Logfile of random's system information tool 1.05 (written by random/random)
Run by PISTA at 2008-12-29 14:13:32
Microsoft Windows XP Professional Szervizcsomag 3
System drive C: has 28 GB (49%) free of 56 GB
Total RAM: 1023 MB (48% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:13:43, on 2008.12.29.
Platform: Windows XP Szervizcsomag 3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\PISTA\Local Settings\Temporary Internet Files\Content.IE5\YB92408K\RSIT[1].exe
C:\Program Files\HijackThis\PISTA.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hivatkozások
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live bejelentkezési segítség - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "D:\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'HELYI SZOLGÁLTATÁS')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'HELYI SZOLGÁLTATÁS')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide2] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,L,,4,N (User 'HELYI SZOLGÁLTATÁS')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'HÁLÓZATI SZOLGÁLTATÁS')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'HÁLÓZATI SZOLGÁLTATÁS')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader gyorsindító.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\NUCLEA~1\VideoGet\Plugins\VIDEOG~1.DLL
O9 - Extra 'Tools' menuitem: Add to &VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\NUCLEA~1\VideoGet\Plugins\VIDEOG~1.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) -
http://appldnld.apple.com.edgesuite.net ... plugin.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resour ... se6662.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Uninterruptible Power Supply (UPS) - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
--
End of file - 7298 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\HP Usg Daily.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-11-10 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live bejelentkezési segítség - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-11-10 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-11-10 73728]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"=Mixer.exe /startup []
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2004-11-02 32768]
"HPDJ Taskbar Utility"=C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe [2003-12-05 176128]
"HPHUPD05"=C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe [2003-11-13 49152]
"HP Component Manager"=C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [2004-05-12 241664]
"HP Software Update"=C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe [2003-12-05 49152]
"HPHmon05"=C:\WINDOWS\system32\hphmon05.exe [2004-02-02 495616]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-08-11 413696]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-11-10 136600]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2008-07-01 1447168]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"DAEMON Tools"=D:\DAEMON Tools\daemon.exe [2007-08-16 167368]
"Orb"=C:\Program Files\Winamp Remote\bin\OrbTray.exe [2008-01-07 495616]
C:\Documents and Settings\All Users\Start Menu\Programs\Indítópult
Adobe Reader gyorsindító.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-08-04 46080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-04-10 236928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveTrack"=1
"NoResolveSearch"=1
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"NoDrives"=
"NoDriveAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\BCDC++\DCPlusPlus.exe"="D:\BCDC++\DCPlusPlus.exe:*:Enabled:BCDC++"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\IncrediMail\bin\ImpCnt.exe"="C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail"
"D:\Xfire\Xfire.exe"="D:\Xfire\Xfire.exe:*:Enabled:Xfire"
"C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe"="C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\Program Files\Winamp Remote\bin\Orb.exe"="C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb"
"C:\Program Files\Winamp Remote\bin\OrbTray.exe"="C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray"
"C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe"="C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\EA Sports\FIFA 09\FIFA09.exe"="C:\Program Files\EA Sports\FIFA 09\FIFA09.exe:*:Enabled:FIFA09"
"D:\BearShare\BearShare.exe"="D:\BearShare\BearShare.exe:*:Enabled:BearShare"
"D:\Soldat\Soldat.exe"="D:\Soldat\Soldat.exe:*:Enabled:Soldat"
"D:\Quake III Arena\quake3.exe"="D:\Quake III Arena\quake3.exe:*:Enabled:quake3"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{72cb5ebc-8038-11dd-a662-00196609868b}]
shell\AutoRun\command - G:\Web'n'walk_Helper.exe
======List of files/folders created in the last 3 months======
2008-12-28 19:42:16 ----D---- C:\rsit
2008-12-28 11:20:52 ----D---- C:\Program Files\ESET
2008-12-28 10:58:41 ----D---- C:\_OTMoveIt
2008-12-28 10:57:53 ----A---- C:\OTMoveIt3.exe
2008-12-27 15:00:30 ----DC---- C:\Documents and Settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2008-12-27 14:54:02 ----D---- C:\Program Files\Mplayer
2008-12-27 14:50:20 ----A---- C:\WINDOWS\QIII.INI
2008-12-21 11:47:10 ----A---- C:\zjhdjzjh.txt
2008-12-21 10:33:28 ----A---- C:\WINDOWS\system32\msvcr80.dll
2008-12-21 10:33:27 ----A---- C:\WINDOWS\system32\msvcp80.dll
2008-12-21 10:33:26 ----A---- C:\WINDOWS\system32\eEmpty.exe
2008-12-21 10:33:23 ----A---- C:\WINDOWS\system32\TASKMGR.COM
2008-12-21 10:33:23 ----A---- C:\WINDOWS\system32\T.COM
2008-12-21 10:33:23 ----A---- C:\WINDOWS\REGEDIT.COM
2008-12-21 10:33:23 ----A---- C:\WINDOWS\R.COM
2008-12-21 10:33:14 ----D---- C:\Documents and Settings\All Users\Application Data\MicroWorld
2008-12-21 10:32:36 ----A---- C:\mwav.exe
2008-12-20 18:48:37 ----A---- C:\WINDOWS\system32\javaws.exe
2008-12-20 18:48:37 ----A---- C:\WINDOWS\system32\javaw.exe
2008-12-20 18:48:37 ----A---- C:\WINDOWS\system32\java.exe
2008-12-14 18:22:21 ----D---- C:\Documents and Settings\PISTA\Application Data\Soldat
2008-12-11 21:37:44 ----A---- C:\WINDOWS\system32\xfcodec.dll
2008-12-11 17:07:38 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2008-12-11 17:06:43 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2008-12-11 17:06:18 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2008-12-11 17:06:11 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2008-12-07 12:52:17 ----A---- C:\avenger.txt
2008-12-01 17:26:37 ----A---- C:\kaspersky.txt
2008-11-25 14:21:24 ----D---- C:\Program Files\Free Internet Window Washer
2008-11-25 14:20:24 ----A---- C:\FIWWSetup.exe
2008-11-23 17:48:30 ----A---- C:\WINDOWS\system32\deploytk.dll
2008-11-18 11:14:39 ----SHD---- C:\RECYCLER
2008-11-18 10:41:52 ----D---- C:\WINDOWS\temp
2008-11-18 09:55:48 ----D---- C:\WINDOWS\ERDNT
2008-11-15 18:35:12 ----D---- C:\cel
2008-11-15 18:35:08 ----D---- C:\f
2008-11-15 18:32:37 ----D---- C:\Program Files\AVIConverter
2008-11-12 23:28:15 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2008-11-12 23:28:09 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2008-11-12 23:28:01 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2008-11-09 18:57:34 ----HD---- C:\WINDOWS\PIF
2008-11-09 16:19:12 ----D---- C:\Program Files\Windows Live Safety Center
2008-10-29 16:48:22 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-10-28 16:51:48 ----D---- C:\WINDOWS\system32\xircom
2008-10-28 16:51:48 ----D---- C:\Program Files\xerox
2008-10-28 16:51:47 ----D---- C:\Program Files\microsoft frontpage
2008-10-28 16:51:41 ----D---- C:\WINDOWS\Prefetch
2008-10-28 16:37:15 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2008-10-28 16:37:06 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2008-10-28 16:36:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2008-10-28 16:36:47 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2008-10-28 16:36:35 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2008-10-28 16:36:24 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-10-28 16:36:15 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-10-28 16:36:03 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-10-28 16:35:54 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-10-28 16:35:45 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-10-28 16:35:37 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-10-28 16:35:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-10-28 16:35:15 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-10-28 16:35:06 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-10-28 16:34:55 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-10-28 16:34:47 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-10-28 16:30:00 ----D---- C:\WINDOWS\system32\hu
2008-10-28 16:30:00 ----D---- C:\WINDOWS\l2schemas
2008-10-28 16:29:59 ----D---- C:\WINDOWS\system32\bits
2008-10-28 16:24:17 ----D---- C:\WINDOWS\ServicePackFiles
2008-10-28 16:14:01 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-10-24 16:09:05 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2008-10-21 07:56:01 ----D---- C:\Program Files\VirtualDJ
2008-10-17 20:55:15 ----HDC---- C:\WINDOWS\$NtUninstallKB954211_0$
2008-10-16 18:33:04 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2008-10-16 18:32:57 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2008-10-16 18:32:49 ----HDC---- C:\WINDOWS\$NtUninstallKB957095_0$
2008-10-16 18:31:42 ----HDC---- C:\WINDOWS\$NtUninstallKB956841_0$
2008-10-13 15:54:12 ----D---- C:\Documents and Settings\PISTA\Application Data\Leadertech
2008-10-03 00:46:24 ----A---- C:\WINDOWS\system32\frapsvid.dll
2008-09-30 16:43:34 ----A---- C:\WINDOWS\system32\msxml4.dll
======List of files/folders modified in the last 3 months======
2008-12-29 14:13:36 ----D---- C:\Program Files\HijackThis
2008-12-28 19:42:59 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-12-28 17:46:40 ----D---- C:\Program Files\Mozilla Firefox
2008-12-28 13:36:39 ----D---- C:\WINDOWS
2008-12-28 11:28:43 ----AC---- C:\WINDOWS\system32\PnkBstrB.exe
2008-12-28 11:28:37 ----D---- C:\Documents and Settings\PISTA\Application Data\Xfire
2008-12-28 11:21:31 ----SHD---- C:\WINDOWS\Installer
2008-12-28 11:21:25 ----HD---- C:\WINDOWS\inf
2008-12-28 11:21:25 ----D---- C:\WINDOWS\system32\drivers
2008-12-28 11:21:19 ----D---- C:\WINDOWS\system32\CatRoot2
2008-12-28 11:20:52 ----D---- C:\Program Files
2008-12-28 11:07:31 ----SHD---- C:\System Volume Information
2008-12-28 11:07:31 ----D---- C:\WINDOWS\system32\Restore
2008-12-27 12:36:34 ----D---- C:\Documents and Settings\PISTA\Application Data\LimeWire
2008-12-26 19:33:28 ----A---- C:\WINDOWS\system32\PnkBstrA.exe
2008-12-26 15:49:38 ----AC---- C:\WINDOWS\NeroDigital.ini
2008-12-23 15:09:42 ----D---- C:\WINDOWS\system32
2008-12-20 18:48:36 ----D---- C:\Program Files\Java
2008-12-18 14:52:25 ----D---- C:\WINDOWS\system32\dllcache
2008-12-18 14:52:09 ----HD---- C:\WINDOWS\$hf_mig$
2008-12-16 20:31:26 ----D---- C:\Documents and Settings\PISTA\Application Data\uTorrent
2008-12-14 18:22:44 ----RSD---- C:\WINDOWS\Fonts
2008-12-13 07:39:18 ----A---- C:\WINDOWS\system32\mshtml.dll
2008-12-12 13:02:53 ----D---- C:\WINDOWS\Debug
2008-12-11 17:07:18 ----D---- C:\Program Files\Internet Explorer
2008-12-10 00:24:37 ----AC---- C:\WINDOWS\system32\MRT.exe
2008-12-03 14:46:15 ----D---- C:\WINDOWS\system32\Adobe
2008-12-03 14:45:43 ----D---- C:\Documents and Settings\PISTA\Application Data\Adobe
2008-11-28 21:31:40 ----RD---- C:\Zene 1
2008-11-19 17:06:59 ----SD---- C:\WINDOWS\Tasks
2008-11-18 11:14:39 ----D---- C:\WINDOWS\Minidump
2008-11-18 10:35:05 ----A---- C:\WINDOWS\system.ini
2008-11-18 10:33:29 ----D---- C:\WINDOWS\AppPatch
2008-11-18 10:33:29 ----D---- C:\Program Files\Common Files
2008-11-18 09:57:17 ----D---- C:\WINDOWS\system
2008-11-17 15:54:08 ----D---- C:\WINDOWS\Help
2008-11-12 23:27:40 ----D---- C:\WINDOWS\WinSxS
2008-11-09 16:19:14 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-11-08 13:46:54 ----D---- C:\Program Files\EA Sports
2008-11-08 00:16:04 ----AC---- C:\WINDOWS\wincmd.ini
2008-11-06 16:12:03 ----D---- C:\Program Files\LimeWire
2008-10-28 16:53:30 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-28 16:51:48 ----D---- C:\WINDOWS\system32\wbem
2008-10-28 16:51:48 ----D---- C:\WINDOWS\ime
2008-10-28 16:51:14 ----D---- C:\WINDOWS\system32\Setup
2008-10-28 16:51:14 ----D---- C:\Program Files\Messenger
2008-10-28 16:50:28 ----D---- C:\WINDOWS\security
2008-10-28 16:37:16 ----D---- C:\WINDOWS\system32\CatRoot
2008-10-28 16:30:29 ----D---- C:\WINDOWS\ehome
2008-10-28 16:30:26 ----D---- C:\WINDOWS\system32\inetsrv
2008-10-28 16:30:26 ----D---- C:\WINDOWS\Network Diagnostic
2008-10-28 16:30:03 ----D---- C:\WINDOWS\system32\usmt
2008-10-28 16:30:03 ----D---- C:\WINDOWS\system32\hu-hu
2008-10-28 16:29:59 ----D---- C:\WINDOWS\PeerNet
2008-10-28 16:29:59 ----D---- C:\Program Files\Movie Maker
2008-10-28 16:23:45 ----D---- C:\WINDOWS\system32\npp
2008-10-28 16:23:43 ----D---- C:\WINDOWS\msagent
2008-10-28 16:23:41 ----D---- C:\WINDOWS\srchasst
2008-10-28 16:23:40 ----D---- C:\Program Files\NetMeeting
2008-10-28 16:23:37 ----D---- C:\WINDOWS\system32\Com
2008-10-28 16:23:34 ----D---- C:\Program Files\Windows NT
2008-10-28 16:23:34 ----D---- C:\Program Files\Windows Media Player
2008-10-28 16:23:33 ----D---- C:\Program Files\Outlook Express
2008-10-28 16:23:30 ----D---- C:\Program Files\Common Files\System
2008-10-28 16:23:11 ----D---- C:\WINDOWS\system32\oobe
2008-10-28 16:18:35 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-10-23 13:42:23 ----A---- C:\WINDOWS\system32\gdi32.dll
2008-10-23 11:06:59 ----N---- C:\WINDOWS\system32\tzchange.exe
2008-10-22 16:07:40 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-20 17:02:58 ----HD---- C:\Program Files\InstallShield Installation Information
2008-10-20 11:36:01 ----D---- C:\Program Files\Activision
2008-10-20 08:46:11 ----D---- C:\WINDOWS\system32\Macromed
2008-10-16 21:33:32 ----A---- C:\WINDOWS\system32\wininet.dll
2008-10-16 21:33:32 ----A---- C:\WINDOWS\system32\webcheck.dll
2008-10-16 21:33:31 ----A---- C:\WINDOWS\system32\urlmon.dll
2008-10-16 21:33:30 ----A---- C:\WINDOWS\system32\url.dll
2008-10-16 21:33:30 ----A---- C:\WINDOWS\system32\pngfilt.dll
2008-10-16 21:33:30 ----A---- C:\WINDOWS\system32\occache.dll
2008-10-16 21:33:30 ----A---- C:\WINDOWS\system32\mstime.dll
2008-10-16 21:33:30 ----A---- C:\WINDOWS\system32\msrating.dll
2008-10-16 21:33:29 ----A---- C:\WINDOWS\system32\mshtmled.dll
2008-10-16 21:33:26 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2008-10-16 21:33:26 ----A---- C:\WINDOWS\system32\msfeeds.dll
2008-10-16 21:33:26 ----A---- C:\WINDOWS\system32\jsproxy.dll
2008-10-16 21:33:25 ----A---- C:\WINDOWS\system32\iertutil.dll
2008-10-16 21:33:25 ----A---- C:\WINDOWS\system32\iernonce.dll
2008-10-16 21:33:25 ----A---- C:\WINDOWS\system32\ieframe.dll
2008-10-16 21:33:23 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2008-10-16 21:33:22 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2008-10-16 21:33:22 ----A---- C:\WINDOWS\system32\ieaksie.dll
2008-10-16 21:33:22 ----A---- C:\WINDOWS\system32\ieakeng.dll
2008-10-16 21:33:22 ----A---- C:\WINDOWS\system32\icardie.dll
2008-10-16 21:33:22 ----A---- C:\WINDOWS\system32\extmgr.dll
2008-10-16 21:33:22 ----A---- C:\WINDOWS\system32\dxtrans.dll
2008-10-16 21:33:22 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2008-10-16 21:33:22 ----A---- C:\WINDOWS\system32\advpack.dll
2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuweb.dll
2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2008-10-16 14:13:11 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2008-10-16 14:12:22 ----A---- C:\WINDOWS\system32\wucltui.dll
2008-10-16 14:12:20 ----A---- C:\WINDOWS\system32\wuapi.dll
2008-10-16 14:11:09 ----A---- C:\WINDOWS\system32\ieudinit.exe
2008-10-16 14:09:44 ----AC---- C:\WINDOWS\system32\wups2.dll
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wuauclt.exe
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\cdm.dll
2008-10-16 14:09:40 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2008-10-16 14:08:58 ----AC---- C:\WINDOWS\system32\wups.dll
2008-10-16 14:08:08 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2008-10-16 14:07:32 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2008-10-16 14:06:48 ----A---- C:\WINDOWS\system32\muweb.dll
2008-10-16 14:06:48 ----A---- C:\WINDOWS\system32\mucltui.dll
2008-10-16 14:06:40 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2008-10-15 17:37:43 ----A---- C:\WINDOWS\system32\netapi32.dll
2008-10-15 08:04:53 ----A---- C:\WINDOWS\system32\ieakui.dll
2008-10-13 17:02:26 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-10-13 16:49:48 ----D---- C:\WINDOWS\system32\DirectX
2008-10-13 16:49:39 ----RSD---- C:\WINDOWS\assembly
2008-10-13 16:48:48 ----D---- C:\Program Files\Common Files\Microsoft Shared
2008-10-03 11:04:45 ----A---- C:\WINDOWS\system32\strmdll.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AFS2K;AFS2k; C:\WINDOWS\system32\drivers\AFS2K.sys [2007-05-11 82380]
R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-07-01 53256]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-07-01 34312]
R1 intelppm;Intel processzor illesztőprogramja; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
R1 WS2IFSL;Windows Socket 2.0 - nem IFS-t szolgáltató támogatási környezet; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-26 12032]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-07-01 39944]
R2 irda;IrDA protokoll; C:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-13 88192]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-08-04 1273344]
R3 cmpci;C-Media PCI Audio Driver (WDM); C:\WINDOWS\system32\drivers\cmaudio.sys [2001-10-30 280782]
R3 GCR410P;GEMPLUS GCR410P Serial intelligenskártya-olvasó; C:\WINDOWS\system32\DRIVERS\grserial.sys [2008-04-14 28544]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-05-14 51056]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-05-14 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-05-14 21488]
R3 irsir;Microsoft soros infravörös illesztőprogram; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 Rasirda;WAN miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-03-04 74496]
R3 usbccgp;Microsoft USB általános szülő-illesztőprogram; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 bővített állomásvezérlő miniport illesztőprogramja; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2-engedélyezett hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER osztály; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 USBSTOR;USB háttértár illesztőprogramja; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB univerzális állomásvezérlő miniport illesztőprogramja; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 a0ctr8n5;a0ctr8n5; C:\WINDOWS\system32\drivers\a0ctr8n5.sys []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-08-26 26056]
S3 PnkBstrK;PnkBstrK; \??\C:\WINDOWS\system32\drivers\PnkBstrK.sys []
S3 rkhdrv40;Rootkit Unhooker Driver; C:\WINDOWS\system32\drivers\rkhdrv40.sys []
S3 rtl8139;Realtek RTL8139(A/B/C) alapú PCI gyors Ethernet-adapter NT illesztőprogramja; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 SONYPVU1;Sony USB-szűrő illesztőprogramja (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-08-04 380928]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-07-01 468224]
R2 Irmon;Infravörös figyelő; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-11-10 152984]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-06-20 322120]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-12-26 70968]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2008-12-28 201872]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2003-05-14 65795]
R3 usnjsvc;Messenger megosztási mappák – USN-naplóolvasó szolgáltatás; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-08-05 516096]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2008-07-01 19200]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;A Windows Media Player hálózatmegosztási szolgáltatása; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-10 919040]
-----------------EOF-----------------
hát eléggé hosszú lognak tünik:)
És nem mutatja hogy mi küldi.