Zdravím, nevím, co se děje, v notasu mám AV ..MSE, který mě neustále hlásí, že nebyla dlouho spuštěna kontrola, hrozí ohrožení..přitom dopolko kontrolovala...svítí oranžově, ale jak udělám novou kontrolu, šup zezelená...
Dnes kompletní kontrola MSE, opět to samé,za dopoledne 3 x .. beru log zpět a pokusím se to nějak vyřešit sama, bez funkčního AV- nemůžu být,.
Hledala jsem různé opravy na microsoftu, ale nakonec jsem ho odinstalovala a pak znovu nainstalovala, zatím drží..log vložím, až budeš..

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Pro vyosek, prosím o kontrolu logu
Moderátor: Moderátoři
Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
- jaruneczka
- Vzorný návštěvník
- Příspěvky: 417
- Registrován: 09 čer 2008 11:45
- Bydliště: Ostrava
Re: Pro vyosek, prosím o kontrolu logu
Ahoj,
ja bych to videl spis na nejakou chybu MSE, pokud je nyni OK...
Ale preventivne log z RSIT vlozit muzes...
ja bych to videl spis na nejakou chybu MSE, pokud je nyni OK...
Ale preventivne log z RSIT vlozit muzes...
- jaruneczka
- Vzorný návštěvník
- Příspěvky: 417
- Registrován: 09 čer 2008 11:45
- Bydliště: Ostrava
Re: Pro vyosek, prosím o kontrolu logu
Logfile of random's system information tool 1.09 (written by random/random)
Run by Jaruneczka at 2012-05-13 07:18:47
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 260 GB (90%) free of 290 GB
Total RAM: 1900 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:18:51, on 13.5.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Launch Manager\LMworker.exe
C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe
C:\Users\Jaruneczka\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Program Files\trend micro\Jaruneczka.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'Default user')
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files (x86)\ICQ7.7\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files (x86)\ICQ7.7\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EgisTec Ticket Service - Egis Technology Inc. - C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe
O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: GREGService - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
O23 - Service: Guard.Mail.ru - Unknown owner - C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Live Updater Service - Acer Incorporated - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI IScheduleSvc - NTI Corporation - C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9701 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE"
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Launch Manager\LMworker.exe"
"C:\Program Files (x86)\Launch Manager\LMutilps32.exe" --system-level-mutex="Local\{B904A927-FE6B-48fd-8C83-6B807BED1F9C}"
"C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe"
"C:\Program Files (x86)\Acer\Registration\GREGsvc.exe"
"C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe"
"C:\Program Files\Acer\Acer Updater\UpdaterService.exe"
"C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
taskeng.exe {EC7D5D24-AE8F-4EB6-ACCA-BBA6186C9291}
"C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe"
"C:\Users\Jaruneczka\AppData\Roaming\Google\Google Talk\googletalk.exe" /startmenu
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files\EgisTec IPS\PMMUpdate.exe"
"C:\Program Files\EgisTec IPS\EgisUpdate.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 3396
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-2994249906-4171692639-4229379737-10006_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-2994249906-4171692639-4229379737-10006 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Users\Jaruneczka\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Jaruneczka\AppData\Roaming\Mozilla\Firefox\Profiles\m1nb7omo.default
prefs.js - "browser.startup.homepage" - "www.centrum.cz"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.3.6&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.235 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0]
"Description"=WildTangent Games App Presence Detector Plugin
"Path"=C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.235 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_235.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2012-04-26 325408]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17 3855520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-06-07 1152264]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-04-26 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-06-07 1152264]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2012-03-26 1271168]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AmIcoSinglun64]
C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2011-01-26 368728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcadeMovieService]
C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [2011-08-27 177448]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BackupManagerTray]
C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [2011-04-24 297280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
C:\Users\Jaruneczka\AppData\Roaming\Google\Google Talk\googletalk.exe [2007-01-01 3739648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Guard.Mail.ru.gui]
C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe [2012-04-26 1564368]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\Windows\system32\hkcmd.exe [2011-05-09 391960]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\Windows\system32\igfxtray.exe [2011-05-09 168216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
C:\Program Files (x86)\Launch Manager\LManager.exe [2011-03-14 1081424]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\Windows\system32\igfxpers.exe [2011-05-09 419096]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power Management]
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [2011-08-02 1831016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDVCPL]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-06-09 11860072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SuiteTray]
C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [2011-09-20 341360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-01-18 254696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-10-08 2392360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-03-25 385024]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-05-13 07:18:47 ----D---- C:\rsit
2012-05-12 11:16:04 ----D---- C:\Program Files (x86)\Microsoft Security Client
2012-05-12 11:16:02 ----D---- C:\Program Files\Microsoft Security Client
2012-05-11 13:47:59 ----D---- C:\Luba stacionář
2012-05-09 08:57:03 ----A---- C:\Windows\system32\DWrite.dll
2012-05-09 08:57:02 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2012-05-09 08:57:02 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-05-09 08:57:01 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2012-05-09 08:57:01 ----A---- C:\Windows\system32\win32k.sys
2012-05-09 08:57:00 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2012-05-09 08:56:50 ----A---- C:\Windows\system32\drivers\partmgr.sys
2012-05-09 08:56:38 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-05-01 21:41:03 ----D---- C:\ProgramData\Malwarebytes
2012-04-30 22:01:03 ----D---- C:\Program Files\Microsoft Silverlight
2012-04-30 22:01:03 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2012-04-30 22:00:37 ----D---- C:\f13c2529636ec171416a
2012-04-27 18:48:22 ----D---- C:\Program Files (x86)\MyPlayCity.com
2012-04-27 11:44:21 ----D---- C:\ProgramData\rionix
2012-04-27 11:43:32 ----D---- C:\Program Files (x86)\ReflexiveArcade
2012-04-27 09:57:16 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-04-27 09:57:03 ----D---- C:\Windows\system32\Macromed
2012-04-26 21:59:31 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2012-04-26 21:30:25 ----D---- C:\Users\Jaruneczka\AppData\Roaming\newsXpresso
2012-04-26 20:03:37 ----D---- C:\Windows\Sun
2012-04-26 18:49:34 ----A---- C:\Windows\SYSWOW64\javaws.exe
2012-04-26 18:49:34 ----A---- C:\Windows\SYSWOW64\javaw.exe
2012-04-26 18:49:34 ----A---- C:\Windows\SYSWOW64\java.exe
2012-04-26 18:49:20 ----D---- C:\Program Files (x86)\Java
2012-04-26 18:48:55 ----AHD---- C:\book
2012-04-26 18:46:15 ----D---- C:\Users\Jaruneczka\AppData\Roaming\Identities
2012-04-26 18:42:06 ----D---- C:\Users\Jaruneczka\AppData\Roaming\CyberLink
2012-04-26 18:41:31 ----SD---- C:\Users\Jaruneczka\AppData\Roaming\Microsoft
2012-04-26 18:41:31 ----D---- C:\Users\Jaruneczka\AppData\Roaming\Media Center Programs
2012-04-26 18:41:31 ----D---- C:\Users\Jaruneczka\AppData\Roaming\Macromedia
2012-04-26 18:40:12 ----SHD---- C:\Recovery
2012-04-26 16:00:42 ----D---- C:\Fotky
2012-04-26 16:00:01 ----D---- C:\Users\Jaruneczka\AppData\Roaming\WinRAR
2012-04-26 15:59:22 ----D---- C:\Program Files (x86)\WinRAR
2012-04-26 15:57:50 ----D---- C:\Stažené
2012-04-26 15:42:32 ----D---- C:\Zálohy
2012-04-26 15:30:49 ----D---- C:\Program Files\trend micro
2012-04-26 15:13:44 ----D---- C:\Users\Jaruneczka\AppData\Roaming\IrfanView
2012-04-26 15:13:39 ----D---- C:\Program Files (x86)\IrfanView
2012-04-26 14:59:53 ----D---- C:\Users\Jaruneczka\AppData\Roaming\ICQ Search
2012-04-26 14:59:47 ----D---- C:\Program Files (x86)\Guard-ICQ
2012-04-26 14:59:44 ----D---- C:\Program Files (x86)\ICQ6Toolbar
2012-04-26 14:59:42 ----D---- C:\ProgramData\ICQ
2012-04-26 14:59:20 ----D---- C:\Users\Jaruneczka\AppData\Roaming\ICQ
2012-04-26 14:59:07 ----D---- C:\Program Files (x86)\ICQ7.7
2012-04-26 14:53:00 ----D---- C:\Users\Jaruneczka\AppData\Roaming\OpenOffice.org
2012-04-26 14:50:29 ----D---- C:\Program Files (x86)\OpenOffice.org 3
2012-04-26 14:50:04 ----D---- C:\ProgramData\Sun
2012-04-26 14:50:00 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2012-04-26 14:43:55 ----D---- C:\Users\Jaruneczka\AppData\Roaming\Google
2012-04-26 14:30:55 ----D---- C:\Users\Jaruneczka\AppData\Roaming\Thunderbird
2012-04-26 14:30:42 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2012-04-26 14:24:20 ----D---- C:\Program Files (x86)\Microsoft.NET
2012-04-26 14:22:02 ----D---- C:\Windows\SYSWOW64\Wat
2012-04-26 14:22:01 ----D---- C:\Windows\system32\Wat
2012-04-26 14:09:57 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-04-26 14:09:57 ----A---- C:\Windows\system32\mshtmled.dll
2012-04-26 14:09:56 ----A---- C:\Windows\SYSWOW64\url.dll
2012-04-26 14:09:56 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-04-26 14:09:56 ----A---- C:\Windows\system32\jscript9.dll
2012-04-26 14:09:56 ----A---- C:\Windows\system32\iertutil.dll
2012-04-26 14:09:55 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2012-04-26 14:09:55 ----A---- C:\Windows\SYSWOW64\jscript.dll
2012-04-26 14:09:55 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-04-26 14:09:55 ----A---- C:\Windows\system32\url.dll
2012-04-26 14:09:55 ----A---- C:\Windows\system32\ieui.dll
2012-04-26 14:09:54 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-04-26 14:09:54 ----A---- C:\Windows\system32\urlmon.dll
2012-04-26 14:09:54 ----A---- C:\Windows\system32\jsproxy.dll
2012-04-26 14:09:54 ----A---- C:\Windows\system32\jscript.dll
2012-04-26 14:09:53 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-04-26 14:09:53 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-04-26 14:09:53 ----A---- C:\Windows\system32\wininet.dll
2012-04-26 14:09:52 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-04-26 14:09:51 ----A---- C:\Windows\system32\mshtml.dll
2012-04-26 14:09:50 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-04-26 14:09:48 ----A---- C:\Windows\system32\ieframe.dll
2012-04-26 14:04:47 ----A---- C:\Windows\system32\MRT.exe
2012-04-26 14:04:37 ----A---- C:\Windows\SYSWOW64\wmi.dll
2012-04-26 14:04:37 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2012-04-26 14:04:37 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2012-04-26 14:04:37 ----A---- C:\Windows\system32\wmi.dll
2012-04-26 14:04:37 ----A---- C:\Windows\system32\wintrust.dll
2012-04-26 14:04:37 ----A---- C:\Windows\system32\imagehlp.dll
2012-04-26 14:04:37 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2012-04-26 14:02:18 ----A---- C:\Windows\system32\schannel.dll
2012-04-26 14:02:18 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2012-04-26 14:02:17 ----A---- C:\Windows\SYSWOW64\webio.dll
2012-04-26 14:02:17 ----A---- C:\Windows\SYSWOW64\schannel.dll
2012-04-26 14:02:17 ----A---- C:\Windows\system32\webio.dll
2012-04-26 14:02:17 ----A---- C:\Windows\system32\lsass.exe
2012-04-26 14:02:17 ----A---- C:\Windows\system32\lsasrv.dll
2012-04-26 14:02:17 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2012-04-26 14:02:17 ----A---- C:\Windows\system32\drivers\cng.sys
2012-04-26 14:02:16 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2012-04-26 14:02:16 ----A---- C:\Windows\SYSWOW64\secur32.dll
2012-04-26 14:02:16 ----A---- C:\Windows\system32\sspisrv.dll
2012-04-26 14:02:16 ----A---- C:\Windows\system32\sspicli.dll
2012-04-26 14:02:16 ----A---- C:\Windows\system32\secur32.dll
2012-04-26 14:02:13 ----A---- C:\Windows\system32\shell32.dll
2012-04-26 14:02:12 ----A---- C:\Windows\SYSWOW64\shell32.dll
2012-04-26 14:02:11 ----A---- C:\Windows\system32\ntshrui.dll
2012-04-26 14:02:10 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2012-04-26 14:02:04 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2012-04-26 14:02:04 ----A---- C:\Windows\system32\poqexec.exe
2012-04-26 14:01:57 ----A---- C:\Windows\system32\quartz.dll
2012-04-26 14:01:56 ----A---- C:\Windows\SYSWOW64\quartz.dll
2012-04-26 14:01:56 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2012-04-26 14:01:56 ----A---- C:\Windows\system32\qdvd.dll
2012-04-26 14:01:54 ----A---- C:\Windows\system32\XpsPrint.dll
2012-04-26 14:01:53 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2012-04-26 14:01:50 ----A---- C:\Windows\system32\psisdecd.dll
2012-04-26 14:01:49 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2012-04-26 14:01:44 ----A---- C:\Windows\system32\rdrmemptylst.exe
2012-04-26 14:01:44 ----A---- C:\Windows\system32\rdpwsx.dll
2012-04-26 14:01:44 ----A---- C:\Windows\system32\rdpcorekmts.dll
2012-04-26 14:01:42 ----A---- C:\Windows\system32\csrsrv.dll
2012-04-26 14:01:40 ----A---- C:\Windows\SYSWOW64\msvcrt.dll
2012-04-26 14:01:40 ----A---- C:\Windows\system32\msvcrt.dll
2012-04-26 14:01:38 ----A---- C:\Windows\system32\drivers\afd.sys
2012-04-26 14:01:36 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2012-04-26 14:01:36 ----A---- C:\Windows\system32\ntdll.dll
2012-04-26 14:00:57 ----A---- C:\Windows\SYSWOW64\tzres.dll
2012-04-26 14:00:57 ----A---- C:\Windows\system32\tzres.dll
2012-04-26 14:00:16 ----A---- C:\Windows\system32\EncDec.dll
2012-04-26 14:00:15 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2012-04-26 14:00:14 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2012-04-26 14:00:14 ----A---- C:\Windows\system32\oleacc.dll
2012-04-26 14:00:13 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2012-04-26 14:00:13 ----A---- C:\Windows\system32\oleaut32.dll
2012-04-26 13:57:40 ----A---- C:\Windows\system32\packager.dll
2012-04-26 13:57:39 ----A---- C:\Windows\SYSWOW64\packager.dll
2012-04-26 13:57:31 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2012-04-26 13:57:31 ----A---- C:\Windows\system32\rdpcore.dll
2012-04-26 13:57:30 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2012-04-26 13:57:30 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2012-04-26 12:42:09 ----D---- C:\Users\Jaruneczka\AppData\Roaming\Mozilla
2012-04-26 12:42:01 ----D---- C:\ProgramData\Mozilla
2012-04-26 12:42:01 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2012-04-26 12:41:57 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-04-26 12:40:03 ----D---- C:\Program Files\CCleaner
2012-04-26 12:23:33 ----D---- C:\Users\Jaruneczka\AppData\Roaming\Adobe
2012-04-26 12:17:12 ----D---- C:\ProgramData\clear.fi
2012-04-26 11:54:49 ----D---- C:\Users\Jaruneczka\AppData\Roaming\Skype
======List of files/folders modified in the last 1 month======
2012-05-13 07:18:22 ----D---- C:\Windows\Temp
2012-05-13 07:18:22 ----D---- C:\Windows
2012-05-13 06:51:00 ----D---- C:\Windows\system32\config
2012-05-13 06:41:12 ----A---- C:\Windows\SYSWOW64\log.txt
2012-05-13 05:06:56 ----D---- C:\Windows\Prefetch
2012-05-12 16:30:21 ----D---- C:\Windows\SoftwareDistribution
2012-05-12 16:10:47 ----D---- C:\Program Files\Common Files
2012-05-12 16:09:45 ----D---- C:\Program Files (x86)\Common Files
2012-05-12 12:12:32 ----SHD---- C:\System Volume Information
2012-05-12 11:42:25 ----RD---- C:\Program Files (x86)
2012-05-12 11:41:21 ----D---- C:\Windows\debug
2012-05-12 11:40:51 ----D---- C:\Windows\system32\catroot
2012-05-12 11:16:07 ----SHD---- C:\Windows\Installer
2012-05-12 11:16:05 ----D---- C:\Windows\SysWOW64
2012-05-12 11:16:05 ----D---- C:\Windows\system32\drivers
2012-05-12 11:16:05 ----D---- C:\Windows\inf
2012-05-12 11:16:04 ----D---- C:\Windows\system32\catroot2
2012-05-12 11:16:02 ----RD---- C:\Program Files
2012-05-12 11:05:57 ----D---- C:\Windows\Downloaded Program Files
2012-05-12 10:03:19 ----RSD---- C:\Windows\assembly
2012-05-12 10:03:19 ----D---- C:\Windows\Microsoft.NET
2012-05-12 09:28:19 ----D---- C:\Windows\system32\wdi
2012-05-12 09:27:54 ----D---- C:\Windows\SYSWOW64\config
2012-05-12 06:39:39 ----D---- C:\Windows\Tasks
2012-05-12 06:39:39 ----D---- C:\Windows\system32\Tasks
2012-05-11 15:21:00 ----SD---- C:\ProgramData\Microsoft
2012-05-09 09:15:03 ----D---- C:\Windows\winsxs
2012-05-09 09:13:35 ----D---- C:\Windows\System32
2012-05-09 09:05:49 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-05-09 08:58:05 ----D---- C:\Program Files\Windows Journal
2012-05-03 13:46:29 ----D---- C:\ProgramData\Adobe
2012-05-01 21:41:03 ----HD---- C:\ProgramData
2012-05-01 05:40:09 ----D---- C:\Windows\system32\NDF
2012-04-27 07:19:05 ----D---- C:\Windows\system32\drivers\etc
2012-04-27 03:34:55 ----D---- C:\Windows\rescache
2012-04-26 22:59:21 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-04-26 21:50:19 ----D---- C:\ProgramData\McAfee
2012-04-26 21:49:07 ----D---- C:\Windows\system32\DriverStore
2012-04-26 18:49:35 ----D---- C:\Windows\system32\OEM
2012-04-26 18:49:05 ----HD---- C:\OEM
2012-04-26 18:48:24 ----AD---- C:\Windows\DeployWinRE2
2012-04-26 18:46:42 ----D---- C:\ProgramData\oem
2012-04-26 18:46:10 ----SHD---- C:\$Recycle.Bin
2012-04-26 18:41:31 ----RD---- C:\Users
2012-04-26 18:40:12 ----D---- C:\Windows\system32\Recovery
2012-04-26 14:59:47 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-04-26 14:51:04 ----RSD---- C:\Windows\Fonts
2012-04-26 14:33:11 ----D---- C:\Windows\SYSWOW64\cs-CZ
2012-04-26 14:33:11 ----D---- C:\Windows\system32\cs-CZ
2012-04-26 14:24:25 ----D---- C:\Windows\SYSWOW64\en-US
2012-04-26 14:24:25 ----D---- C:\Windows\system32\en-US
2012-04-26 14:23:39 ----D---- C:\Windows\Logs
2012-04-26 14:16:19 ----D---- C:\Windows\ehome
2012-04-26 14:16:19 ----D---- C:\Program Files\Common Files\System
2012-04-26 14:16:14 ----D---- C:\Windows\SYSWOW64\migration
2012-04-26 14:16:14 ----D---- C:\Program Files\Internet Explorer
2012-04-26 14:16:14 ----D---- C:\Program Files (x86)\Internet Explorer
2012-04-26 14:16:13 ----D---- C:\Windows\system32\migration
2012-04-26 14:16:06 ----D---- C:\Windows\SYSWOW64\sk-SK
2012-04-26 14:16:06 ----D---- C:\Windows\system32\sk-SK
2012-04-26 14:03:03 ----D---- C:\Windows\system32\restore
2012-04-26 12:50:28 ----D---- C:\Windows\Panther
2012-04-26 12:28:21 ----RD---- C:\Program Files (x86)\Skype
2012-04-26 12:27:58 ----D---- C:\ProgramData\Skype
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iaStor.sys [2010-09-14 437272]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2012-03-20 203888]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2011-12-23 22648]
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2011-12-23 20520]
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2011-12-23 62776]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-03-17 2712064]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2011-03-25 12262336]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-06-14 2899176]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2011-04-20 169584]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2011-09-20 18432]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-10-08 1395248]
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2011-09-20 17408]
S3 AmUStor;AM USB Stroage Driver; C:\Windows\system32\drivers\AmUStor.SYS [2011-01-14 74840]
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 98688]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-03 63928]
R2 BBUpdate;BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-05-13 249648]
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2011-03-14 352336]
R2 ePowerSvc;ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2011-08-02 872552]
R2 GREGService;GREGService; C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2011-05-30 36456]
R2 Guard.Mail.ru;Guard.Mail.ru; C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe [2012-04-26 1564368]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-14 13336]
R2 Live Updater Service;Live Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2011-04-22 244624]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-02-01 326168]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2012-03-26 12600]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [2011-04-24 256832]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-01 2656280]
R3 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-29 2292096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
S3 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-06-07 191752]
S3 EgisTec Ticket Service;EgisTec Ticket Service; C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [2011-06-21 173424]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-12-23 655624]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-21 129976]
S3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-04-26 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
-----------------EOF-----------------
Run by Jaruneczka at 2012-05-13 07:18:47
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 260 GB (90%) free of 290 GB
Total RAM: 1900 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:18:51, on 13.5.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Launch Manager\LMworker.exe
C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe
C:\Users\Jaruneczka\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Program Files\trend micro\Jaruneczka.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'Default user')
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files (x86)\ICQ7.7\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files (x86)\ICQ7.7\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EgisTec Ticket Service - Egis Technology Inc. - C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe
O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: GREGService - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
O23 - Service: Guard.Mail.ru - Unknown owner - C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Live Updater Service - Acer Incorporated - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI IScheduleSvc - NTI Corporation - C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9701 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE"
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Launch Manager\LMworker.exe"
"C:\Program Files (x86)\Launch Manager\LMutilps32.exe" --system-level-mutex="Local\{B904A927-FE6B-48fd-8C83-6B807BED1F9C}"
"C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe"
"C:\Program Files (x86)\Acer\Registration\GREGsvc.exe"
"C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe"
"C:\Program Files\Acer\Acer Updater\UpdaterService.exe"
"C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
taskeng.exe {EC7D5D24-AE8F-4EB6-ACCA-BBA6186C9291}
"C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe"
"C:\Users\Jaruneczka\AppData\Roaming\Google\Google Talk\googletalk.exe" /startmenu
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files\EgisTec IPS\PMMUpdate.exe"
"C:\Program Files\EgisTec IPS\EgisUpdate.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 3396
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-2994249906-4171692639-4229379737-10006_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-2994249906-4171692639-4229379737-10006 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Users\Jaruneczka\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Jaruneczka\AppData\Roaming\Mozilla\Firefox\Profiles\m1nb7omo.default
prefs.js - "browser.startup.homepage" - "www.centrum.cz"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.3.6&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.235 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0]
"Description"=WildTangent Games App Presence Detector Plugin
"Path"=C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.235 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_235.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2012-04-26 325408]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17 3855520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-06-07 1152264]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-04-26 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-06-07 1152264]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2012-03-26 1271168]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AmIcoSinglun64]
C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2011-01-26 368728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcadeMovieService]
C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [2011-08-27 177448]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BackupManagerTray]
C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [2011-04-24 297280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
C:\Users\Jaruneczka\AppData\Roaming\Google\Google Talk\googletalk.exe [2007-01-01 3739648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Guard.Mail.ru.gui]
C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe [2012-04-26 1564368]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\Windows\system32\hkcmd.exe [2011-05-09 391960]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\Windows\system32\igfxtray.exe [2011-05-09 168216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
C:\Program Files (x86)\Launch Manager\LManager.exe [2011-03-14 1081424]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\Windows\system32\igfxpers.exe [2011-05-09 419096]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power Management]
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [2011-08-02 1831016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDVCPL]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-06-09 11860072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SuiteTray]
C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [2011-09-20 341360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-01-18 254696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-10-08 2392360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-03-25 385024]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-05-13 07:18:47 ----D---- C:\rsit
2012-05-12 11:16:04 ----D---- C:\Program Files (x86)\Microsoft Security Client
2012-05-12 11:16:02 ----D---- C:\Program Files\Microsoft Security Client
2012-05-11 13:47:59 ----D---- C:\Luba stacionář
2012-05-09 08:57:03 ----A---- C:\Windows\system32\DWrite.dll
2012-05-09 08:57:02 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2012-05-09 08:57:02 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-05-09 08:57:01 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2012-05-09 08:57:01 ----A---- C:\Windows\system32\win32k.sys
2012-05-09 08:57:00 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2012-05-09 08:56:50 ----A---- C:\Windows\system32\drivers\partmgr.sys
2012-05-09 08:56:38 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-05-01 21:41:03 ----D---- C:\ProgramData\Malwarebytes
2012-04-30 22:01:03 ----D---- C:\Program Files\Microsoft Silverlight
2012-04-30 22:01:03 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2012-04-30 22:00:37 ----D---- C:\f13c2529636ec171416a
2012-04-27 18:48:22 ----D---- C:\Program Files (x86)\MyPlayCity.com
2012-04-27 11:44:21 ----D---- C:\ProgramData\rionix
2012-04-27 11:43:32 ----D---- C:\Program Files (x86)\ReflexiveArcade
2012-04-27 09:57:16 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-04-27 09:57:03 ----D---- C:\Windows\system32\Macromed
2012-04-26 21:59:31 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2012-04-26 21:30:25 ----D---- C:\Users\Jaruneczka\AppData\Roaming\newsXpresso
2012-04-26 20:03:37 ----D---- C:\Windows\Sun
2012-04-26 18:49:34 ----A---- C:\Windows\SYSWOW64\javaws.exe
2012-04-26 18:49:34 ----A---- C:\Windows\SYSWOW64\javaw.exe
2012-04-26 18:49:34 ----A---- C:\Windows\SYSWOW64\java.exe
2012-04-26 18:49:20 ----D---- C:\Program Files (x86)\Java
2012-04-26 18:48:55 ----AHD---- C:\book
2012-04-26 18:46:15 ----D---- C:\Users\Jaruneczka\AppData\Roaming\Identities
2012-04-26 18:42:06 ----D---- C:\Users\Jaruneczka\AppData\Roaming\CyberLink
2012-04-26 18:41:31 ----SD---- C:\Users\Jaruneczka\AppData\Roaming\Microsoft
2012-04-26 18:41:31 ----D---- C:\Users\Jaruneczka\AppData\Roaming\Media Center Programs
2012-04-26 18:41:31 ----D---- C:\Users\Jaruneczka\AppData\Roaming\Macromedia
2012-04-26 18:40:12 ----SHD---- C:\Recovery
2012-04-26 16:00:42 ----D---- C:\Fotky
2012-04-26 16:00:01 ----D---- C:\Users\Jaruneczka\AppData\Roaming\WinRAR
2012-04-26 15:59:22 ----D---- C:\Program Files (x86)\WinRAR
2012-04-26 15:57:50 ----D---- C:\Stažené
2012-04-26 15:42:32 ----D---- C:\Zálohy
2012-04-26 15:30:49 ----D---- C:\Program Files\trend micro
2012-04-26 15:13:44 ----D---- C:\Users\Jaruneczka\AppData\Roaming\IrfanView
2012-04-26 15:13:39 ----D---- C:\Program Files (x86)\IrfanView
2012-04-26 14:59:53 ----D---- C:\Users\Jaruneczka\AppData\Roaming\ICQ Search
2012-04-26 14:59:47 ----D---- C:\Program Files (x86)\Guard-ICQ
2012-04-26 14:59:44 ----D---- C:\Program Files (x86)\ICQ6Toolbar
2012-04-26 14:59:42 ----D---- C:\ProgramData\ICQ
2012-04-26 14:59:20 ----D---- C:\Users\Jaruneczka\AppData\Roaming\ICQ
2012-04-26 14:59:07 ----D---- C:\Program Files (x86)\ICQ7.7
2012-04-26 14:53:00 ----D---- C:\Users\Jaruneczka\AppData\Roaming\OpenOffice.org
2012-04-26 14:50:29 ----D---- C:\Program Files (x86)\OpenOffice.org 3
2012-04-26 14:50:04 ----D---- C:\ProgramData\Sun
2012-04-26 14:50:00 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2012-04-26 14:43:55 ----D---- C:\Users\Jaruneczka\AppData\Roaming\Google
2012-04-26 14:30:55 ----D---- C:\Users\Jaruneczka\AppData\Roaming\Thunderbird
2012-04-26 14:30:42 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2012-04-26 14:24:20 ----D---- C:\Program Files (x86)\Microsoft.NET
2012-04-26 14:22:02 ----D---- C:\Windows\SYSWOW64\Wat
2012-04-26 14:22:01 ----D---- C:\Windows\system32\Wat
2012-04-26 14:09:57 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-04-26 14:09:57 ----A---- C:\Windows\system32\mshtmled.dll
2012-04-26 14:09:56 ----A---- C:\Windows\SYSWOW64\url.dll
2012-04-26 14:09:56 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-04-26 14:09:56 ----A---- C:\Windows\system32\jscript9.dll
2012-04-26 14:09:56 ----A---- C:\Windows\system32\iertutil.dll
2012-04-26 14:09:55 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2012-04-26 14:09:55 ----A---- C:\Windows\SYSWOW64\jscript.dll
2012-04-26 14:09:55 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-04-26 14:09:55 ----A---- C:\Windows\system32\url.dll
2012-04-26 14:09:55 ----A---- C:\Windows\system32\ieui.dll
2012-04-26 14:09:54 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-04-26 14:09:54 ----A---- C:\Windows\system32\urlmon.dll
2012-04-26 14:09:54 ----A---- C:\Windows\system32\jsproxy.dll
2012-04-26 14:09:54 ----A---- C:\Windows\system32\jscript.dll
2012-04-26 14:09:53 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-04-26 14:09:53 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-04-26 14:09:53 ----A---- C:\Windows\system32\wininet.dll
2012-04-26 14:09:52 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-04-26 14:09:51 ----A---- C:\Windows\system32\mshtml.dll
2012-04-26 14:09:50 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-04-26 14:09:48 ----A---- C:\Windows\system32\ieframe.dll
2012-04-26 14:04:47 ----A---- C:\Windows\system32\MRT.exe
2012-04-26 14:04:37 ----A---- C:\Windows\SYSWOW64\wmi.dll
2012-04-26 14:04:37 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2012-04-26 14:04:37 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2012-04-26 14:04:37 ----A---- C:\Windows\system32\wmi.dll
2012-04-26 14:04:37 ----A---- C:\Windows\system32\wintrust.dll
2012-04-26 14:04:37 ----A---- C:\Windows\system32\imagehlp.dll
2012-04-26 14:04:37 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2012-04-26 14:02:18 ----A---- C:\Windows\system32\schannel.dll
2012-04-26 14:02:18 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2012-04-26 14:02:17 ----A---- C:\Windows\SYSWOW64\webio.dll
2012-04-26 14:02:17 ----A---- C:\Windows\SYSWOW64\schannel.dll
2012-04-26 14:02:17 ----A---- C:\Windows\system32\webio.dll
2012-04-26 14:02:17 ----A---- C:\Windows\system32\lsass.exe
2012-04-26 14:02:17 ----A---- C:\Windows\system32\lsasrv.dll
2012-04-26 14:02:17 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2012-04-26 14:02:17 ----A---- C:\Windows\system32\drivers\cng.sys
2012-04-26 14:02:16 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2012-04-26 14:02:16 ----A---- C:\Windows\SYSWOW64\secur32.dll
2012-04-26 14:02:16 ----A---- C:\Windows\system32\sspisrv.dll
2012-04-26 14:02:16 ----A---- C:\Windows\system32\sspicli.dll
2012-04-26 14:02:16 ----A---- C:\Windows\system32\secur32.dll
2012-04-26 14:02:13 ----A---- C:\Windows\system32\shell32.dll
2012-04-26 14:02:12 ----A---- C:\Windows\SYSWOW64\shell32.dll
2012-04-26 14:02:11 ----A---- C:\Windows\system32\ntshrui.dll
2012-04-26 14:02:10 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2012-04-26 14:02:04 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2012-04-26 14:02:04 ----A---- C:\Windows\system32\poqexec.exe
2012-04-26 14:01:57 ----A---- C:\Windows\system32\quartz.dll
2012-04-26 14:01:56 ----A---- C:\Windows\SYSWOW64\quartz.dll
2012-04-26 14:01:56 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2012-04-26 14:01:56 ----A---- C:\Windows\system32\qdvd.dll
2012-04-26 14:01:54 ----A---- C:\Windows\system32\XpsPrint.dll
2012-04-26 14:01:53 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2012-04-26 14:01:50 ----A---- C:\Windows\system32\psisdecd.dll
2012-04-26 14:01:49 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2012-04-26 14:01:44 ----A---- C:\Windows\system32\rdrmemptylst.exe
2012-04-26 14:01:44 ----A---- C:\Windows\system32\rdpwsx.dll
2012-04-26 14:01:44 ----A---- C:\Windows\system32\rdpcorekmts.dll
2012-04-26 14:01:42 ----A---- C:\Windows\system32\csrsrv.dll
2012-04-26 14:01:40 ----A---- C:\Windows\SYSWOW64\msvcrt.dll
2012-04-26 14:01:40 ----A---- C:\Windows\system32\msvcrt.dll
2012-04-26 14:01:38 ----A---- C:\Windows\system32\drivers\afd.sys
2012-04-26 14:01:36 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2012-04-26 14:01:36 ----A---- C:\Windows\system32\ntdll.dll
2012-04-26 14:00:57 ----A---- C:\Windows\SYSWOW64\tzres.dll
2012-04-26 14:00:57 ----A---- C:\Windows\system32\tzres.dll
2012-04-26 14:00:16 ----A---- C:\Windows\system32\EncDec.dll
2012-04-26 14:00:15 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2012-04-26 14:00:14 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2012-04-26 14:00:14 ----A---- C:\Windows\system32\oleacc.dll
2012-04-26 14:00:13 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2012-04-26 14:00:13 ----A---- C:\Windows\system32\oleaut32.dll
2012-04-26 13:57:40 ----A---- C:\Windows\system32\packager.dll
2012-04-26 13:57:39 ----A---- C:\Windows\SYSWOW64\packager.dll
2012-04-26 13:57:31 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2012-04-26 13:57:31 ----A---- C:\Windows\system32\rdpcore.dll
2012-04-26 13:57:30 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2012-04-26 13:57:30 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2012-04-26 12:42:09 ----D---- C:\Users\Jaruneczka\AppData\Roaming\Mozilla
2012-04-26 12:42:01 ----D---- C:\ProgramData\Mozilla
2012-04-26 12:42:01 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2012-04-26 12:41:57 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-04-26 12:40:03 ----D---- C:\Program Files\CCleaner
2012-04-26 12:23:33 ----D---- C:\Users\Jaruneczka\AppData\Roaming\Adobe
2012-04-26 12:17:12 ----D---- C:\ProgramData\clear.fi
2012-04-26 11:54:49 ----D---- C:\Users\Jaruneczka\AppData\Roaming\Skype
======List of files/folders modified in the last 1 month======
2012-05-13 07:18:22 ----D---- C:\Windows\Temp
2012-05-13 07:18:22 ----D---- C:\Windows
2012-05-13 06:51:00 ----D---- C:\Windows\system32\config
2012-05-13 06:41:12 ----A---- C:\Windows\SYSWOW64\log.txt
2012-05-13 05:06:56 ----D---- C:\Windows\Prefetch
2012-05-12 16:30:21 ----D---- C:\Windows\SoftwareDistribution
2012-05-12 16:10:47 ----D---- C:\Program Files\Common Files
2012-05-12 16:09:45 ----D---- C:\Program Files (x86)\Common Files
2012-05-12 12:12:32 ----SHD---- C:\System Volume Information
2012-05-12 11:42:25 ----RD---- C:\Program Files (x86)
2012-05-12 11:41:21 ----D---- C:\Windows\debug
2012-05-12 11:40:51 ----D---- C:\Windows\system32\catroot
2012-05-12 11:16:07 ----SHD---- C:\Windows\Installer
2012-05-12 11:16:05 ----D---- C:\Windows\SysWOW64
2012-05-12 11:16:05 ----D---- C:\Windows\system32\drivers
2012-05-12 11:16:05 ----D---- C:\Windows\inf
2012-05-12 11:16:04 ----D---- C:\Windows\system32\catroot2
2012-05-12 11:16:02 ----RD---- C:\Program Files
2012-05-12 11:05:57 ----D---- C:\Windows\Downloaded Program Files
2012-05-12 10:03:19 ----RSD---- C:\Windows\assembly
2012-05-12 10:03:19 ----D---- C:\Windows\Microsoft.NET
2012-05-12 09:28:19 ----D---- C:\Windows\system32\wdi
2012-05-12 09:27:54 ----D---- C:\Windows\SYSWOW64\config
2012-05-12 06:39:39 ----D---- C:\Windows\Tasks
2012-05-12 06:39:39 ----D---- C:\Windows\system32\Tasks
2012-05-11 15:21:00 ----SD---- C:\ProgramData\Microsoft
2012-05-09 09:15:03 ----D---- C:\Windows\winsxs
2012-05-09 09:13:35 ----D---- C:\Windows\System32
2012-05-09 09:05:49 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-05-09 08:58:05 ----D---- C:\Program Files\Windows Journal
2012-05-03 13:46:29 ----D---- C:\ProgramData\Adobe
2012-05-01 21:41:03 ----HD---- C:\ProgramData
2012-05-01 05:40:09 ----D---- C:\Windows\system32\NDF
2012-04-27 07:19:05 ----D---- C:\Windows\system32\drivers\etc
2012-04-27 03:34:55 ----D---- C:\Windows\rescache
2012-04-26 22:59:21 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-04-26 21:50:19 ----D---- C:\ProgramData\McAfee
2012-04-26 21:49:07 ----D---- C:\Windows\system32\DriverStore
2012-04-26 18:49:35 ----D---- C:\Windows\system32\OEM
2012-04-26 18:49:05 ----HD---- C:\OEM
2012-04-26 18:48:24 ----AD---- C:\Windows\DeployWinRE2
2012-04-26 18:46:42 ----D---- C:\ProgramData\oem
2012-04-26 18:46:10 ----SHD---- C:\$Recycle.Bin
2012-04-26 18:41:31 ----RD---- C:\Users
2012-04-26 18:40:12 ----D---- C:\Windows\system32\Recovery
2012-04-26 14:59:47 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-04-26 14:51:04 ----RSD---- C:\Windows\Fonts
2012-04-26 14:33:11 ----D---- C:\Windows\SYSWOW64\cs-CZ
2012-04-26 14:33:11 ----D---- C:\Windows\system32\cs-CZ
2012-04-26 14:24:25 ----D---- C:\Windows\SYSWOW64\en-US
2012-04-26 14:24:25 ----D---- C:\Windows\system32\en-US
2012-04-26 14:23:39 ----D---- C:\Windows\Logs
2012-04-26 14:16:19 ----D---- C:\Windows\ehome
2012-04-26 14:16:19 ----D---- C:\Program Files\Common Files\System
2012-04-26 14:16:14 ----D---- C:\Windows\SYSWOW64\migration
2012-04-26 14:16:14 ----D---- C:\Program Files\Internet Explorer
2012-04-26 14:16:14 ----D---- C:\Program Files (x86)\Internet Explorer
2012-04-26 14:16:13 ----D---- C:\Windows\system32\migration
2012-04-26 14:16:06 ----D---- C:\Windows\SYSWOW64\sk-SK
2012-04-26 14:16:06 ----D---- C:\Windows\system32\sk-SK
2012-04-26 14:03:03 ----D---- C:\Windows\system32\restore
2012-04-26 12:50:28 ----D---- C:\Windows\Panther
2012-04-26 12:28:21 ----RD---- C:\Program Files (x86)\Skype
2012-04-26 12:27:58 ----D---- C:\ProgramData\Skype
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iaStor.sys [2010-09-14 437272]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2012-03-20 203888]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2011-12-23 22648]
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2011-12-23 20520]
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2011-12-23 62776]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-03-17 2712064]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2011-03-25 12262336]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-06-14 2899176]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2011-04-20 169584]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2011-09-20 18432]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-10-08 1395248]
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2011-09-20 17408]
S3 AmUStor;AM USB Stroage Driver; C:\Windows\system32\drivers\AmUStor.SYS [2011-01-14 74840]
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 98688]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-03 63928]
R2 BBUpdate;BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-05-13 249648]
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2011-03-14 352336]
R2 ePowerSvc;ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2011-08-02 872552]
R2 GREGService;GREGService; C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2011-05-30 36456]
R2 Guard.Mail.ru;Guard.Mail.ru; C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe [2012-04-26 1564368]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-14 13336]
R2 Live Updater Service;Live Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2011-04-22 244624]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-02-01 326168]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2012-03-26 12600]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [2011-04-24 256832]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-01 2656280]
R3 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-29 2292096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
S3 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-06-07 191752]
S3 EgisTec Ticket Service;EgisTec Ticket Service; C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [2011-06-21 173424]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-12-23 655624]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-21 129976]
S3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-04-26 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
-----------------EOF-----------------
Re: Pro vyosek, prosím o kontrolu logu
Log se mi jevi cisty, ja myslim ze muzes byt v klidu 

- jaruneczka
- Vzorný návštěvník
- Příspěvky: 417
- Registrován: 09 čer 2008 11:45
- Bydliště: Ostrava
Re: Pro vyosek, prosím o kontrolu logu
uff.... jsem si oddychla, děkuji pěkně, krásný zbytek neděle 

Re: Pro vyosek, prosím o kontrolu logu
Neni zac, pekny zbytek nedeli i Tobe s Lubkou 
