Kedves Stell! 2 napja írtam neked, de csak most olvastam, hogy sikerült is gyorsan válaszolnod! Szóval futattam az RSIT és bemásolom ide neked, amit a log jegyzettömbbe kirakott nekem. Az infoból sajnos véletlenül kiléptem és nem csinál újat helyett vmiért, hiába futtatom le újra. Amúgy a problémám annyi, hogy az Avira Antivir állandóan behozott egy Zwunzi nevű fájlt amire azt mondja, hogy egy troja, de hiába kattintottam rá, hogy akkor törölje, vagy helyezze karanténba nem csinálta meg, hanem időröl-időre újra felhozta. Nem tudom, mi ez a zwunzi a C:/Programfiles-ba találtam rá egy Zwunzi mappában volt benn egy exe egy, dll, és egy uninstall fájl. Unistallálni akkor nem engedte. Azért írok múltidőben, mert most, hogy az imént beléptem megint felhozta az Antivir, hogy a zwunzi.dll egy trója, de most sikerült kitörlönie, a megmaradt exe fájlt meg én töröltem sima shift del-el. Nem tudom, hogy ezzel jót csináltam e vagy rosszat, de most azóta nem jelzett a vírusírtó. Nem tudom, kell e most még valamit csinálnom.
Köszi a segítőkészséget!
Íme ezt írja a log:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Rendszergazda at 2009-11-27 17:43:15
Microsoft Windows XP Professional Szervizcsomag 3
System drive C: has 60 GB (73%) free of 82 GB
Total RAM: 2047 MB (75% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:43:18, on 2009.11.27.
Platform: Windows XP Szervizcsomag 3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Documents and Settings\Rendszergazda\Asztal\RSIT.exe
C:\Program Files\HiJackThis\Rendszergazda.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hivatkozások
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Windows Live ID bejelentkezési segítség - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'HELYI SZOLGÁLTATÁS')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'HÁLÓZATI SZOLGÁLTATÁS')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: t-com.lnk = ?
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: E&xportálás Microsoft Excel formátumba -
res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Kutatás - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftup ... 6656482531
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) -
http://mail.bekescsaba.hu:8080/activex/AMC.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D872676F-6E21-426F-BD9F-D4DC1579B60B}: NameServer = 80.95.64.6 80.95.64.7
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Marvell Yukon Service (yksvc) - Unknown owner - RUNDLL32.EXE (file missing)
O23 - Service: Zwunzi Service - Unknown owner - C:\Documents and Settings\All Users\Application Data\Zwunzi\zwunzi127.exe
--
End of file - 7039 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\User_Feed_Synchronization-{D75B0FF6-863A-466D-9D17-0EFEB3516C36}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll [2003-05-15 50376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-05-26 1088296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2009-08-03 202080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID bejelentkezési segítség - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
AcroIEToolbarHelper Class - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [2003-05-15 147456]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-27 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-27 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [2003-05-15 147456]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2009-08-03 1471832]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-11-17 17676288]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2008-06-19 57344]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-27 149280]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2009-07-01 37888]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2009-03-23 1983816]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2009-03-17 767312]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Indítópult^Windows Search.lnk]
C:\PROGRA~1\WI459E~1\WINDOW~1.EXE [2008-05-26 123904]
C:\Documents and Settings\All Users\Start Menu\Programs\Indítópult
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Documents and Settings\Rendszergazda\Start Menu\Programs\Indítópult
t-com.lnk -
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-10-29 143360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"ForceClassicControlPanel"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Winamp Remote\bin\Orb.exe"="C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb"
"C:\Program Files\Winamp Remote\bin\OrbTray.exe"="C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray"
"C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe"="C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1c982005-c2f9-11de-a126-0018f35bb33c}]
shell\AutoRun\command - E:\start.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a23f64fc-c6fe-11de-9b15-0018f35bb33c}]
shell\AutoRun\command - I:\6ruaqx.exe
shell\open\command - I:\6ruaqx.exe
======List of files/folders created in the last 1 months======
2009-11-27 17:23:10 ----D---- C:\rsit
2009-11-25 20:53:20 ----HDC---- C:\WINDOWS\$NtUninstallKB976098-v2$
2009-11-25 20:53:14 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2009-11-25 20:15:27 ----D---- C:\Program Files\HiJackThis
2009-11-22 13:08:50 ----D---- C:\Documents and Settings\All Users\Application Data\Zwunzi
2009-11-22 13:08:32 ----D---- C:\Program Files\Free Video To Audio Converter
2009-11-22 12:58:43 ----A---- C:\WINDOWS\NeroDigital.ini
2009-11-22 12:34:55 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\ABBYY
2009-11-22 12:30:08 ----D---- C:\Program Files\ABBYY FineReader 8.0 Professional Edition
2009-11-22 12:05:47 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\Nero
2009-11-22 11:49:37 ----D---- C:\Program Files\Common Files\Nero
2009-11-12 22:52:56 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2009-11-02 19:36:20 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\Windows Search
2009-11-01 19:36:28 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\dvdcss
2009-11-01 12:57:57 ----D---- C:\WINDOWS\PixArt
2009-11-01 12:57:56 ----D---- C:\Program Files\Trust
2009-11-01 12:57:56 ----D---- C:\Program Files\Common Files\PCCamera
2009-11-01 12:53:08 ----A---- C:\WINDOWS\system32\PAStiSvc.exe
2009-11-01 12:53:02 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2009-11-01 12:51:29 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\ArcSoft
2009-11-01 12:50:56 ----D---- C:\Program Files\Common Files\ArcSoft
2009-11-01 12:50:39 ----A---- C:\WINDOWS\PCDLIB32.DLL
2009-11-01 12:50:35 ----D---- C:\Program Files\ArcSoft
2009-11-01 12:37:58 ----HD---- C:\Program Files\InstallShield Installation Information
2009-11-01 12:37:23 ----D---- C:\WINDOWS\Downloaded Installations
2009-11-01 12:37:22 ----D---- C:\Program Files\Common Files\InstallShield
2009-11-01 12:08:52 ----HD---- C:\Documents and Settings\All Users\Application Data\CanonIJScan
2009-11-01 12:08:51 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\Canon
2009-11-01 12:01:34 ----A---- C:\WINDOWS\system32\CNHMCA.dll
2009-11-01 12:01:34 ----A---- C:\WINDOWS\system32\CNC250U.dll
2009-11-01 12:01:34 ----A---- C:\WINDOWS\system32\CNC250L.dll
2009-11-01 12:01:34 ----A---- C:\WINDOWS\system32\CNC250I.dll
2009-11-01 12:01:34 ----A---- C:\WINDOWS\system32\CNC250C.dll
2009-11-01 12:01:18 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\Canon Easy-WebPrint EX
2009-11-01 12:00:08 ----D---- C:\Program Files\Common Files\CANON
2009-11-01 11:57:30 ----HD---- C:\Documents and Settings\All Users\Application Data\CanonBJ
2009-11-01 11:57:23 ----A---- C:\WINDOWS\system32\CNMLM9W.DLL
2009-11-01 11:57:20 ----HD---- C:\WINDOWS\system32\CanonIJ Uninstaller Information
2009-11-01 11:57:15 ----A---- C:\WINDOWS\system32\CNC250O.dll
2009-11-01 11:57:11 ----A---- C:\WINDOWS\system32\CNMIU9W.DLL
2009-11-01 11:57:04 ----HD---- C:\Program Files\CanonBJ
2009-11-01 11:55:09 ----D---- C:\Program Files\Canon
2009-11-01 10:42:05 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\Jasc Software Inc
2009-11-01 09:58:30 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\AdobeUM
2009-11-01 09:48:41 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\GHISLER
2009-11-01 09:42:50 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\vlc
2009-11-01 09:41:51 ----D---- C:\Program Files\VideoLAN
2009-10-31 20:41:26 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2009-10-31 20:11:22 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\uTorrent
2009-10-31 20:11:20 ----D---- C:\Program Files\uTorrent
2009-10-30 06:41:34 ----A---- C:\WINDOWS\system32\hidserv.dll
2009-10-28 06:15:10 ----HDC---- C:\WINDOWS\$NtUninstallKB971513$
2009-10-28 06:12:00 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2009-10-28 06:11:55 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2009-10-28 06:11:45 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2009-10-28 06:11:36 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2009-10-28 06:11:30 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2009-10-28 06:11:24 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2009-10-28 06:11:18 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2009-10-28 06:11:13 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2009-10-28 06:11:06 ----HDC---- C:\WINDOWS\$NtUninstallKB973525$
2009-10-28 06:02:54 ----D---- C:\Program Files\Windows Live SkyDrive
2009-10-28 05:56:14 ----D---- C:\Program Files\Common Files\Windows Live
2009-10-28 05:55:44 ----D---- C:\WINDOWS\ie8updates
2009-10-28 05:54:37 ----D---- C:\Program Files\Microsoft
2009-10-28 05:42:59 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-10-28 05:39:13 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\Mozilla
2009-10-28 05:38:26 ----D---- C:\Program Files\Axis Communications
2009-10-28 05:38:14 ----D---- C:\WINDOWS\Sun
2009-10-28 05:37:54 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\Macromedia
2009-10-28 05:37:13 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\Adobe
2009-10-28 05:36:00 ----D---- C:\WINDOWS\pss
======List of files/folders modified in the last 1 months======
2009-11-27 17:33:52 ----D---- C:\Program Files
2009-11-27 17:23:25 ----D---- C:\WINDOWS\Prefetch
2009-11-27 17:17:39 ----D---- C:\WINDOWS\Temp
2009-11-27 17:17:35 ----D---- C:\WINDOWS\system32\CatRoot2
2009-11-27 17:17:34 ----D---- C:\Program Files\Mozilla Firefox
2009-11-26 09:22:48 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-11-26 09:18:47 ----D---- C:\WINDOWS
2009-11-26 09:16:58 ----D---- C:\WINDOWS\system32
2009-11-25 20:53:23 ----HD---- C:\WINDOWS\inf
2009-11-25 20:53:19 ----A---- C:\WINDOWS\imsins.BAK
2009-11-25 20:53:16 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-11-25 20:53:04 ----HD---- C:\WINDOWS\$hf_mig$
2009-11-25 20:53:02 ----SHD---- C:\WINDOWS\Installer
2009-11-25 20:53:00 ----D---- C:\WINDOWS\WinSxS
2009-11-22 12:00:15 ----D---- C:\Program Files\Nero
2009-11-22 11:52:33 ----D---- C:\Documents and Settings\All Users\Application Data\Nero
2009-11-22 11:49:37 ----D---- C:\Program Files\Common Files
2009-11-15 19:32:55 ----SD---- C:\Documents and Settings\Rendszergazda\Application Data\Microsoft
2009-11-13 20:32:02 ----D---- C:\WINDOWS\Help
2009-11-12 22:55:18 ----A---- C:\WINDOWS\win.ini
2009-11-05 18:36:21 ----A---- C:\WINDOWS\system32\MRT.exe
2009-11-02 19:14:52 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-11-01 12:59:13 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\Skype
2009-11-01 12:58:04 ----D---- C:\WINDOWS\system32\CatRoot
2009-11-01 12:57:57 ----D---- C:\WINDOWS\twain_32
2009-11-01 12:57:57 ----D---- C:\WINDOWS\system32\drivers
2009-11-01 12:01:35 ----D---- C:\WINDOWS\Media
2009-11-01 09:58:17 ----D---- C:\Program Files\Common Files\Adobe
2009-11-01 09:57:34 ----RSD---- C:\WINDOWS\Fonts
2009-11-01 09:57:27 ----D---- C:\Program Files\Adobe
2009-11-01 09:54:10 ----D---- C:\Program Files\totalcmd
2009-10-31 20:41:27 ----D---- C:\WINDOWS\system32\DirectX
2009-10-28 16:07:15 ----A---- C:\WINDOWS\system32\tzchange.exe
2009-10-28 06:41:51 ----D---- C:\WINDOWS\Microsoft.NET
2009-10-28 06:41:46 ----RSD---- C:\WINDOWS\assembly
2009-10-28 06:27:54 ----SD---- C:\WINDOWS\Tasks
2009-10-28 06:20:57 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-10-28 06:16:44 ----D---- C:\Program Files\Internet Explorer
2009-10-28 06:02:59 ----D---- C:\Program Files\Windows Live
2009-10-28 05:54:40 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-10-28 05:54:06 ----D---- C:\WINDOWS\Registration
2009-10-28 05:43:57 ----D---- C:\Documents and Settings\Rendszergazda\Application Data\Winamp
2009-10-28 05:43:16 ----D---- C:\Program Files\Winamp
2009-10-28 05:38:28 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-10-28 05:37:24 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-10-28 05:36:10 ----SH---- C:\boot.ini
2009-10-28 05:36:09 ----A---- C:\WINDOWS\system.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 intelppm;Intel processzor illesztőprogramja; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
R1 kbdhid;Billentyűzet HID-illesztőprogram; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-10-28 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-10-28 55656]
R3 Arp1394;1394 ARP ügyfélprotokoll; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-10-29 3341824]
R3 HDAudBus;Microsoft UAA busz-illesztőprogram - High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Microsoft HID osztályú illesztőprogram; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-11-25 4952576]
R3 mouhid;Egér HID-illesztőprogram; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-26 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 hálózati illesztőprogram; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 PAC207;Trust WB-1400T Webcam; C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-02-24 162176]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 usbehci;Microsoft USB 2.0 bővített állomásvezérlő miniport illesztőprogramja; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2-engedélyezett hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Microsoft USB univerzális állomásvezérlő miniport illesztőprogramja; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2008-09-19 290432]
S3 CCDECODE;Feliratdekódoló; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 MSTEE;Microsoft Streaming Tee/Sink - Sink átalakító; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI kodek; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV-/videokapcsolat; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft USB általános szülő-illesztőprogram; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER osztály; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB-képolvasó illesztőprogramja; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB háttértár illesztőprogramja; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WSTCODEC;World Standard Teletext kodek; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-10-28 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-10-28 185089]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-10-29 585728]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-27 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-09-23 935208]
R2 STI Simulator;STI Simulator; C:\WINDOWS\System32\PAStiSvc.exe [2005-01-14 53248]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 1533808]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
R2 yksvc;Marvell Yukon Service; ykx32mpcoinst,serviceStartProc []
S2 Zwunzi Service;Zwunzi Service; C:\Documents and Settings\All Users\Application Data\Zwunzi\zwunzi127.exe [2009-11-12 58720]
S3 aspnet_state;ASP.NET-állapotszolgáltatás; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;A Windows Media Player hálózatmegosztási szolgáltatása; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-10 919040]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp portmegosztási szolgáltatás; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------