Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu, pomalý pc, vytížení CPU, praská zvuk.

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Bary
Návštěvník
Návštěvník
Příspěvky: 22
Registrován: 16 dub 2006 13:30

Prosím o kontrolu, pomalý pc, vytížení CPU, praská zvuk.

#1 Příspěvek od Bary »

Dobrý den, zde je log:


Logfile of random's system information tool 1.09 (written by random/random)
Run by Administrator at 2012-07-31 19:23:41
Systém Microsoft Windows XP Professional Service Pack 3
System drive E: has 681 MB (0%) free of 305 GB
Total RAM: 3199 MB (78% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:24:04, on 31.7.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17109)
Boot mode: Normal

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Windows Defender\MsMpEng.exe
E:\Program Files\Zrychleni Pocitace\PCSUService.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Alwil Software\Avast5\AvastSvc.exe
E:\WINDOWS\Explorer.EXE
E:\Genius\ioCentre\gTaskBar.exe
E:\WINDOWS\RTHDCPL.EXE
E:\WINDOWS\system32\RunDLL32.exe
E:\Genius\ioCentre\gMouseTask.exe
E:\Genius\ioCentre\gKbdTask.exe
E:\Genius\ioCentre\gAutoPan.exe
E:\Genius\ioCentre\gAutoScroll.exe
E:\Genius\ioCentre\gZoom.exe
E:\Genius\ioCentre\gMGlass.exe
E:\Genius\ioCentre\gIMMgm.exe
E:\Genius\ioCentre\gDeskMgm.exe
E:\Genius\ioCentre\gTaskSwitch.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Documents and Settings\Administrator\Data aplikací\QipGuard\QipGuard.exe
E:\Program Files\DAEMON Tools Pro\DTAgent.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\RapidBIT\cisvc.exe
E:\WINDOWS\system32\FsUsbExService.Exe
E:\Program Files\Java\jre6\bin\jqs.exe
E:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
E:\WINDOWS\system32\libusbd-nt.exe
E:\WINDOWS\system32\nvsvc32.exe
E:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
E:\WINDOWS\system32\PnkBstrA.exe
E:\Program Files\QipGuard\QipGuard.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\DRIVERS\WtSrv.exe
e:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
e:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
E:\WINDOWS\system32\wbem\wmiapsrv.exe
E:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
E:\WINDOWS\system32\wuauclt.exe
E:\WINDOWS\system32\taskmgr.exe
E:\Documents and Settings\Administrator\Dokumenty\Downloads\RSIT.exe
E:\Program Files\trend micro\Administrator.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - E:\Documents and Settings\Administrator\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - e:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - E:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - E:\Documents and Settings\Administrator\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - E:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - E:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [ioCentre] E:\Genius\ioCentre\gTaskBar.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] E:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [QIP Internet Guardian] E:\Documents and Settings\Administrator\Data aplikací\QipGuard\QipGuard.exe /p
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "E:\Program Files\DAEMON Tools Pro\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [Google Update] "E:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-21-1004336348-1801674531-1417001333-1004\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1004336348-1801674531-1417001333-1004\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'UpdatusUser')
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - E:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - E:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - E:\Documents and Settings\Administrator\Plocha\PartyCasino.lnk (file missing)
O9 - Extra 'Tools' menuitem: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - E:\Documents and Settings\Administrator\Plocha\PartyCasino.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - E:\Program Files\QIP\qip.exe (HKCU)
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{85F79B9D-A40F-473F-82BE-A1A617E9C80E}: NameServer = 213.191.99.9
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - E:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - E:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - E:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - E:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Remote Connections Service (FlexService) - BitMicro Software Corporation - E:\Program Files\RapidBIT\cisvc.exe
O23 - Service: FsUsbExService - Teruten - E:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - E:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - E:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - http://libusb-win32.sourceforge.net - E:\WINDOWS\system32\libusbd-nt.exe
O23 - Service: Maya 7 PLE Documentation Server (mple7docserver) - Unknown owner - E:\Programy\Maya\docs\wrapper.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - E:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - E:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PC Speed Up Service (PCSUService) - Unknown owner - E:\Program Files\Zrychleni Pocitace\PCSUService.exe
O23 - Service: PnkBstrA - Unknown owner - E:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: QipGuard - QIP.ru - E:\Program Files\QipGuard\QipGuard.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - E:\Program Files\WinPcap\rpcapd.exe
O23 - Service: ServiceLayer - Nokia - E:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - E:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - E:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - E:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: WinTab Service (WinTabService) - Tablet Driver - E:\WINDOWS\system32\DRIVERS\WtSrv.exe

--
End of file - 9950 bytes

======Scheduled tasks folder======

E:\WINDOWS\tasks\Clean System Memory.job
E:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
E:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
E:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1004336348-1801674531-1417001333-500Core1cc8e22aa83283a.job
E:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1004336348-1801674531-1417001333-500UA.job
E:\WINDOWS\tasks\MP Scheduled Scan.job
E:\WINDOWS\tasks\RegCure Program Check.job
E:\WINDOWS\tasks\RegCure.job
E:\WINDOWS\tasks\WGASetup.job

=========Mozilla firefox=========

ProfilePath - E:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\80w6ee87.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://qip.ru"
prefs.js - "extensions.enabledItems" - "{b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6, eafo3fflauncher@ea.com:1.1, {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.76, {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.7, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.7, {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11, {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14, {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}:6.0.18, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, jqs@sun.com:1.0, {20a82645-c095-46ed-80e3-08825760534b}:1.2.1, personas@christopher.beard:1.6.2, {32a1fd71-835e-4b11-8e54-886fda0b4c89}:1.1, {ea614400-e918-4741-9a97-7a972ff7c30b}:2.1.14, {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1, {E22FCDEF-FF51-4525-AF64-FC91756B5977}:1.0, {EFE81DF7-961E-42A8-96CA-5696882A4558}:1.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5"
prefs.js - "keyword.URL" - "http://search.qip.ru/search?from=FF&query="

"jqs@sun.com"=E:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{20a82645-c095-46ed-80e3-08825760534b}"=E:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}"=E:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.235 Plugin
"Path"=E:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=E:\WINDOWS\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Web Player
"Path"=E:\Program Files\DivX\DivX Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=E:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@iahgames.com/prodown]
"Description"=IAHGames 2.03.2331
"Path"=E:\Program Files\IAHgames\Playfast\npiahpd.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=E:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=E:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=E:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=E:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@rsj.de/prodown]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@thrixxx.com/WebLaunch]
"Description"=thriXXX WebLaunch 1.0
"Path"=E:\Program Files\thriXXX\WebLaunch\Binaries\npWebLaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=E:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=E:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll

E:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
{E22FCDEF-FF51-4525-AF64-FC91756B5977}
{EFE81DF7-961E-42A8-96CA-5696882A4558}

E:\Program Files\Mozilla Firefox\components\
aboutCertError.js
aboutPrivateBrowsing.js
aboutRights.js
aboutRobots.js
aboutSessionRestore.js
binary.manifest
browser.xpt
browsercomps.dll
browserdirprovider.dll
brwsrcmp.dll
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
npwachk.xpt
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsHandlerService.js
nsHelperAppDlg.js
nsIQTScriptablePlugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPostUpdateWin.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js

E:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npdeployJava1.dll
npdivx32.dll
npdivx32.xpt
npnul32.dll
NPOFFICE.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
npwachk.dll
npWebLaunch.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

E:\Program Files\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

E:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\80w6ee87.default\extensions\
eafo3fflauncher@ea.com
personas@christopher.beard
{20a82645-c095-46ed-80e3-08825760534b}
{32a1fd71-835e-4b11-8e54-886fda0b4c89}
{800b5000-a755-47e1-992b-48a1c1357f07}
{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
{ea614400-e918-4741-9a97-7a972ff7c30b}

E:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\80w6ee87.default\searchplugins\
icqplugin-1.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin.gif
icqplugin.src
icqplugin.xml
MySpace.xml
qip-search.xml
search-results.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-15 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - e:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - E:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-04-02 266240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - E:\Documents and Settings\Administrator\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2011-10-12 142288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - E:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-09 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - E:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-02-09 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - E:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-04-02 266240]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ioCentre"=E:\Genius\ioCentre\gTaskBar.exe [2006-12-08 241664]
"RTHDCPL"=E:\WINDOWS\RTHDCPL.EXE [2009-02-13 17508864]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"NvCplDaemon"=E:\WINDOWS\system32\NvCpl.dll [2012-02-10 15494464]
"nwiz"=E:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2012-02-10 1634112]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=E:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
""= []
"QIP Internet Guardian"=E:\Documents and Settings\Administrator\Data aplikací\QipGuard\QipGuard.exe [2011-10-12 191440]
"DAEMON Tools Pro Agent"=E:\Program Files\DAEMON Tools Pro\DTAgent.exe [2012-02-02 3034432]
"Google Update"=E:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-06-24 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - E:\WINDOWS\system32\WPDShServiceObj.dll [2008-04-27 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=E:\PROGRA~1\WIFD1F~1\MpShHook.dll [2006-11-03 83224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCMD"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableTaskMgr"=0
"DisableCMD"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoSetActiveDesktop"=0
"NoActiveDesktopChanges"=0
"NoFolderOptions"=0
"NoRun"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoSetActiveDesktop"=0
"NoActiveDesktopChanges"=0
"NoFolderOptions"=0
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"E:\hry\Firefly Studios\Stronghold Legends\StrongholdLegends.exe"="E:\hry\Firefly Studios\Stronghold Legends\StrongholdLegends.exe:*:Enabled:Stronghold Legends"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"E:\Programy\Maya85\bin\maya.exe"="E:\Programy\Maya85\bin\maya.exe:*:Enabled:Maya"
"C:\Program Files\BearShare\BearShare.exe"="C:\Program Files\BearShare\BearShare.exe:*:Enabled:BearShare"
"C:\Program Files\ICQ\ICQ6\ICQ.exe"="C:\Program Files\ICQ\ICQ6\ICQ.exe:*:Enabled:ICQ Library"
"E:\Program Files\QIP\qip.exe"="E:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"E:\Documents and Settings\Administrator\Application Data\PowerChallenge\PowerSoccer\PowerSoccer.exe"="E:\Documents and Settings\Administrator\Application Data\PowerChallenge\PowerSoccer\PowerSoccer.exe:*:Enabled:PowerSoccer"
"E:\Program Files\Guillemot\tools\giWebUpdater.exe"="E:\Program Files\Guillemot\tools\giWebUpdater.exe:*:Enabled:Guillemot Web Updater"
"E:\Program Files\Electronic Arts\EADM\Core.exe"="E:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager"
"E:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe"="E:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe:*:Enabled:Kerio Personal Firewall 4 - GUI"
"E:\Programy\Autodesk\Maya8.5\bin\maya.exe"="E:\Programy\Autodesk\Maya8.5\bin\maya.exe:*:Enabled:Maya"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"E:\Program Files\ICQ6.5\ICQ.exe"="E:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"E:\Programy\SmartFTP Client\SmartFTP.exe"="E:\Programy\SmartFTP Client\SmartFTP.exe:*:Enabled:SmartFTP Client 3.0"
"E:\hry\Firefly Studios\Stronghold 2\Stronghold2.exe"="E:\hry\Firefly Studios\Stronghold 2\Stronghold2.exe:*:Enabled:Stronghold 2"
"E:\hry\EA GAMES\Battlefield 2\BF2.exe"="E:\hry\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2"
"E:\Programy\Pinnacle\VideoSpin2\Programs\RM.exe"="E:\Programy\Pinnacle\VideoSpin2\Programs\RM.exe:*:Enabled:Render Manager"
"E:\Programy\Pinnacle\VideoSpin2\Programs\umi.exe"="E:\Programy\Pinnacle\VideoSpin2\Programs\umi.exe:*:Enabled:umi"
"E:\Programy\Pinnacle\VideoSpin2\Programs\VideoSpin.exe"="E:\Programy\Pinnacle\VideoSpin2\Programs\VideoSpin.exe:*:Enabled:Pinnacle VideoSpin"
"E:\hry\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe"="E:\hry\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
"E:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe"="E:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
"E:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe"="E:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
"E:\Programy\Pinnacle\Studio 12\Programs\RM.exe"="E:\Programy\Pinnacle\Studio 12\Programs\RM.exe:*:Enabled:Render Manager"
"E:\Programy\Pinnacle\Studio 12\Programs\Studio.exe"="E:\Programy\Pinnacle\Studio 12\Programs\Studio.exe:*:Enabled:Studio"
"E:\Programy\Pinnacle\Studio 12\Programs\umi.exe"="E:\Programy\Pinnacle\Studio 12\Programs\umi.exe:*:Enabled:umi"
"E:\hry\KONAMI\Pro Evolution Soccer 2011\pes2011.exe"="E:\hry\KONAMI\Pro Evolution Soccer 2011\pes2011.exe:*:Enabled:Pro Evolution Soccer 2011"
"E:\Program Files\ICQ7.2\ICQ.exe"="E:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"E:\Program Files\ICQ7.2\aolload.exe"="E:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"E:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="E:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
"E:\Program Files\Autodesk\Backburner\monitor.exe"="E:\Program Files\Autodesk\Backburner\monitor.exe:*:Enabled:backburner 2.3 monitor"
"E:\Program Files\Autodesk\Backburner\manager.exe"="E:\Program Files\Autodesk\Backburner\manager.exe:*:Enabled:backburner 2.3 manager"
"E:\Program Files\Autodesk\Backburner\server.exe"="E:\Program Files\Autodesk\Backburner\server.exe:*:Enabled:backburner 2.3 server"
"E:\hry\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe"="E:\hry\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe:*:Enabled:Battlefield: Bad Company™ 2"
"E:\hry\Electronic Arts\Need for Speed(TM) Hot Pursuit\Launcher.exe"="E:\hry\Electronic Arts\Need for Speed(TM) Hot Pursuit\Launcher.exe:*:Enabled:Need for Speed(TM) Hot Pursuit"
"E:\hry\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat"="E:\hry\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"E:\WINDOWS\system32\PnkBstrA.exe"="E:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"E:\WINDOWS\system32\PnkBstrB.exe"="E:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"E:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe"="E:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe:*:Enabled:Kerio Personal Firewall 4 - Service"
"E:\hry\Atari\TDU2\_UpLauncher.exe"="E:\hry\Atari\TDU2\_UpLauncher.exe:*:Enabled:UpLauncher"
"E:\hry\Atari\TDU2\UpLauncher.exe"="E:\hry\Atari\TDU2\UpLauncher.exe:*:Enabled:Test Drive Unlimited 2"
"E:\hry\Ubisoft\Assassin's Creed Brotherhood\ACBSP.exe"="E:\hry\Ubisoft\Assassin's Creed Brotherhood\ACBSP.exe:*:Enabled:Assassin's Creed Brotherhood"
"E:\hry\Ubisoft\Assassin's Creed Brotherhood\ACBMP.exe"="E:\hry\Ubisoft\Assassin's Creed Brotherhood\ACBMP.exe:*:Enabled:Assassin's Creed Brotherhood Multiplayer"
"E:\hry\Ubisoft\Assassin's Creed Brotherhood\AssassinsCreedBrotherhood.exe"="E:\hry\Ubisoft\Assassin's Creed Brotherhood\AssassinsCreedBrotherhood.exe:*:Enabled:Assassin's Creed Brotherhood Update"
"E:\hry\Ubisoft\Assassin's Creed Brotherhood\UPlayBrowser.exe"="E:\hry\Ubisoft\Assassin's Creed Brotherhood\UPlayBrowser.exe:*:Enabled:Assassin's Creed Brotherhood Uplay"
"E:\hry\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe"="E:\hry\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:*:Enabled:Assassin's Creed Dx9"
"E:\hry\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe"="E:\hry\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:*:Enabled:Assassin's Creed Dx10"
"E:\hry\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe"="E:\hry\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:*:Enabled:Assassin's Creed Update"
"E:\hry\Codemasters\DiRT 3\dirt3_game.exe"="E:\hry\Codemasters\DiRT 3\dirt3_game.exe:*:Enabled:DiRT 3"
"E:\Program Files\Pando Networks\Media Booster\PMB.exe"="E:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"E:\hry\GamesCampus\MLBDugoutHeroes\MLBDugoutHeroes.exe"="E:\hry\GamesCampus\MLBDugoutHeroes\MLBDugoutHeroes.exe:*:Enabled:MLBDugoutHeroes"
"Z:\game\FF2Client.exe"="Z:\game\FF2Client.exe:*:Enabled:FIFA ONLINE"
"E:\hry\EA Sports\Fifa Online 2\FF2Client.exe"="E:\hry\EA Sports\Fifa Online 2\FF2Client.exe:*:Enabled:FIFA ONLINE"
"E:\hry\Ubisoft\Might & Magic Heroes VI - Internal Private Closed Beta\Might & Magic Heroes VI - Internal Private Closed Beta.exe"="E:\hry\Ubisoft\Might & Magic Heroes VI - Internal Private Closed Beta\Might & Magic Heroes VI - Internal Private Closed Beta.exe:*:Enabled:Might & Magic Heroes VI - Internal Private Closed Beta"
"E:\hry\Microsoft Games\Age of Empires Online\Spartan.exe"="E:\hry\Microsoft Games\Age of Empires Online\Spartan.exe:*:Enabled:Age of Empires Online"
"E:\hry\Ubisoft\Might & Magic Heroes VI\Might & Magic Heroes VI.exe"="E:\hry\Ubisoft\Might & Magic Heroes VI\Might & Magic Heroes VI.exe:*:Enabled:Might & Magic Heroes VI"
"E:\hry\Ubisoft\Driver San Francisco\Driver.exe"="E:\hry\Ubisoft\Driver San Francisco\Driver.exe:*:Enabled:Driver San Francisco"
"E:\hry\Battlefield 3™\bf3.exe"="E:\hry\Battlefield 3™\bf3.exe:*:Enabled:Battlefield 3™"
"E:\hry\KONAMI\Pro Evolution Soccer 2012\pes2012.exe"="E:\hry\KONAMI\Pro Evolution Soccer 2012\pes2012.exe:*:Enabled:Pro Evolution Soccer 2012"
"E:\hry\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="E:\hry\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM)"
"E:\Program Files\Sony Ericsson\Update Engine\Sony Ericsson Update Engine.exe"="E:\Program Files\Sony Ericsson\Update Engine\Sony Ericsson Update Engine.exe:*:Enabled:Update Engine"
"E:\hry\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe"="E:\hry\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
"E:\Programy\Pinnacle\Studio 15\Programs\RM.exe"="E:\Programy\Pinnacle\Studio 15\Programs\RM.exe:*:Enabled:Render Manager"
"E:\Programy\Pinnacle\Studio 15\Programs\Studio.exe"="E:\Programy\Pinnacle\Studio 15\Programs\Studio.exe:*:Enabled:Studio"
"E:\Programy\Pinnacle\Studio 15\Programs\umi.exe"="E:\Programy\Pinnacle\Studio 15\Programs\umi.exe:*:Enabled:umi"
"E:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="E:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"E:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"="E:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe"
"E:\Program Files\Skype\Phone\Skype.exe"="E:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"E:\Program Files\uTorrent\uTorrent.exe"="E:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"E:\Program Files\Ubisoft\Rayman Origins\Rayman Origins.exe"="E:\Program Files\Ubisoft\Rayman Origins\Rayman Origins.exe:*:Enabled:Rayman Origins"
"E:\Program Files\Ubisoft\Rayman Origins\gu.exe"="E:\Program Files\Ubisoft\Rayman Origins\gu.exe:*:Enabled:Rayman Origins"
"E:\Program Files\Ubisoft\Assassin's Creed Revelations\ACRSP.exe"="E:\Program Files\Ubisoft\Assassin's Creed Revelations\ACRSP.exe:*:Enabled:Assassin's Creed Revelations"
"E:\Program Files\Ubisoft\Assassin's Creed Revelations\ACRMP.exe"="E:\Program Files\Ubisoft\Assassin's Creed Revelations\ACRMP.exe:*:Enabled:Assassin's Creed Revelations Multiplayer"
"E:\Program Files\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe"="E:\Program Files\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe:*:Enabled:Assassin's Creed Revelations Update"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"E:\Program Files\ICQ7.2\ICQ.exe"="E:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"E:\Program Files\ICQ7.2\aolload.exe"="E:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"E:\Program Files\Pando Networks\Media Booster\PMB.exe"="E:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=E:\WINDOWS\system32\Iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=E:\WINDOWS\system32\l3codeca.acm
"msacm.vorbis"=vorbis.acm
"SENTINEL"=snti386.dll
"vidc.VP60"=E:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=E:\WINDOWS\system32\vp6vfw.dll
"VIDC.CFHD"=CFHD.dll
"midi1"=wdmaud.drv
"wave1"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"midi3"=wdmaud.drv
"wave2"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"midi5"=wdmaud.drv
"wave3"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.lhacm"=lhacm.acm
"vidc.mjpg"=pvmjpg30.dll
"wave5"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux4"=wdmaud.drv
"wave6"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux5"=wdmaud.drv
"wave7"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux6"=wdmaud.drv
"wave8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux7"=wdmaud.drv
"wave9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux8"=wdmaud.drv
"VIDC.WMV3"=wmv9vcm.dll
"VIDC.FMVC"=fmcodec.dll
"wave4"=wdmaud.drv
"mixer4"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.MPG4"=mpg4c32.dll
"VIDC.MP42"=mpg4c32.dll
"aux9"=wdmaud.drv

======File associations======

.ini - open - "E:\Programy\IDM Computer Solutions\UltraEdit\Uedit32.exe" "%1"
.txt - open - "E:\Programy\IDM Computer Solutions\UltraEdit\Uedit32.exe" "%1"

======List of files/folders created in the last 1 month======

2012-07-31 16:19:50 ----D---- E:\WINDOWS\LastGood
2012-07-29 12:47:39 ----D---- E:\i68Backups
2012-07-14 16:41:57 ----D---- E:\Program Files\DAEMON Tools Pro
2012-07-14 15:36:04 ----D---- E:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Pro
2012-07-07 21:03:02 ----A---- E:\WINDOWS\system32\msvcr90.dll
2012-07-07 21:01:35 ----A---- E:\WINDOWS\SchedLgU.Txt
2012-07-07 19:02:04 ----HDC---- E:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$

======List of files/folders modified in the last 1 month======

2012-07-31 19:23:51 ----D---- E:\Program Files\trend micro
2012-07-31 19:23:36 ----D---- E:\WINDOWS\Prefetch
2012-07-31 19:22:56 ----D---- E:\WINDOWS\temp
2012-07-31 18:02:14 ----HD---- E:\WINDOWS\inf
2012-07-31 16:24:09 ----D---- E:\Program Files\Zrychleni Pocitace
2012-07-31 16:22:37 ----D---- E:\WINDOWS\system32\CatRoot2
2012-07-31 16:19:50 ----D---- E:\WINDOWS
2012-07-31 16:16:12 ----SD---- E:\WINDOWS\Tasks
2012-07-31 06:21:55 ----AC---- E:\WINDOWS\NeroDigital.ini
2012-07-29 22:21:17 ----D---- E:\temp
2012-07-29 20:41:43 ----AC---- E:\WINDOWS\win.ini
2012-07-29 20:41:43 ----AC---- E:\WINDOWS\system.ini
2012-07-28 10:07:01 ----D---- E:\hry
2012-07-28 10:05:49 ----D---- E:\Program Files\Ubisoft
2012-07-28 10:03:54 ----D---- E:\Downloady
2012-07-28 01:41:22 ----D---- E:\Documents and Settings\Administrator\Data aplikací\uTorrent
2012-07-27 18:44:09 ----D---- E:\Program Files
2012-07-27 11:36:25 ----D---- E:\Documents and Settings\Administrator\Data aplikací\Skype
2012-07-26 23:16:46 ----D---- E:\Program Files\Mozilla Firefox
2012-07-24 18:39:49 ----SHD---- E:\WINDOWS\Installer
2012-07-24 18:39:48 ----SHD---- E:\Config.Msi
2012-07-22 20:26:19 ----HD---- E:\Program Files\InstallShield Installation Information
2012-07-17 17:53:18 ----D---- E:\Documents and Settings\Administrator\Data aplikací\gtk-2.0
2012-07-16 16:46:24 ----D---- E:\Documents and Settings\All Users\Data aplikací\Ubisoft
2012-07-16 16:16:58 ----D---- E:\WINDOWS\WinSxS
2012-07-16 16:15:32 ----D---- E:\WINDOWS\system32\DirectX
2012-07-16 16:14:40 ----RSD---- E:\WINDOWS\assembly
2012-07-14 17:03:46 ----D---- E:\Program Files\Atari
2012-07-14 16:51:43 ----D---- E:\Documents and Settings\Administrator\Data aplikací\DAEMON Tools Pro
2012-07-14 15:31:29 ----D---- E:\Program Files\DAEMON Tools Lite
2012-07-12 06:10:18 ----HD---- E:\WINDOWS\$hf_mig$
2012-07-08 16:36:05 ----D---- E:\Programy
2012-07-08 16:36:05 ----D---- E:\Program Files\VstPlugins
2012-07-08 16:35:48 ----D---- E:\WINDOWS\system32
2012-07-08 16:20:36 ----AD---- E:\Documents and Settings\All Users\Data aplikací\TEMP
2012-07-08 11:58:35 ----D---- E:\Program Files\K-Lite Codec Pack
2012-07-07 20:50:47 ----D---- E:\WINDOWS\system32\CatRoot
2012-07-07 13:12:07 ----D---- E:\Documents and Settings\Administrator\Data aplikací\LucasArts
2012-07-02 18:54:03 ----RSD---- E:\WINDOWS\Fonts

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 imagedrv;imagedrv; E:\WINDOWS\System32\Drivers\imagedrv.sys [2007-07-03 11304]
R0 imagesrv;imagesrv; E:\WINDOWS\system32\DRIVERS\imagesrv.sys [2007-07-03 132904]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; E:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; E:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 sptd;sptd; E:\WINDOWS\System32\Drivers\sptd.sys [2012-07-14 473656]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; E:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-01-18 77696]
R1 Aavmker4;avast! Asynchronous Virus Monitor; E:\WINDOWS\system32\drivers\Aavmker4.sys [2011-04-18 30680]
R1 aswRdr;aswRdr; E:\WINDOWS\system32\drivers\aswRdr.sys [2011-04-18 25432]
R1 aswSnx;aswSnx; E:\WINDOWS\system32\drivers\aswSnx.sys [2011-04-18 441176]
R1 aswSP;aswSP; E:\WINDOWS\system32\drivers\aswSP.sys [2011-04-18 307288]
R1 aswTdi;avast! Network Shield Support; E:\WINDOWS\system32\drivers\aswTdi.sys [2011-04-18 49240]
R1 ehdrv;ehdrv; E:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
R1 epfwtdi;epfwtdi; E:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-02-06 56280]
R1 fwdrv;Firewall Driver; E:\WINDOWS\system32\drivers\fwdrv.sys [2005-09-26 286720]
R1 intelppm;Řadič procesoru Intel; E:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; E:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 khips;Kerio HIPS Driver; E:\WINDOWS\system32\drivers\khips.sys [2005-09-26 81920]
R1 SCDEmu;SCDEmu; E:\WINDOWS\system32\drivers\SCDEmu.sys [2009-03-15 56268]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; E:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 adfs;adfs; E:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
R2 aswFsBlk;aswFsBlk; E:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-04-18 19544]
R2 aswMon2;avast! Standard Shield Support; E:\WINDOWS\system32\drivers\aswMon2.sys [2011-04-18 102488]
R2 atksgt;atksgt; E:\WINDOWS\system32\DRIVERS\atksgt.sys [2010-05-21 281760]
R2 DS1410D;DS1410D; \??\E:\WINDOWS\system32\drivers\ds1410d.sys []
R2 epfw;epfw; E:\WINDOWS\system32\DRIVERS\epfw.sys [2009-02-06 130952]
R2 Hardlock;Hardlock; \??\E:\WINDOWS\system32\drivers\hardlock.sys []
R2 Haspnt;Haspnt; \??\E:\WINDOWS\system32\drivers\Haspnt.sys []
R2 irda;Protokol IrDA; E:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-14 88192]
R2 lirsgt;lirsgt; E:\WINDOWS\system32\DRIVERS\lirsgt.sys [2010-05-21 25888]
R2 Sentinel;Sentinel; E:\WINDOWS\System32\Drivers\SENTINEL.SYS [2001-06-21 73728]
R3 Arp1394;Protokol 1394 ARP Client; E:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-27 60800]
R3 FsUsbExDisk;FsUsbExDisk; \??\E:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; E:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Ovladač třídy standardu HID; E:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); E:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-02-13 5029376]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1; E:\WINDOWS\system32\drivers\libusb0.sys [2005-03-09 33792]
R3 MarvinBus;Pinnacle Marvin Bus; E:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
R3 mouhid;Ovladač myši standardu HID; E:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NIC1394;1394 Net Driver; E:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-27 61824]
R3 nv;nv; E:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2012-02-10 13415040]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; E:\WINDOWS\system32\drivers\nvhda32.sys [2012-01-17 123712]
R3 Rasirda;WAN Miniport (IrDA); E:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; E:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-01-03 105856]
R3 SCREAMINGBDRIVER;Screaming Bee Audio; E:\WINDOWS\system32\drivers\ScreamingBAudio.sys [2006-09-26 21920]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; E:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; E:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 61883;61883 Unit Device; E:\WINDOWS\system32\DRIVERS\61883.sys [2008-04-13 48128]
S3 alzinpx7;alzinpx7; E:\WINDOWS\system32\drivers\alzinpx7.sys []
S3 Ambfilt;Ambfilt; E:\WINDOWS\system32\drivers\Ambfilt.sys [2008-08-05 1684736]
S3 amjex6h6;amjex6h6; E:\WINDOWS\system32\drivers\amjex6h6.sys []
S3 Avc;AVC Device; E:\WINDOWS\system32\DRIVERS\avc.sys [2008-04-13 38912]
S3 Bulk;HDJBulk; E:\WINDOWS\System32\Drivers\HDJBulk.sys [2008-12-09 83328]
S3 catchme;catchme; \??\E:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; E:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-07-09 16384]
S3 eamon;eamon; E:\WINDOWS\system32\DRIVERS\eamon.sys [2009-02-06 113448]
S3 gHidPnp;USB Device Enhanced Function Driver; E:\WINDOWS\System32\Drivers\gHidPnp.Sys [2006-07-14 14848]
S3 gMouUsb;USB Mouse Device Drv; E:\WINDOWS\system32\DRIVERS\gMouUsb.sys [2006-07-14 9984]
S3 HDJAsioK;HDJAsioK; E:\WINDOWS\System32\Drivers\HDJAsioK.sys [2008-12-09 132608]
S3 HDJMidi;Hercules DJ Console MIDI; E:\WINDOWS\system32\DRIVERS\HDJMidi.sys [2008-12-05 95872]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; E:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2008-09-26 101376]
S3 imhidusb;Immersion's HID USB Driver; E:\WINDOWS\system32\DRIVERS\imhidusb.sys [2001-07-23 29372]
S3 irsir;Microsoft Serial Infrared Driver; E:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
S3 ksaud;Creative USB Audio Driver; E:\WINDOWS\system32\drivers\ksaud.sys [2008-12-11 768768]
S3 ksaudfl;ksaudfl; E:\WINDOWS\system32\drivers\ksaudfl.sys [2008-10-24 1830912]
S3 Monfilt;Monfilt; E:\WINDOWS\system32\drivers\Monfilt.sys [2006-01-04 1389056]
S3 MSDV;Microsoft DV Camera and VCR; E:\WINDOWS\system32\DRIVERS\msdv.sys [2004-07-09 52096]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; E:\WINDOWS\system32\drivers\MSTEE.sys [2002-12-12 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; E:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-07-09 83968]
S3 NdisIP;Microsoft TV/Video Connection; E:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-07-09 10112]
S3 nm;Ovladač programu Sledování sítě; E:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-14 40320]
S3 nmwcd;Nokia USB Phone Parent Driver; E:\WINDOWS\system32\drivers\ccdcmb.sys [2011-05-18 18176]
S3 nmwcdc;Nokia USB Communication Driver; E:\WINDOWS\system32\drivers\ccdcmbo.sys [2011-05-18 23168]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; E:\WINDOWS\system32\drivers\nmwcdnsu.sys [2011-05-18 137600]
S3 NPF;NetGroup Packet Filter Driver; E:\WINDOWS\system32\drivers\npf.sys [2007-11-06 34064]
S3 NPPTNT2;NPPTNT2; \??\E:\WINDOWS\system32\npptNT2.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; E:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SLIP;BDA Slip De-Framer; E:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-07-09 10880]
S3 Sntnlusb;Rainbow USB SuperPro; E:\WINDOWS\system32\DRIVERS\SNTNLUSB.SYS [2001-06-21 20032]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); E:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); E:\WINDOWS\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); E:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; E:\WINDOWS\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 streamip;BDA IPSink; E:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-07-09 14976]
S3 Tablet2k;Serial Tablet Port Driver; E:\WINDOWS\System32\Drivers\Tablet2k.sys [2000-06-13 15370]
S3 TClass2k;Tablet Class Driver; E:\WINDOWS\system32\DRIVERS\TClass2k.sys [2003-03-05 23202]
S3 UCTblHid;HID Tablet Port Driver; E:\WINDOWS\system32\DRIVERS\UCTblHid.sys [2003-03-05 11090]
S3 upperdev;upperdev; E:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2011-05-18 8192]
S3 usbaudio;Ovladač zvukové karty USB (WDM); E:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbprint;Třída USB Printer; E:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; E:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; E:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; E:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2011-05-18 8192]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; E:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 vproiah;vproiah; E:\WINDOWS\system32\DRIVERS\vproiah.sys [2011-08-03 16128]
S3 Wdf01000;Kernel Mode Driver Frameworks service; E:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WinUSB;Sony Ericsson USB Device sa0101 Driver; E:\WINDOWS\system32\DRIVERS\WinUSB.sys [2006-11-02 39368]
S3 WpdUsb;WpdUsb; E:\WINDOWS\system32\DRIVERS\wpdusb.sys [2008-04-27 38528]
S3 WSTCODEC;World Standard Teletext Codec; E:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-07-09 18688]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; E:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; E:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-04-18 42184]
R2 FlexService;Remote Connections Service; E:\Program Files\RapidBIT\cisvc.exe [2009-05-17 41984]
R2 FsUsbExService;FsUsbExService; E:\WINDOWS\system32\FsUsbExService.Exe [2009-03-31 233472]
R2 JavaQuickStarterService;Java Quick Starter; E:\Program Files\Java\jre6\bin\jqs.exe [2011-02-02 153376]
R2 KPF4;Kerio Personal Firewall 4; E:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe [2005-10-10 1617920]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1; E:\WINDOWS\system32\libusbd-nt.exe [2005-03-09 18944]
R2 NVSvc;NVIDIA Driver Helper Service; E:\WINDOWS\system32\nvsvc32.exe [2012-02-10 164160]
R2 nvUpdatusService;NVIDIA Update Service Daemon; E:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-10 2348352]
R2 PCSUService;PC Speed Up Service; E:\Program Files\Zrychleni Pocitace\PCSUService.exe [2011-12-06 267488]
R2 PnkBstrA;PnkBstrA; E:\WINDOWS\system32\PnkBstrA.exe [2011-10-16 75136]
R2 QipGuard;QipGuard; E:\Program Files\QipGuard\QipGuard.exe [2011-10-12 191440]
R2 WinDefend;Windows Defender; E:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R2 WinTabService;WinTab Service; E:\WINDOWS\system32\DRIVERS\WtSrv.exe [2003-09-30 40960]
R2 wlidsvc;Windows Live ID Sign-in Assistant; e:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; E:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 Irmon;Sledování infračerveného přenosu; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 SkypeUpdate;Skype Updater; E:\Program Files\Skype\Updater\Updater.exe [2012-01-31 158856]
S3 Adobe LM Service;Adobe LM Service; E:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-12-04 72704]
S3 aspnet_state;ASP.NET State Service; E:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; E:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-01-16 1045256]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; E:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; E:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 mple7docserver;Maya 7 PLE Documentation Server; E:\Programy\Maya\docs\wrapper.exe [2004-07-16 126976]
S3 npggsvc;nProtect GameGuard Service; E:\WINDOWS\system32\GameMon.des [2011-04-25 4160376]
S3 ose;Office Source Engine; E:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); E:\Program Files\WinPcap\rpcapd.exe [2007-11-06 92792]
S3 ServiceLayer;ServiceLayer; E:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2011-06-08 633856]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; E:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
S3 SwitchBoard;SwitchBoard; E:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; E:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; E:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 gupdate1c9eea6ae1c5426;Služba Google Update (gupdate1c9eea6ae1c5426); E:\Program Files\Google\Update\GoogleUpdate.exe [2009-06-16 133104]
S4 gupdatem;Služba Google Update (gupdatem); E:\Program Files\Google\Update\GoogleUpdate.exe [2009-06-16 133104]
S4 NBService;NBService; E:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; e:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 NMIndexingService;NMIndexingService; E:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119410
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu, pomalý pc, vytížení CPU, praská zvuk.

#2 Příspěvek od Rudy »

Máte téměř zcela zaplněný disk. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do nového okna zkopírujte:
:files
E:\Documents and Settings\Administrator\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
E:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
E:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
E:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1004336348-1801674531-1417001333-500Core1cc8e22aa83283a.job
E:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1004336348-1801674531-1417001333-500UA.job

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Bary
Návštěvník
Návštěvník
Příspěvky: 22
Registrován: 16 dub 2006 13:30

Re: Prosím o kontrolu, pomalý pc, vytížení CPU, praská zvuk.

#3 Příspěvek od Bary »

Zde je log.


Logfile of random's system information tool 1.09 (written by random/random)
Run by Administrator at 2012-07-31 22:25:28
Systém Microsoft Windows XP Professional Service Pack 3
System drive E: has 2 GB (1%) free of 305 GB
Total RAM: 3199 MB (73% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:25:33, on 31.7.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17109)
Boot mode: Normal

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Windows Defender\MsMpEng.exe
E:\Program Files\Zrychleni Pocitace\PCSUService.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Alwil Software\Avast5\AvastSvc.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\RapidBIT\cisvc.exe
E:\WINDOWS\system32\FsUsbExService.Exe
E:\Program Files\Java\jre6\bin\jqs.exe
E:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
E:\WINDOWS\system32\libusbd-nt.exe
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\PnkBstrA.exe
E:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
E:\Program Files\QipGuard\QipGuard.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\DRIVERS\WtSrv.exe
e:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
e:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
E:\WINDOWS\system32\wbem\wmiapsrv.exe
E:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
E:\WINDOWS\notepad.exe
E:\WINDOWS\system32\wuauclt.exe
E:\Genius\ioCentre\gTaskBar.exe
E:\WINDOWS\RTHDCPL.EXE
E:\WINDOWS\system32\RunDLL32.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Documents and Settings\Administrator\Data aplikací\QipGuard\QipGuard.exe
E:\Program Files\DAEMON Tools Pro\DTAgent.exe
E:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
E:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
E:\Documents and Settings\Administrator\Dokumenty\Downloads\RSIT.exe
E:\Program Files\trend micro\Administrator.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {95289393-33EA-4F8D-B952-483415B9C955} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - e:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - E:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - E:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - E:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [ioCentre] E:\Genius\ioCentre\gTaskBar.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] E:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [QIP Internet Guardian] E:\Documents and Settings\Administrator\Data aplikací\QipGuard\QipGuard.exe /p
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "E:\Program Files\DAEMON Tools Pro\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [Google Update] "E:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-21-1004336348-1801674531-1417001333-1004\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1004336348-1801674531-1417001333-1004\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'UpdatusUser')
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - E:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - E:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - E:\Documents and Settings\Administrator\Plocha\PartyCasino.lnk (file missing)
O9 - Extra 'Tools' menuitem: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - E:\Documents and Settings\Administrator\Plocha\PartyCasino.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - E:\Program Files\QIP\qip.exe (HKCU)
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{85F79B9D-A40F-473F-82BE-A1A617E9C80E}: NameServer = 213.191.99.9
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - E:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - E:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - E:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - E:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Remote Connections Service (FlexService) - BitMicro Software Corporation - E:\Program Files\RapidBIT\cisvc.exe
O23 - Service: FsUsbExService - Teruten - E:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - E:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - E:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - http://libusb-win32.sourceforge.net - E:\WINDOWS\system32\libusbd-nt.exe
O23 - Service: Maya 7 PLE Documentation Server (mple7docserver) - Unknown owner - E:\Programy\Maya\docs\wrapper.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - E:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - E:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PC Speed Up Service (PCSUService) - Unknown owner - E:\Program Files\Zrychleni Pocitace\PCSUService.exe
O23 - Service: PnkBstrA - Unknown owner - E:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: QipGuard - QIP.ru - E:\Program Files\QipGuard\QipGuard.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - E:\Program Files\WinPcap\rpcapd.exe
O23 - Service: ServiceLayer - Nokia - E:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - E:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - E:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - E:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: WinTab Service (WinTabService) - Tablet Driver - E:\WINDOWS\system32\DRIVERS\WtSrv.exe

--
End of file - 10127 bytes

======Scheduled tasks folder======

E:\WINDOWS\tasks\Clean System Memory.job
E:\WINDOWS\tasks\MP Scheduled Scan.job
E:\WINDOWS\tasks\RegCure Program Check.job
E:\WINDOWS\tasks\RegCure.job
E:\WINDOWS\tasks\WGASetup.job

=========Mozilla firefox=========

ProfilePath - E:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\80w6ee87.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://qip.ru"
prefs.js - "extensions.enabledItems" - "{b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6, eafo3fflauncher@ea.com:1.1, {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.76, {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.7, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.7, {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11, {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14, {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}:6.0.18, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, jqs@sun.com:1.0, {20a82645-c095-46ed-80e3-08825760534b}:1.2.1, personas@christopher.beard:1.6.2, {32a1fd71-835e-4b11-8e54-886fda0b4c89}:1.1, {ea614400-e918-4741-9a97-7a972ff7c30b}:2.1.14, {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1, {E22FCDEF-FF51-4525-AF64-FC91756B5977}:1.0, {EFE81DF7-961E-42A8-96CA-5696882A4558}:1.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5"
prefs.js - "keyword.URL" - "http://search.qip.ru/search?from=FF&query="

"jqs@sun.com"=E:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{20a82645-c095-46ed-80e3-08825760534b}"=E:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}"=E:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.235 Plugin
"Path"=E:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=E:\WINDOWS\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Web Player
"Path"=E:\Program Files\DivX\DivX Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=E:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@iahgames.com/prodown]
"Description"=IAHGames 2.03.2331
"Path"=E:\Program Files\IAHgames\Playfast\npiahpd.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=E:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=E:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=E:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=E:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@rsj.de/prodown]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@thrixxx.com/WebLaunch]
"Description"=thriXXX WebLaunch 1.0
"Path"=E:\Program Files\thriXXX\WebLaunch\Binaries\npWebLaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=E:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=E:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll

E:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
{E22FCDEF-FF51-4525-AF64-FC91756B5977}
{EFE81DF7-961E-42A8-96CA-5696882A4558}

E:\Program Files\Mozilla Firefox\components\
aboutCertError.js
aboutPrivateBrowsing.js
aboutRights.js
aboutRobots.js
aboutSessionRestore.js
binary.manifest
browser.xpt
browsercomps.dll
browserdirprovider.dll
brwsrcmp.dll
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
npwachk.xpt
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsHandlerService.js
nsHelperAppDlg.js
nsIQTScriptablePlugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPostUpdateWin.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js

E:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npdeployJava1.dll
npdivx32.dll
npdivx32.xpt
npnul32.dll
NPOFFICE.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
npwachk.dll
npWebLaunch.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

E:\Program Files\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

E:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\80w6ee87.default\extensions\
eafo3fflauncher@ea.com
personas@christopher.beard
{20a82645-c095-46ed-80e3-08825760534b}
{32a1fd71-835e-4b11-8e54-886fda0b4c89}
{800b5000-a755-47e1-992b-48a1c1357f07}
{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
{ea614400-e918-4741-9a97-7a972ff7c30b}

E:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\80w6ee87.default\searchplugins\
icqplugin-1.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin.gif
icqplugin.src
icqplugin.xml
MySpace.xml
qip-search.xml
search-results.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-15 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - e:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - E:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-04-02 266240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - E:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-09 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - E:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-02-09 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - E:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-04-02 266240]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ioCentre"=E:\Genius\ioCentre\gTaskBar.exe [2006-12-08 241664]
"RTHDCPL"=E:\WINDOWS\RTHDCPL.EXE [2009-02-13 17508864]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"NvCplDaemon"=E:\WINDOWS\system32\NvCpl.dll [2012-02-10 15494464]
"nwiz"=E:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2012-02-10 1634112]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=E:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
""= []
"QIP Internet Guardian"=E:\Documents and Settings\Administrator\Data aplikací\QipGuard\QipGuard.exe [2011-10-12 191440]
"DAEMON Tools Pro Agent"=E:\Program Files\DAEMON Tools Pro\DTAgent.exe [2012-02-02 3034432]
"Google Update"=E:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-06-24 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - E:\WINDOWS\system32\WPDShServiceObj.dll [2008-04-27 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=E:\PROGRA~1\WIFD1F~1\MpShHook.dll [2006-11-03 83224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCMD"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableTaskMgr"=0
"DisableCMD"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoSetActiveDesktop"=0
"NoActiveDesktopChanges"=0
"NoFolderOptions"=0
"NoRun"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoSetActiveDesktop"=0
"NoActiveDesktopChanges"=0
"NoFolderOptions"=0
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"E:\hry\Firefly Studios\Stronghold Legends\StrongholdLegends.exe"="E:\hry\Firefly Studios\Stronghold Legends\StrongholdLegends.exe:*:Enabled:Stronghold Legends"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"E:\Programy\Maya85\bin\maya.exe"="E:\Programy\Maya85\bin\maya.exe:*:Enabled:Maya"
"C:\Program Files\BearShare\BearShare.exe"="C:\Program Files\BearShare\BearShare.exe:*:Enabled:BearShare"
"C:\Program Files\ICQ\ICQ6\ICQ.exe"="C:\Program Files\ICQ\ICQ6\ICQ.exe:*:Enabled:ICQ Library"
"E:\Program Files\QIP\qip.exe"="E:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"E:\Documents and Settings\Administrator\Application Data\PowerChallenge\PowerSoccer\PowerSoccer.exe"="E:\Documents and Settings\Administrator\Application Data\PowerChallenge\PowerSoccer\PowerSoccer.exe:*:Enabled:PowerSoccer"
"E:\Program Files\Guillemot\tools\giWebUpdater.exe"="E:\Program Files\Guillemot\tools\giWebUpdater.exe:*:Enabled:Guillemot Web Updater"
"E:\Program Files\Electronic Arts\EADM\Core.exe"="E:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager"
"E:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe"="E:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe:*:Enabled:Kerio Personal Firewall 4 - GUI"
"E:\Programy\Autodesk\Maya8.5\bin\maya.exe"="E:\Programy\Autodesk\Maya8.5\bin\maya.exe:*:Enabled:Maya"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"E:\Program Files\ICQ6.5\ICQ.exe"="E:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"E:\Programy\SmartFTP Client\SmartFTP.exe"="E:\Programy\SmartFTP Client\SmartFTP.exe:*:Enabled:SmartFTP Client 3.0"
"E:\hry\Firefly Studios\Stronghold 2\Stronghold2.exe"="E:\hry\Firefly Studios\Stronghold 2\Stronghold2.exe:*:Enabled:Stronghold 2"
"E:\hry\EA GAMES\Battlefield 2\BF2.exe"="E:\hry\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2"
"E:\Programy\Pinnacle\VideoSpin2\Programs\RM.exe"="E:\Programy\Pinnacle\VideoSpin2\Programs\RM.exe:*:Enabled:Render Manager"
"E:\Programy\Pinnacle\VideoSpin2\Programs\umi.exe"="E:\Programy\Pinnacle\VideoSpin2\Programs\umi.exe:*:Enabled:umi"
"E:\Programy\Pinnacle\VideoSpin2\Programs\VideoSpin.exe"="E:\Programy\Pinnacle\VideoSpin2\Programs\VideoSpin.exe:*:Enabled:Pinnacle VideoSpin"
"E:\hry\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe"="E:\hry\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
"E:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe"="E:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
"E:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe"="E:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
"E:\Programy\Pinnacle\Studio 12\Programs\RM.exe"="E:\Programy\Pinnacle\Studio 12\Programs\RM.exe:*:Enabled:Render Manager"
"E:\Programy\Pinnacle\Studio 12\Programs\Studio.exe"="E:\Programy\Pinnacle\Studio 12\Programs\Studio.exe:*:Enabled:Studio"
"E:\Programy\Pinnacle\Studio 12\Programs\umi.exe"="E:\Programy\Pinnacle\Studio 12\Programs\umi.exe:*:Enabled:umi"
"E:\hry\KONAMI\Pro Evolution Soccer 2011\pes2011.exe"="E:\hry\KONAMI\Pro Evolution Soccer 2011\pes2011.exe:*:Enabled:Pro Evolution Soccer 2011"
"E:\Program Files\ICQ7.2\ICQ.exe"="E:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"E:\Program Files\ICQ7.2\aolload.exe"="E:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"E:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="E:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
"E:\Program Files\Autodesk\Backburner\monitor.exe"="E:\Program Files\Autodesk\Backburner\monitor.exe:*:Enabled:backburner 2.3 monitor"
"E:\Program Files\Autodesk\Backburner\manager.exe"="E:\Program Files\Autodesk\Backburner\manager.exe:*:Enabled:backburner 2.3 manager"
"E:\Program Files\Autodesk\Backburner\server.exe"="E:\Program Files\Autodesk\Backburner\server.exe:*:Enabled:backburner 2.3 server"
"E:\hry\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe"="E:\hry\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe:*:Enabled:Battlefield: Bad Company™ 2"
"E:\hry\Electronic Arts\Need for Speed(TM) Hot Pursuit\Launcher.exe"="E:\hry\Electronic Arts\Need for Speed(TM) Hot Pursuit\Launcher.exe:*:Enabled:Need for Speed(TM) Hot Pursuit"
"E:\hry\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat"="E:\hry\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"E:\WINDOWS\system32\PnkBstrA.exe"="E:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"E:\WINDOWS\system32\PnkBstrB.exe"="E:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"E:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe"="E:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe:*:Enabled:Kerio Personal Firewall 4 - Service"
"E:\hry\Atari\TDU2\_UpLauncher.exe"="E:\hry\Atari\TDU2\_UpLauncher.exe:*:Enabled:UpLauncher"
"E:\hry\Atari\TDU2\UpLauncher.exe"="E:\hry\Atari\TDU2\UpLauncher.exe:*:Enabled:Test Drive Unlimited 2"
"E:\hry\Ubisoft\Assassin's Creed Brotherhood\ACBSP.exe"="E:\hry\Ubisoft\Assassin's Creed Brotherhood\ACBSP.exe:*:Enabled:Assassin's Creed Brotherhood"
"E:\hry\Ubisoft\Assassin's Creed Brotherhood\ACBMP.exe"="E:\hry\Ubisoft\Assassin's Creed Brotherhood\ACBMP.exe:*:Enabled:Assassin's Creed Brotherhood Multiplayer"
"E:\hry\Ubisoft\Assassin's Creed Brotherhood\AssassinsCreedBrotherhood.exe"="E:\hry\Ubisoft\Assassin's Creed Brotherhood\AssassinsCreedBrotherhood.exe:*:Enabled:Assassin's Creed Brotherhood Update"
"E:\hry\Ubisoft\Assassin's Creed Brotherhood\UPlayBrowser.exe"="E:\hry\Ubisoft\Assassin's Creed Brotherhood\UPlayBrowser.exe:*:Enabled:Assassin's Creed Brotherhood Uplay"
"E:\hry\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe"="E:\hry\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:*:Enabled:Assassin's Creed Dx9"
"E:\hry\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe"="E:\hry\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:*:Enabled:Assassin's Creed Dx10"
"E:\hry\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe"="E:\hry\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:*:Enabled:Assassin's Creed Update"
"E:\hry\Codemasters\DiRT 3\dirt3_game.exe"="E:\hry\Codemasters\DiRT 3\dirt3_game.exe:*:Enabled:DiRT 3"
"E:\Program Files\Pando Networks\Media Booster\PMB.exe"="E:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"E:\hry\GamesCampus\MLBDugoutHeroes\MLBDugoutHeroes.exe"="E:\hry\GamesCampus\MLBDugoutHeroes\MLBDugoutHeroes.exe:*:Enabled:MLBDugoutHeroes"
"Z:\game\FF2Client.exe"="Z:\game\FF2Client.exe:*:Enabled:FIFA ONLINE"
"E:\hry\EA Sports\Fifa Online 2\FF2Client.exe"="E:\hry\EA Sports\Fifa Online 2\FF2Client.exe:*:Enabled:FIFA ONLINE"
"E:\hry\Ubisoft\Might & Magic Heroes VI - Internal Private Closed Beta\Might & Magic Heroes VI - Internal Private Closed Beta.exe"="E:\hry\Ubisoft\Might & Magic Heroes VI - Internal Private Closed Beta\Might & Magic Heroes VI - Internal Private Closed Beta.exe:*:Enabled:Might & Magic Heroes VI - Internal Private Closed Beta"
"E:\hry\Microsoft Games\Age of Empires Online\Spartan.exe"="E:\hry\Microsoft Games\Age of Empires Online\Spartan.exe:*:Enabled:Age of Empires Online"
"E:\hry\Ubisoft\Might & Magic Heroes VI\Might & Magic Heroes VI.exe"="E:\hry\Ubisoft\Might & Magic Heroes VI\Might & Magic Heroes VI.exe:*:Enabled:Might & Magic Heroes VI"
"E:\hry\Ubisoft\Driver San Francisco\Driver.exe"="E:\hry\Ubisoft\Driver San Francisco\Driver.exe:*:Enabled:Driver San Francisco"
"E:\hry\Battlefield 3™\bf3.exe"="E:\hry\Battlefield 3™\bf3.exe:*:Enabled:Battlefield 3™"
"E:\hry\KONAMI\Pro Evolution Soccer 2012\pes2012.exe"="E:\hry\KONAMI\Pro Evolution Soccer 2012\pes2012.exe:*:Enabled:Pro Evolution Soccer 2012"
"E:\hry\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="E:\hry\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM)"
"E:\Program Files\Sony Ericsson\Update Engine\Sony Ericsson Update Engine.exe"="E:\Program Files\Sony Ericsson\Update Engine\Sony Ericsson Update Engine.exe:*:Enabled:Update Engine"
"E:\hry\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe"="E:\hry\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
"E:\Programy\Pinnacle\Studio 15\Programs\RM.exe"="E:\Programy\Pinnacle\Studio 15\Programs\RM.exe:*:Enabled:Render Manager"
"E:\Programy\Pinnacle\Studio 15\Programs\Studio.exe"="E:\Programy\Pinnacle\Studio 15\Programs\Studio.exe:*:Enabled:Studio"
"E:\Programy\Pinnacle\Studio 15\Programs\umi.exe"="E:\Programy\Pinnacle\Studio 15\Programs\umi.exe:*:Enabled:umi"
"E:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="E:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"E:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"="E:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe"
"E:\Program Files\Skype\Phone\Skype.exe"="E:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"E:\Program Files\uTorrent\uTorrent.exe"="E:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"E:\Program Files\Ubisoft\Rayman Origins\Rayman Origins.exe"="E:\Program Files\Ubisoft\Rayman Origins\Rayman Origins.exe:*:Enabled:Rayman Origins"
"E:\Program Files\Ubisoft\Rayman Origins\gu.exe"="E:\Program Files\Ubisoft\Rayman Origins\gu.exe:*:Enabled:Rayman Origins"
"E:\Program Files\Ubisoft\Assassin's Creed Revelations\ACRSP.exe"="E:\Program Files\Ubisoft\Assassin's Creed Revelations\ACRSP.exe:*:Enabled:Assassin's Creed Revelations"
"E:\Program Files\Ubisoft\Assassin's Creed Revelations\ACRMP.exe"="E:\Program Files\Ubisoft\Assassin's Creed Revelations\ACRMP.exe:*:Enabled:Assassin's Creed Revelations Multiplayer"
"E:\Program Files\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe"="E:\Program Files\Ubisoft\Assassin's Creed Revelations\AssassinsCreedRevelations.exe:*:Enabled:Assassin's Creed Revelations Update"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"E:\Program Files\ICQ7.2\ICQ.exe"="E:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"E:\Program Files\ICQ7.2\aolload.exe"="E:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"E:\Program Files\Pando Networks\Media Booster\PMB.exe"="E:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=E:\WINDOWS\system32\Iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=E:\WINDOWS\system32\l3codeca.acm
"msacm.vorbis"=vorbis.acm
"SENTINEL"=snti386.dll
"vidc.VP60"=E:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=E:\WINDOWS\system32\vp6vfw.dll
"VIDC.CFHD"=CFHD.dll
"midi1"=wdmaud.drv
"wave1"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"midi3"=wdmaud.drv
"wave2"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"midi5"=wdmaud.drv
"wave3"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.lhacm"=lhacm.acm
"vidc.mjpg"=pvmjpg30.dll
"wave5"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux4"=wdmaud.drv
"wave6"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux5"=wdmaud.drv
"wave7"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux6"=wdmaud.drv
"wave8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux7"=wdmaud.drv
"wave9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux8"=wdmaud.drv
"VIDC.WMV3"=wmv9vcm.dll
"VIDC.FMVC"=fmcodec.dll
"wave4"=wdmaud.drv
"mixer4"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.MPG4"=mpg4c32.dll
"VIDC.MP42"=mpg4c32.dll
"aux9"=wdmaud.drv

======File associations======

.ini - open - "E:\Programy\IDM Computer Solutions\UltraEdit\Uedit32.exe" "%1"
.txt - open - "E:\Programy\IDM Computer Solutions\UltraEdit\Uedit32.exe" "%1"

======List of files/folders created in the last 1 month======

2012-07-31 22:13:45 ----D---- E:\_OTM
2012-07-29 12:47:39 ----D---- E:\i68Backups
2012-07-14 16:41:57 ----D---- E:\Program Files\DAEMON Tools Pro
2012-07-14 15:36:04 ----D---- E:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Pro
2012-07-07 21:03:02 ----A---- E:\WINDOWS\system32\msvcr90.dll
2012-07-07 21:01:35 ----A---- E:\WINDOWS\SchedLgU.Txt
2012-07-07 19:02:04 ----HDC---- E:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$

======List of files/folders modified in the last 1 month======

2012-07-31 22:25:33 ----D---- E:\WINDOWS\Prefetch
2012-07-31 22:25:29 ----D---- E:\Program Files\trend micro
2012-07-31 22:25:27 ----D---- E:\WINDOWS\temp
2012-07-31 22:22:55 ----D---- E:\Program Files\Zrychleni Pocitace
2012-07-31 22:19:18 ----SD---- E:\WINDOWS\Tasks
2012-07-31 22:17:14 ----D---- E:\WINDOWS
2012-07-31 22:14:46 ----D---- E:\WINDOWS\system32\CatRoot2
2012-07-31 22:14:17 ----D---- E:\WINDOWS\system32
2012-07-31 19:29:02 ----AC---- E:\WINDOWS\NeroDigital.ini
2012-07-31 18:02:14 ----HD---- E:\WINDOWS\inf
2012-07-29 22:21:17 ----D---- E:\temp
2012-07-29 20:41:43 ----AC---- E:\WINDOWS\win.ini
2012-07-29 20:41:43 ----AC---- E:\WINDOWS\system.ini
2012-07-28 10:07:01 ----D---- E:\hry
2012-07-28 10:05:49 ----D---- E:\Program Files\Ubisoft
2012-07-28 10:03:54 ----D---- E:\Downloady
2012-07-28 01:41:22 ----D---- E:\Documents and Settings\Administrator\Data aplikací\uTorrent
2012-07-27 18:44:09 ----D---- E:\Program Files
2012-07-27 11:36:25 ----D---- E:\Documents and Settings\Administrator\Data aplikací\Skype
2012-07-26 23:16:46 ----D---- E:\Program Files\Mozilla Firefox
2012-07-24 18:39:49 ----SHD---- E:\WINDOWS\Installer
2012-07-24 18:39:48 ----SHD---- E:\Config.Msi
2012-07-22 20:26:19 ----HD---- E:\Program Files\InstallShield Installation Information
2012-07-17 17:53:18 ----D---- E:\Documents and Settings\Administrator\Data aplikací\gtk-2.0
2012-07-16 16:46:24 ----D---- E:\Documents and Settings\All Users\Data aplikací\Ubisoft
2012-07-16 16:16:58 ----D---- E:\WINDOWS\WinSxS
2012-07-16 16:15:32 ----D---- E:\WINDOWS\system32\DirectX
2012-07-16 16:14:40 ----RSD---- E:\WINDOWS\assembly
2012-07-14 17:03:46 ----D---- E:\Program Files\Atari
2012-07-14 16:51:43 ----D---- E:\Documents and Settings\Administrator\Data aplikací\DAEMON Tools Pro
2012-07-14 15:31:29 ----D---- E:\Program Files\DAEMON Tools Lite
2012-07-12 06:10:18 ----HD---- E:\WINDOWS\$hf_mig$
2012-07-08 16:36:05 ----D---- E:\Programy
2012-07-08 16:36:05 ----D---- E:\Program Files\VstPlugins
2012-07-08 16:20:36 ----AD---- E:\Documents and Settings\All Users\Data aplikací\TEMP
2012-07-08 11:58:35 ----D---- E:\Program Files\K-Lite Codec Pack
2012-07-07 20:50:47 ----D---- E:\WINDOWS\system32\CatRoot
2012-07-07 13:12:07 ----D---- E:\Documents and Settings\Administrator\Data aplikací\LucasArts
2012-07-02 18:54:03 ----RSD---- E:\WINDOWS\Fonts

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 imagedrv;imagedrv; E:\WINDOWS\System32\Drivers\imagedrv.sys [2007-07-03 11304]
R0 imagesrv;imagesrv; E:\WINDOWS\system32\DRIVERS\imagesrv.sys [2007-07-03 132904]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; E:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; E:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 sptd;sptd; E:\WINDOWS\System32\Drivers\sptd.sys [2012-07-14 473656]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; E:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-01-18 77696]
R1 Aavmker4;avast! Asynchronous Virus Monitor; E:\WINDOWS\system32\drivers\Aavmker4.sys [2011-04-18 30680]
R1 aswRdr;aswRdr; E:\WINDOWS\system32\drivers\aswRdr.sys [2011-04-18 25432]
R1 aswSnx;aswSnx; E:\WINDOWS\system32\drivers\aswSnx.sys [2011-04-18 441176]
R1 aswSP;aswSP; E:\WINDOWS\system32\drivers\aswSP.sys [2011-04-18 307288]
R1 aswTdi;avast! Network Shield Support; E:\WINDOWS\system32\drivers\aswTdi.sys [2011-04-18 49240]
R1 ehdrv;ehdrv; E:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
R1 epfwtdi;epfwtdi; E:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-02-06 56280]
R1 fwdrv;Firewall Driver; E:\WINDOWS\system32\drivers\fwdrv.sys [2005-09-26 286720]
R1 intelppm;Řadič procesoru Intel; E:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; E:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 khips;Kerio HIPS Driver; E:\WINDOWS\system32\drivers\khips.sys [2005-09-26 81920]
R1 SCDEmu;SCDEmu; E:\WINDOWS\system32\drivers\SCDEmu.sys [2009-03-15 56268]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; E:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 adfs;adfs; E:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
R2 aswFsBlk;aswFsBlk; E:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-04-18 19544]
R2 aswMon2;avast! Standard Shield Support; E:\WINDOWS\system32\drivers\aswMon2.sys [2011-04-18 102488]
R2 atksgt;atksgt; E:\WINDOWS\system32\DRIVERS\atksgt.sys [2010-05-21 281760]
R2 DS1410D;DS1410D; \??\E:\WINDOWS\system32\drivers\ds1410d.sys []
R2 epfw;epfw; E:\WINDOWS\system32\DRIVERS\epfw.sys [2009-02-06 130952]
R2 Hardlock;Hardlock; \??\E:\WINDOWS\system32\drivers\hardlock.sys []
R2 Haspnt;Haspnt; \??\E:\WINDOWS\system32\drivers\Haspnt.sys []
R2 irda;Protokol IrDA; E:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-14 88192]
R2 lirsgt;lirsgt; E:\WINDOWS\system32\DRIVERS\lirsgt.sys [2010-05-21 25888]
R2 Sentinel;Sentinel; E:\WINDOWS\System32\Drivers\SENTINEL.SYS [2001-06-21 73728]
R3 Arp1394;Protokol 1394 ARP Client; E:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-27 60800]
R3 FsUsbExDisk;FsUsbExDisk; \??\E:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; E:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Ovladač třídy standardu HID; E:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); E:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-02-13 5029376]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1; E:\WINDOWS\system32\drivers\libusb0.sys [2005-03-09 33792]
R3 MarvinBus;Pinnacle Marvin Bus; E:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
R3 mouhid;Ovladač myši standardu HID; E:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NIC1394;1394 Net Driver; E:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-27 61824]
R3 nv;nv; E:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2012-02-10 13415040]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; E:\WINDOWS\system32\drivers\nvhda32.sys [2012-01-17 123712]
R3 Rasirda;WAN Miniport (IrDA); E:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; E:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-01-03 105856]
R3 SCREAMINGBDRIVER;Screaming Bee Audio; E:\WINDOWS\system32\drivers\ScreamingBAudio.sys [2006-09-26 21920]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; E:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; E:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 61883;61883 Unit Device; E:\WINDOWS\system32\DRIVERS\61883.sys [2008-04-13 48128]
S3 ahwhbihe;ahwhbihe; E:\WINDOWS\system32\drivers\ahwhbihe.sys []
S3 Ambfilt;Ambfilt; E:\WINDOWS\system32\drivers\Ambfilt.sys [2008-08-05 1684736]
S3 ap7i20ll;ap7i20ll; E:\WINDOWS\system32\drivers\ap7i20ll.sys []
S3 Avc;AVC Device; E:\WINDOWS\system32\DRIVERS\avc.sys [2008-04-13 38912]
S3 Bulk;HDJBulk; E:\WINDOWS\System32\Drivers\HDJBulk.sys [2008-12-09 83328]
S3 catchme;catchme; \??\E:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; E:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-07-09 16384]
S3 eamon;eamon; E:\WINDOWS\system32\DRIVERS\eamon.sys [2009-02-06 113448]
S3 gHidPnp;USB Device Enhanced Function Driver; E:\WINDOWS\System32\Drivers\gHidPnp.Sys [2006-07-14 14848]
S3 gMouUsb;USB Mouse Device Drv; E:\WINDOWS\system32\DRIVERS\gMouUsb.sys [2006-07-14 9984]
S3 HDJAsioK;HDJAsioK; E:\WINDOWS\System32\Drivers\HDJAsioK.sys [2008-12-09 132608]
S3 HDJMidi;Hercules DJ Console MIDI; E:\WINDOWS\system32\DRIVERS\HDJMidi.sys [2008-12-05 95872]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; E:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2008-09-26 101376]
S3 imhidusb;Immersion's HID USB Driver; E:\WINDOWS\system32\DRIVERS\imhidusb.sys [2001-07-23 29372]
S3 irsir;Microsoft Serial Infrared Driver; E:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
S3 ksaud;Creative USB Audio Driver; E:\WINDOWS\system32\drivers\ksaud.sys [2008-12-11 768768]
S3 ksaudfl;ksaudfl; E:\WINDOWS\system32\drivers\ksaudfl.sys [2008-10-24 1830912]
S3 Monfilt;Monfilt; E:\WINDOWS\system32\drivers\Monfilt.sys [2006-01-04 1389056]
S3 MSDV;Microsoft DV Camera and VCR; E:\WINDOWS\system32\DRIVERS\msdv.sys [2004-07-09 52096]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; E:\WINDOWS\system32\drivers\MSTEE.sys [2002-12-12 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; E:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-07-09 83968]
S3 NdisIP;Microsoft TV/Video Connection; E:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-07-09 10112]
S3 nm;Ovladač programu Sledování sítě; E:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-14 40320]
S3 nmwcd;Nokia USB Phone Parent Driver; E:\WINDOWS\system32\drivers\ccdcmb.sys [2011-05-18 18176]
S3 nmwcdc;Nokia USB Communication Driver; E:\WINDOWS\system32\drivers\ccdcmbo.sys [2011-05-18 23168]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; E:\WINDOWS\system32\drivers\nmwcdnsu.sys [2011-05-18 137600]
S3 NPF;NetGroup Packet Filter Driver; E:\WINDOWS\system32\drivers\npf.sys [2007-11-06 34064]
S3 NPPTNT2;NPPTNT2; \??\E:\WINDOWS\system32\npptNT2.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; E:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SLIP;BDA Slip De-Framer; E:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-07-09 10880]
S3 Sntnlusb;Rainbow USB SuperPro; E:\WINDOWS\system32\DRIVERS\SNTNLUSB.SYS [2001-06-21 20032]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); E:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); E:\WINDOWS\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); E:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; E:\WINDOWS\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 streamip;BDA IPSink; E:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-07-09 14976]
S3 Tablet2k;Serial Tablet Port Driver; E:\WINDOWS\System32\Drivers\Tablet2k.sys [2000-06-13 15370]
S3 TClass2k;Tablet Class Driver; E:\WINDOWS\system32\DRIVERS\TClass2k.sys [2003-03-05 23202]
S3 UCTblHid;HID Tablet Port Driver; E:\WINDOWS\system32\DRIVERS\UCTblHid.sys [2003-03-05 11090]
S3 upperdev;upperdev; E:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2011-05-18 8192]
S3 usbaudio;Ovladač zvukové karty USB (WDM); E:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbprint;Třída USB Printer; E:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; E:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; E:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; E:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2011-05-18 8192]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; E:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 vproiah;vproiah; E:\WINDOWS\system32\DRIVERS\vproiah.sys [2011-08-03 16128]
S3 Wdf01000;Kernel Mode Driver Frameworks service; E:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WinUSB;Sony Ericsson USB Device sa0101 Driver; E:\WINDOWS\system32\DRIVERS\WinUSB.sys [2006-11-02 39368]
S3 WpdUsb;WpdUsb; E:\WINDOWS\system32\DRIVERS\wpdusb.sys [2008-04-27 38528]
S3 WSTCODEC;World Standard Teletext Codec; E:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-07-09 18688]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; E:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; E:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-04-18 42184]
R2 FlexService;Remote Connections Service; E:\Program Files\RapidBIT\cisvc.exe [2009-05-17 41984]
R2 FsUsbExService;FsUsbExService; E:\WINDOWS\system32\FsUsbExService.Exe [2009-03-31 233472]
R2 JavaQuickStarterService;Java Quick Starter; E:\Program Files\Java\jre6\bin\jqs.exe [2011-02-02 153376]
R2 KPF4;Kerio Personal Firewall 4; E:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe [2005-10-10 1617920]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1; E:\WINDOWS\system32\libusbd-nt.exe [2005-03-09 18944]
R2 NVSvc;NVIDIA Driver Helper Service; E:\WINDOWS\system32\nvsvc32.exe [2012-02-10 164160]
R2 nvUpdatusService;NVIDIA Update Service Daemon; E:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-10 2348352]
R2 PCSUService;PC Speed Up Service; E:\Program Files\Zrychleni Pocitace\PCSUService.exe [2011-12-06 267488]
R2 PnkBstrA;PnkBstrA; E:\WINDOWS\system32\PnkBstrA.exe [2011-10-16 75136]
R2 QipGuard;QipGuard; E:\Program Files\QipGuard\QipGuard.exe [2011-10-12 191440]
R2 WinDefend;Windows Defender; E:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R2 WinTabService;WinTab Service; E:\WINDOWS\system32\DRIVERS\WtSrv.exe [2003-09-30 40960]
R2 wlidsvc;Windows Live ID Sign-in Assistant; e:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; E:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 Irmon;Sledování infračerveného přenosu; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 SkypeUpdate;Skype Updater; E:\Program Files\Skype\Updater\Updater.exe [2012-01-31 158856]
S3 Adobe LM Service;Adobe LM Service; E:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-12-04 72704]
S3 aspnet_state;ASP.NET State Service; E:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; E:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-01-16 1045256]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; E:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; E:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 mple7docserver;Maya 7 PLE Documentation Server; E:\Programy\Maya\docs\wrapper.exe [2004-07-16 126976]
S3 npggsvc;nProtect GameGuard Service; E:\WINDOWS\system32\GameMon.des [2011-04-25 4160376]
S3 ose;Office Source Engine; E:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); E:\Program Files\WinPcap\rpcapd.exe [2007-11-06 92792]
S3 ServiceLayer;ServiceLayer; E:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2011-06-08 633856]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; E:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
S3 SwitchBoard;SwitchBoard; E:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; E:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; E:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 gupdate1c9eea6ae1c5426;Služba Google Update (gupdate1c9eea6ae1c5426); E:\Program Files\Google\Update\GoogleUpdate.exe [2009-06-16 133104]
S4 gupdatem;Služba Google Update (gupdatem); E:\Program Files\Google\Update\GoogleUpdate.exe [2009-06-16 133104]
S4 NBService;NBService; E:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; e:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 NMIndexingService;NMIndexingService; E:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119410
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu, pomalý pc, vytížení CPU, praská zvuk.

#4 Příspěvek od Rudy »

Dvouklikem na soubor E:\Program Files\trend micro\Administrator.exe spustte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R3 - URLSearchHook: (no name) - {95289393-33EA-4F8D-B952-483415B9C955} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O4 - HKUS\S-1-5-21-1004336348-1801674531-1417001333-1004\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1004336348-1801674531-1417001333-1004\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'UpdatusUser')
O9 - Extra button: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - E:\Documents and Settings\Administrator\Plocha\PartyCasino.lnk (file missing)
O9 - Extra 'Tools' menuitem: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - E:\Documents and Settings\Administrator\Plocha\PartyCasino.lnk (file missing)
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp<. OTM po osbě uklidí. Nakonec restartujte PC. Vyčištěním přibylo asi 1,5GB volného místa, což je stále málo. Musíte odinstalovat z PC vše nepotřebné, případně některá data (dokumenty, obrázky, filmy, hudbu) přesunout na jiný disk.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Bary
Návštěvník
Návštěvník
Příspěvky: 22
Registrován: 16 dub 2006 13:30

Re: Prosím o kontrolu, pomalý pc, vytížení CPU, praská zvuk.

#5 Příspěvek od Bary »

Hotovo. Chcete nový log z RSIT?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119410
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu, pomalý pc, vytížení CPU, praská zvuk.

#6 Příspěvek od Rudy »

Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Bary
Návštěvník
Návštěvník
Příspěvky: 22
Registrován: 16 dub 2006 13:30

Re: Prosím o kontrolu, pomalý pc, vytížení CPU, praská zvuk.

#7 Příspěvek od Bary »

Možná nepatrná změna, ale musím říct, že praskání zvuku začalo po výměně Grafické karty.. Takže tam problém s virem atd. asi nebude. PC bych zrychlil uvolněním více místa na disku, bohužel nevím kam se ty GB ztratily :) Vyčištění disku a Ccleaner jsem použil. Jinak když zapnu pc, tak když se objeví plocha, start zvuk windows se ozve až třeba 3 minuty poté. A když chci krátce po startu něco spustit (např. prohlížeč), stihl bych si mezitím udělat večeři, než se to spustí :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119410
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu, pomalý pc, vytížení CPU, praská zvuk.

#8 Příspěvek od Rudy »

Máte někde nějaká data, kterých je hodně. Ty musí jinam (na jiné úložiště), pak je možné řešit věci další. Prohledejte Documents and settings\Administrator.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Bary
Návštěvník
Návštěvník
Příspěvky: 22
Registrován: 16 dub 2006 13:30

Re: Prosím o kontrolu, pomalý pc, vytížení CPU, praská zvuk.

#9 Příspěvek od Bary »

Já si v týdnu pořídím nový HDD, pak to na tomto disku trošku vyklidím a dám vědět. Zatím děkuji.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119410
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu, pomalý pc, vytížení CPU, praská zvuk.

#10 Příspěvek od Rudy »

Zatím není zač!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Bary
Návštěvník
Návštěvník
Příspěvky: 22
Registrován: 16 dub 2006 13:30

Re: Prosím o kontrolu, pomalý pc, vytížení CPU, praská zvuk.

#11 Příspěvek od Bary »

Dobrý den, již pracuji na uvolnění místa, ovšem po provedení předchozích kroků zvuk nejen praská, ale sám se ztlumuje, vypíná, zesiluje. Zapnu písničku, dám hlasitost tak akorát, po chvíli to začne řvát na celý pokoj a pak se to na 2 vteřiny vypne úplně. Bedničkama to není, dělá to i do sluchátek, bedničky na jiném pc běží v pořádku. Nevíte čím by to mohlo být?
Děkuji.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119410
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu, pomalý pc, vytížení CPU, praská zvuk.

#12 Příspěvek od Rudy »

To je poměrně zajímavá závada, která se moc často nevyskytuje. Zkuste nejprve zkontrolovat konektor, do něhož jsou repr připojeny. Může tam být špatný kontakt.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosím o kontrolu, pomalý pc, vytížení CPU, praská zvuk.

#13 Příspěvek od motji »

Jak to tu vypadá? :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119410
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu, pomalý pc, vytížení CPU, praská zvuk.

#14 Příspěvek od Rudy »

Zamykám pro neaktivitu. Pokude budete chtít v tématu pokračovat, kontaktujte mne, nebo některého moderátora přes e-mail. Děkuji.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno