program Files\Internet Download Manager
2007-10-23 13:50:22 0 d-------- C:\Documents and Settings\hadus\Application Data\Adobe
2007-10-19 06:57:15 0 d-------- C:\Documents and Settings\hadus\Application Data\Sun
2007-10-06 10:29:05 0 dr-h----- C:\Documents and Settings\hadus\Application Data\SecuROM
2007-10-03 22:50:10 0 d-------- C:\Documents and Settings\hadus\Application Data\InstallShield
2007-10-03 17:02:29 684 --a------ C:\WINDOWS\mozver.dat
2007-10-03 17:02:15 0 d-------- C:\Program Files\DivX
2007-10-01 17:51:32 0 d-------- C:\Documents and Settings\hadus\Application Data\WinRAR
2007-10-01 15:07:50 0 d-------- C:\Documents and Settings\hadus\Application Data\Apple Computer
2007-10-01 15:07:09 0 d-------- C:\Program Files\QuickTime
2007-10-01 15:06:39 0 d-------- C:\Program Files\Apple Software Update
2007-10-01 15:05:39 0 d-------- C:\Documents and Settings\hadus\Application Data\Media Player Classic
2007-10-01 13:38:14 356352 --a------ C:\WINDOWS\eSellerateEngine.dll <Not Verified; eSellerate Inc.; eSellerateEngine>
2007-10-01 13:38:09 0 d-------- C:\Program Files\QO Labs
2007-10-01 13:05:17 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-10-01 13:05:14 0 d-------- C:\Program Files\MSXML 6.0
2007-10-01 13:02:11 0 d-------- C:\Program Files\MSXML 4.0
2007-10-01 07:12:10 0 d-------- C:\Program Files\DAEMON Tools Pro
2007-09-30 22:10:50 0 d-------- C:\Program Files\uTorrent
2007-09-30 22:08:09 298104 --a------ C:\WINDOWS\system32\imon.dll <Not Verified; Eset; NOD32 Antivirus System>
2007-09-30 22:00:31 0 d-------- C:\Documents and Settings\hadus\Application Data\IDM
2007-09-30 21:22:51 0 d-------- C:\Documents and Settings\hadus\Application Data\Macromedia
2007-09-30 21:01:38 0 d-------- C:\Program Files\Common Files\ODBC
2007-09-30 21:01:35 0 d-------- C:\Program Files\Common Files\SpeechEngines
2007-09-30 21:01:08 62 --ahs---- C:\Documents and Settings\hadus\Application Data\desktop.ini
2007-09-30 20:54:50 0 --a------ C:\WINDOWS\nsreg.dat
2007-09-30 20:54:46 0 d-------- C:\Documents and Settings\hadus\Application Data\Mozilla
2007-09-30 20:46:32 0 d-------- C:\Program Files\Miranda IM
2007-09-30 20:41:17 0 d-------- C:\Documents and Settings\hadus\Application Data\Nero
2007-09-30 20:40:37 0 d-------- C:\Program Files\Common Files\Nero
2007-09-30 20:39:36 0 d-------- C:\Documents and Settings\hadus\Application Data\Sunbelt Software
2007-09-30 20:39:03 0 d-------- C:\Program Files\Nero
2007-09-30 20:32:43 0 d-------- C:\Program Files\Lavasoft
2007-09-30 20:32:25 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-09-30 20:30:51 0 d-------- C:\Program Files\CyberLink
2007-09-30 20:24:43 0 d-------- C:\Program Files\Winamp
2007-09-30 20:21:12 0 d-------- C:\Program Files\K-Lite Codec Pack
2007-09-30 20:21:10 0 d-------- C:\Documents and Settings\hadus\Application Data\Real
2007-09-30 20:20:12 0 d-------- C:\Program Files\Java
2007-09-30 20:19:48 0 d-------- C:\Program Files\Common Files\Java
2007-09-30 20:19:25 0 d-------- C:\Program Files\IrfanView
2007-09-30 20:15:22 0 d-------- C:\Documents and Settings\hadus\Application Data\iolo
2007-09-30 20:05:06 0 d-------- C:\Program Files\Bonjour
2007-09-30 20:02:52 0 d-------- C:\Program Files\Common Files\Adobe
2007-09-30 19:58:24 0 d-------- C:\Program Files\Common Files\Macrovision Shared
2007-09-30 19:49:53 0 d-------- C:\Program Files\Microsoft Works
2007-09-30 19:49:49 0 d-------- C:\Program Files\MSBuild
2007-09-30 19:44:32 0 d-------- C:\Program Files\Analog Devices
2007-09-30 19:41:54 0 d-------- C:\Program Files\Alcohol Soft
2007-09-30 19:40:47 0 d-------- C:\Documents and Settings\hadus\Application Data\DAEMON Tools Pro
2007-09-30 19:36:32 0 d-------- C:\Documents and Settings\hadus\Application Data\GlarySoft
2007-09-30 19:36:16 0 d-------- C:\Program Files\Absolute Uninstaller
2007-09-30 19:33:56 0 d-------- C:\Program Files\Upm 3.2.0
2007-09-30 19:30:45 0 d-------- C:\Program Files\DIFX
2007-09-30 19:29:30 0 d-------- C:\Program Files\AMD
2007-09-30 19:23:48 0 d-------- C:\Program Files\Common Files\InstallShield
2007-09-30 19:21:14 0 d-------- C:\Documents and Settings\hadus\Application Data\Identities
2007-09-30 19:13:21 0 d-------- C:\Program Files\microsoft frontpage
2007-09-30 19:13:03 0 -rahs---- C:\MSDOS.SYS
2007-09-30 19:13:03 0 -rahs---- C:\IO.SYS
2007-09-30 19:13:03 0 --a------ C:\CONFIG.SYS
2007-09-30 19:13:03 0 --a------ C:\AUTOEXEC.BAT
2007-09-30 19:12:00 0 d--h----- C:\Program Files\WindowsUpdate
2007-09-30 19:11:00 0 d-------- C:\Program Files\Common Files\MSSoap
2007-09-30 19:10:49 0 d-------- C:\Program Files\Movie Maker
2007-09-30 19:09:54 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-09-30 19:09:38 0 d-------- C:\Program Files\Online Services
2007-09-30 19:09:32 0 d-------- C:\Program Files\Windows Media Connect 2
2007-09-30 19:09:24 0 d-------- C:\Program Files\Messenger
2007-09-30 19:09:18 0 d-------- C:\Program Files\MSN Gaming Zone
2007-09-30 19:09:07 0 d-------- C:\Program Files\Windows NT
2007-09-17 00:07:00 1626112 --a------ C:\WINDOWS\system32\nwiz.exe
2007-09-17 00:07:00 1019904 --a------ C:\WINDOWS\system32\nvwimg.dll
2007-09-17 00:07:00 1703936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2007-09-17 00:07:00 466944 --a------ C:\WINDOWS\system32\nvshell.dll
2007-09-17 00:07:00 1478656 --a------ C:\WINDOWS\system32\nview.dll
2007-09-17 00:07:00 1339392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2007-09-17 00:07:00 442368 --a------ C:\WINDOWS\system32\nvappbar.exe
2007-09-17 00:07:00 425984 --a------ C:\WINDOWS\system32\keystone.exe
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [17. 09. 2007 00:07]
"nwiz"="nwiz.exe" [17. 09. 2007 00:07 C:\WINDOWS\system32\nwiz.exe]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [17. 11. 2006 15:49]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [01. 05. 2006 03:07]
"@"="" []
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [30. 09. 2007 22:08]
"FRUpdate"="" []
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [20. 11. 2007 21:10]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04. 08. 2004 02:56]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [22. 06. 2007 13:45]
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [30. 09. 2007 22:11]
"FRUpdate"="" []
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [30. 09. 2007 21:00]
"RAM Booster Expert"="C:\Program Files\RAM Booster Expert\RAMBooster.exe" [16. 08. 2006 21:17]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"ShowDeskFix"=regsvr32 /s /n /i:u shell32
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [30. 9. 2007 19:58:19]
Adobe Acrobat Synchronizer.lnk - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [22. 10. 2006 23:01:50]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"=1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBCSSvc]
@="Service"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Schedule
*Newly Created Service* - SP_RSDRV2
*Newly Created Service* - SP_RSSRV
-- End of Deckard's System Scanner: finished at 2007-11-20 22:53:20 ------------