Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pomalý pc + schovaná data?

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
teddys
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 19 zář 2012 20:02

Pomalý pc + schovaná data?

#1 Příspěvek od teddys »

Zdravím, potřeboval bych pomoct ....
za poslední půlrok se mi pc HROZIVĚ zpomalil a na disku C nemám žádné místo i když tam nemám vůbec nic .. moje složka windows má 17 gb, ale když označím všechny soubory a složky v ní, vylezou z toho jen 4gb :D
nevím jak udělat víc místa, protože jsem vymazal opravdu úplně vše ..
jsem bezradný

log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Administrator at 2012-09-19 21:00:57
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 2 GB (6%) free of 25 GB
Total RAM: 1535 MB (41% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:01:16, on 19.9.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Stardock\Object Desktop\ThemeManager\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ChatZum Toolbar\tbunsk9C.tmp\TbHelper2.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Dokumenty\Downloads\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.chatzum.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.chatzum.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\ChatZum Toolbar\tbunsk9C.tmp\tbhelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\BitComet\tools\BitCometBHO_1.3.3.2.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: TBSB09850 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\ChatZum Toolbar\tbunsk9C.tmp\tbcore3.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O3 - Toolbar: ChatZum Toolbar - {37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1} - C:\Program Files\ChatZum Toolbar\tbunsk9C.tmp\tbcore3.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://D:\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - res://D:\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://D:\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (file missing)
O9 - Extra button: Download with YouTube Clip Extractor - {4adf5b46-bb68-4558-997e-3b68315a3930} - C:\Program Files\YouTube Clip Extractor\ClipExtractor.exe (file missing)
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Administrator\Plocha\PartyPoker.lnk (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Administrator\Plocha\PartyPoker.lnk (file missing)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://D:\BitComet\tools\BitCometBHO_1.3.3.2.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: cryptnet32 - cryptnet32.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Stavová služba ASP.NET (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: .NET Runtime Optimization Service v2.0.50727_X86 (clr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (file missing)
O23 - Service: Windows Presentation Foundation Font Cache 3.0.0.0 (FontCache3.0.0.0) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Služba Windows CardSpace (idsvc) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe

--
End of file - 10669 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-1214440339-839522115-500Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-1214440339-839522115-500UA.job
C:\WINDOWS\tasks\WGASetup.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-30 75232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-12-12 194432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - D:\BitComet\tools\BitCometBHO_1.3.3.2.dll [2009-03-02 636216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-10-18 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
TBSB09850 Class - C:\Program Files\ChatZum Toolbar\tbunsk9C.tmp\tbcore3.dll [2012-08-29 2665984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F}
{37D48D9C-3F7E-412F-B5BF-611BE7CCFCA1} - ChatZum Toolbar - C:\Program Files\ChatZum Toolbar\tbunsk9C.tmp\tbcore3.dll [2012-08-29 2665984]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-02-25 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet32]
cryptnet32.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
C:\Program Files\Stardock\Object Desktop\ThemeManager\fastload.dll [2001-12-20 24576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\BitComet\BitComet.exe"="D:\BitComet\BitComet.exe:*:Enabled:BitComet.exe"
"D:\nhl 08\nhl2008.exe"="D:\nhl 08\nhl2008.exe:*:Enabled:nhl2008"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Program Files\Garena\Garena.exe"="C:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"D:\Warcraft III - funkční\Warcraft III.exe"="D:\Warcraft III - funkční\Warcraft III.exe:*:Enabled:Warcraft III"
"E:\Soldat\Soldat.exe"="E:\Soldat\Soldat.exe:*:Enabled:Soldat"
"H:\setup.exe"="H:\setup.exe:*:Enabled:setup.exe"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
"D:\Garena Plus\Room\garena_room.exe"="D:\Garena Plus\Room\garena_room.exe:*:Enabled:Garena"
"D:\nwn2\nwn2main.exe"="D:\nwn2\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main"
"D:\nwn2\nwn2main_amdxp.exe"="D:\nwn2\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD"
"D:\nwn2\nwupdate.exe"="D:\nwn2\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater"
"D:\nwn2\nwn2server.exe"="D:\nwn2\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.xvid"=xvidvfw.dll
"VIDC.FPS1"=frapsvid.dll
"msacm.lhacm"=lhacm.acm
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll
"vidc.mjpg"=bdmjpeg.dll
"vidc.mpeg"=bdmpegv.dll
"msacm.bdmpeg"=bdmpega.acm

======List of files/folders created in the last 3 months======

2012-09-19 21:00:57 ----DC---- C:\rsit
2012-09-19 21:00:57 ----D---- C:\Program Files\trend micro
2012-09-15 16:22:51 ----A---- C:\WINDOWS\system32\TURegOpt.exe
2012-09-15 16:22:26 ----D---- C:\Program Files\TuneUp Utilities 2012
2012-09-15 16:01:41 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\Toolbar4
2012-09-15 16:00:51 ----D---- C:\Program Files\ChatZum Toolbar
2012-09-15 16:00:37 ----SHD---- C:\Documents and Settings\All Users\Data aplikací\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2012-09-06 13:47:59 ----D---- C:\Documents and Settings\All Users\Data aplikací\McAfee Security Scan
2012-09-06 13:47:57 ----D---- C:\Program Files\McAfee Security Scan
2012-09-06 03:06:48 ----D---- C:\Program Files\Common Files\Skype
2012-09-06 03:06:46 ----RD---- C:\Program Files\Skype
2012-09-01 00:04:14 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\GarenaPlus
2012-09-01 00:03:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\GarenaMessenger
2012-08-30 20:09:37 ----DC---- C:\Downloads
2012-08-30 01:15:30 ----AC---- C:\chatzum_nt.exe
2012-08-21 04:49:12 ----SHDC---- C:\Config.Msi
2012-08-16 21:17:32 ----D---- C:\Program Files\Ventrilo
2012-08-16 21:17:21 ----A---- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2012-08-16 21:17:08 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2012-08-16 04:01:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2731847$
2012-08-14 16:48:43 ----D---- C:\Program Files\CCleaner
2012-08-13 03:23:00 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\Party
2012-08-08 20:21:22 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\Apple Computer
2012-08-08 20:15:47 ----D---- C:\Program Files\QuickTime
2012-08-08 20:15:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2012-08-08 20:14:56 ----D---- C:\Program Files\Common Files\Apple
2012-08-08 20:13:39 ----D---- C:\Program Files\Apple Software Update
2012-08-08 20:13:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple
2012-08-06 22:53:16 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\runic games
2012-08-05 03:32:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2718523$
2012-06-29 13:26:44 ----AC---- C:\user.js
2012-06-29 13:26:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Tarma Installer

======List of files/folders modified in the last 3 months======

2012-09-19 21:00:57 ----RD---- C:\Program Files
2012-09-19 21:00:49 ----D---- C:\WINDOWS\Prefetch
2012-09-19 20:48:45 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2012-09-19 20:20:42 ----D---- C:\WINDOWS\Temp
2012-09-19 20:20:42 ----D---- C:\WINDOWS\system32\CatRoot2
2012-09-19 07:45:35 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-09-19 06:59:45 ----SHD---- C:\WINDOWS\Installer
2012-09-15 18:36:41 ----D---- C:\WINDOWS\SoftwareDistribution
2012-09-15 16:53:26 ----D---- C:\WINDOWS
2012-09-15 16:52:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2012-09-15 16:52:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2012-09-15 16:52:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2012-09-15 16:52:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2012-09-15 16:52:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2412687$
2012-09-15 16:52:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2479628$
2012-09-15 16:52:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2012-09-15 16:52:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2506223$
2012-09-15 16:52:22 ----HDC---- C:\WINDOWS\$NtUninstallKB2524375$
2012-09-15 16:52:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2555917$
2012-09-15 16:52:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2544521$
2012-09-15 16:52:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2567053$
2012-09-15 16:52:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$
2012-09-15 16:52:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2641653$
2012-09-15 16:52:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2639417$
2012-09-15 16:52:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2646524$
2012-09-15 16:52:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2660465$
2012-09-15 16:52:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2659262$
2012-09-15 16:52:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2686509$
2012-09-15 16:52:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2709162$
2012-09-15 16:52:06 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2012-09-15 16:52:06 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2012-09-15 16:52:03 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2012-09-15 16:52:03 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2012-09-15 16:52:02 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2012-09-15 16:52:01 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2012-09-15 16:52:01 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2012-09-15 16:52:01 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2012-09-15 16:52:00 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2012-09-15 16:52:00 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2012-09-15 16:51:59 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2012-09-15 16:51:59 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2012-09-15 16:51:58 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2012-09-15 16:51:57 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2012-09-15 16:51:56 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2012-09-15 16:51:56 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2012-09-15 16:51:55 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2012-09-15 16:51:54 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2012-09-15 16:51:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2012-09-15 16:51:49 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9$
2012-09-15 16:51:49 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2012-09-15 16:51:47 ----HDC---- C:\WINDOWS\$NtUninstallKB981349$
2012-09-15 16:51:47 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2012-09-15 16:51:46 ----HDC---- C:\WINDOWS\$NtUninstallXPSEPSCLP$
2012-09-15 16:51:46 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2012-09-15 16:51:46 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2012-09-15 16:48:25 ----SD---- C:\WINDOWS\Tasks
2012-09-15 16:22:51 ----D---- C:\WINDOWS\system32
2012-09-15 16:22:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2012-09-15 16:22:37 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\TuneUp Software
2012-09-14 22:37:26 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\Hamachi
2012-09-14 21:57:18 ----D---- C:\Program Files\OpenOffice.org 2.1
2012-09-14 21:31:16 ----D---- C:\WINDOWS\Debug
2012-09-14 21:31:15 ----D---- C:\WINDOWS\Minidump
2012-09-13 08:41:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2012-09-13 08:38:20 ----HD---- C:\WINDOWS\inf
2012-09-13 08:38:01 ----HD---- C:\WINDOWS\$hf_mig$
2012-09-13 08:35:31 ----A---- C:\WINDOWS\system32\MRT.exe
2012-09-08 23:11:50 ----HD---- C:\Program Files\InstallShield Installation Information
2012-09-06 13:48:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2012-09-06 13:47:54 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2012-09-06 03:06:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2012-09-06 03:06:48 ----D---- C:\Program Files\Common Files
2012-09-05 19:44:09 ----AC---- C:\WINDOWS\system32\CmdLineExt.dll
2012-09-03 17:32:49 ----D---- C:\WINDOWS\system32\DirectX
2012-09-02 11:58:48 ----A---- C:\WINDOWS\NeroDigital.ini
2012-09-01 19:31:58 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Mozilla
2012-09-01 05:04:54 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-08-30 12:50:33 ----D---- C:\Program Files\raidcall
2012-08-25 21:15:22 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\Mumble
2012-08-16 21:18:07 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Ventrilo
2012-08-16 03:15:12 ----D---- C:\WINDOWS\system32\drivers
2012-08-14 16:53:44 ----A---- C:\WINDOWS\wininit.ini
2012-08-14 16:53:27 ----D---- C:\WINDOWS\WinSxS
2012-08-14 16:33:08 ----SHD---- C:\System Volume Information
2012-08-14 16:33:08 ----D---- C:\WINDOWS\system32\Restore
2012-08-14 16:32:35 ----D---- C:\WINDOWS\SxsCaPendDel
2012-08-14 16:23:15 ----D---- C:\Program Files\Mv2Player
2012-08-14 16:22:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\SweetIM
2012-08-14 16:20:57 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-08-14 16:18:43 ----D---- C:\Program Files\TuneUp Utilities 2009
2012-08-14 16:16:00 ----RSD---- C:\WINDOWS\Fonts
2012-08-14 16:09:27 ----D---- C:\WINDOWS\Config
2012-08-05 03:28:55 ----A---- C:\WINDOWS\win.ini
2012-08-05 03:28:51 ----D---- C:\Program Files\Common Files\System
2012-08-04 14:42:16 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\RaidCall
2012-07-12 00:00:20 ----A---- C:\WINDOWS\system32\mshtml.dll
2012-07-06 15:58:55 ----A---- C:\WINDOWS\system32\netapi32.dll
2012-07-06 15:58:55 ----A---- C:\WINDOWS\system32\browser.dll
2012-06-29 13:26:18 ----D---- C:\Program Files\1ClickDownload
2012-06-28 23:33:24 ----A---- C:\WINDOWS\system32\wininet.dll
2012-06-28 23:33:24 ----A---- C:\WINDOWS\system32\urlmon.dll
2012-06-28 23:33:24 ----A---- C:\WINDOWS\system32\url.dll
2012-06-28 23:33:24 ----A---- C:\WINDOWS\system32\shdocvw.dll
2012-06-28 23:33:23 ----A---- C:\WINDOWS\system32\mstime.dll
2012-06-28 23:33:23 ----A---- C:\WINDOWS\system32\mshtmled.dll
2012-06-28 23:33:22 ----A---- C:\WINDOWS\system32\iepeers.dll
2012-06-28 23:33:22 ----A---- C:\WINDOWS\system32\ieencode.dll
2012-06-28 23:33:22 ----A---- C:\WINDOWS\system32\browseui.dll
2012-06-26 12:06:29 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\ICQ
2012-06-21 16:56:19 ----D---- C:\WINDOWS\Help

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nv_agp;NVIDIA nForce AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\nv_agp.sys [2004-04-02 21760]
R0 nvatabus;nvatabus; C:\WINDOWS\system32\DRIVERS\nvatabus.sys [2004-06-03 79360]
R0 nvp2p;NVIDIA PCI to PCI Bridge Filter; C:\WINDOWS\system32\DRIVERS\nvp2p.sys [2003-12-23 8576]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-06-10 45648]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2006-03-26 51200]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2006-03-13 6656]
R0 sfsync04;StarForce Protection Synchronization Driver (version 4.x); C:\WINDOWS\System32\drivers\sfsync04.sys [2006-03-24 50176]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2005-11-03 63488]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-07-11 721904]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-07-09 96104]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 SSHDRV76;SSHDRV76; \??\C:\WINDOWS\system32\drivers\SSHDRV76.sys []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-07-09 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-12-07 56816]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2007-04-25 4030144]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-02-26 3565568]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2011-12-17 25280]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-04-06 33536]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-04-06 12928]
R3 rtl8029;Realtek RTL8029(AS)-based PCI Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8029.SYS [2001-08-17 19017]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys []
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 aghj410j;aghj410j; C:\WINDOWS\system32\drivers\aghj410j.sys []
S3 amrzhfi9;amrzhfi9; C:\WINDOWS\system32\drivers\amrzhfi9.sys []
S3 GarenaPEngine;GarenaPEngine; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\RKI8F.tmp []
S3 GGSAFERDriver;GGSAFER Driver; \??\D:\Garena Plus\Room\safedrv.sys []
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2010-03-20 47360]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-08-06 185089]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-07-09 108289]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-02-25 602112]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-10-03 153376]
R2 StarWindServiceAE;StarWind AE Service; D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [2012-05-29 1528672]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-02-25 593920]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe /svc []
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S2 wmcmgc;Windows Management Configuration; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-06 250568]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe []
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe []
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe []
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe []
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe [2011-06-17 237008]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe []

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomalý pc + schovaná data?

#2 Příspěvek od Rudy »

Také zdravím!
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files\ChatZum Toolbar
D:\BitComet\tools\BitCometBHO_1.3.3.2.dll
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-1214440339-839522115-500Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-1214440339-839522115-500UA.job

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

teddys
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 19 zář 2012 20:02

Re: Pomalý pc + schovaná data?

#3 Příspěvek od teddys »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Administrator at 2012-09-19 21:53:39
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 6 GB (22%) free of 25 GB
Total RAM: 1535 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:53:54, on 19.9.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Stardock\Object Desktop\ThemeManager\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Dokumenty\Downloads\RSIT (1).exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.chatzum.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.chatzum.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\ChatZum Toolbar\tbunsk9C.tmp\tbhelper.dll (file missing)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://D:\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - res://D:\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://D:\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (file missing)
O9 - Extra button: Download with YouTube Clip Extractor - {4adf5b46-bb68-4558-997e-3b68315a3930} - C:\Program Files\YouTube Clip Extractor\ClipExtractor.exe (file missing)
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Administrator\Plocha\PartyPoker.lnk (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Administrator\Plocha\PartyPoker.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: cryptnet32 - cryptnet32.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Stavová služba ASP.NET (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: .NET Runtime Optimization Service v2.0.50727_X86 (clr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (file missing)
O23 - Service: Windows Presentation Foundation Font Cache 3.0.0.0 (FontCache3.0.0.0) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Služba Windows CardSpace (idsvc) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe

--
End of file - 9703 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\WGASetup.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-30 75232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-12-12 194432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-10-18 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Google Update"=C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2012-09-01 116648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-02-25 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet32]
cryptnet32.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
C:\Program Files\Stardock\Object Desktop\ThemeManager\fastload.dll [2001-12-20 24576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\BitComet\BitComet.exe"="D:\BitComet\BitComet.exe:*:Enabled:BitComet.exe"
"D:\nhl 08\nhl2008.exe"="D:\nhl 08\nhl2008.exe:*:Enabled:nhl2008"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Program Files\Garena\Garena.exe"="C:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"D:\Warcraft III - funkční\Warcraft III.exe"="D:\Warcraft III - funkční\Warcraft III.exe:*:Enabled:Warcraft III"
"E:\Soldat\Soldat.exe"="E:\Soldat\Soldat.exe:*:Enabled:Soldat"
"H:\setup.exe"="H:\setup.exe:*:Enabled:setup.exe"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
"D:\Garena Plus\Room\garena_room.exe"="D:\Garena Plus\Room\garena_room.exe:*:Enabled:Garena"
"D:\nwn2\nwn2main.exe"="D:\nwn2\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main"
"D:\nwn2\nwn2main_amdxp.exe"="D:\nwn2\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD"
"D:\nwn2\nwupdate.exe"="D:\nwn2\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater"
"D:\nwn2\nwn2server.exe"="D:\nwn2\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.xvid"=xvidvfw.dll
"VIDC.FPS1"=frapsvid.dll
"msacm.lhacm"=lhacm.acm
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll
"vidc.mjpg"=bdmjpeg.dll
"vidc.mpeg"=bdmpegv.dll
"msacm.bdmpeg"=bdmpega.acm

======List of files/folders created in the last 3 months======

2012-09-19 21:47:01 ----DC---- C:\_OTM
2012-09-19 21:00:57 ----DC---- C:\rsit
2012-09-19 21:00:57 ----D---- C:\Program Files\trend micro
2012-09-15 16:22:51 ----A---- C:\WINDOWS\system32\TURegOpt.exe
2012-09-15 16:22:26 ----D---- C:\Program Files\TuneUp Utilities 2012
2012-09-15 16:01:41 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\Toolbar4
2012-09-15 16:00:37 ----SHD---- C:\Documents and Settings\All Users\Data aplikací\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2012-09-06 13:47:59 ----D---- C:\Documents and Settings\All Users\Data aplikací\McAfee Security Scan
2012-09-06 13:47:57 ----D---- C:\Program Files\McAfee Security Scan
2012-09-06 03:06:48 ----D---- C:\Program Files\Common Files\Skype
2012-09-06 03:06:46 ----RD---- C:\Program Files\Skype
2012-09-01 00:04:14 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\GarenaPlus
2012-09-01 00:03:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\GarenaMessenger
2012-08-30 20:09:37 ----DC---- C:\Downloads
2012-08-30 01:15:30 ----AC---- C:\chatzum_nt.exe
2012-08-21 04:49:12 ----SHDC---- C:\Config.Msi
2012-08-16 21:17:32 ----D---- C:\Program Files\Ventrilo
2012-08-16 21:17:21 ----A---- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2012-08-16 21:17:08 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2012-08-16 04:01:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2731847$
2012-08-14 16:48:43 ----D---- C:\Program Files\CCleaner
2012-08-13 03:23:00 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\Party
2012-08-08 20:21:22 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\Apple Computer
2012-08-08 20:15:47 ----D---- C:\Program Files\QuickTime
2012-08-08 20:15:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2012-08-08 20:14:56 ----D---- C:\Program Files\Common Files\Apple
2012-08-08 20:13:39 ----D---- C:\Program Files\Apple Software Update
2012-08-08 20:13:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple
2012-08-06 22:53:16 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\runic games
2012-08-05 03:32:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2718523$
2012-06-29 13:26:44 ----AC---- C:\user.js
2012-06-29 13:26:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Tarma Installer

======List of files/folders modified in the last 3 months======

2012-09-19 21:53:44 ----D---- C:\WINDOWS\Prefetch
2012-09-19 21:52:21 ----D---- C:\WINDOWS\Temp
2012-09-19 21:48:55 ----D---- C:\WINDOWS\system32\CatRoot2
2012-09-19 21:48:51 ----D---- C:\WINDOWS
2012-09-19 21:47:34 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-09-19 21:47:03 ----SD---- C:\WINDOWS\Tasks
2012-09-19 21:47:03 ----RD---- C:\Program Files
2012-09-19 21:26:25 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2012-09-19 21:19:24 ----SHD---- C:\WINDOWS\Installer
2012-09-19 21:11:05 ----A---- C:\WINDOWS\NeroDigital.ini
2012-09-15 18:36:41 ----D---- C:\WINDOWS\SoftwareDistribution
2012-09-15 16:52:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2012-09-15 16:52:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2012-09-15 16:52:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2012-09-15 16:52:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2012-09-15 16:52:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2412687$
2012-09-15 16:52:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2479628$
2012-09-15 16:52:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2012-09-15 16:52:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2506223$
2012-09-15 16:52:22 ----HDC---- C:\WINDOWS\$NtUninstallKB2524375$
2012-09-15 16:52:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2555917$
2012-09-15 16:52:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2544521$
2012-09-15 16:52:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2567053$
2012-09-15 16:52:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$
2012-09-15 16:52:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2641653$
2012-09-15 16:52:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2639417$
2012-09-15 16:52:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2646524$
2012-09-15 16:52:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2660465$
2012-09-15 16:52:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2659262$
2012-09-15 16:52:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2686509$
2012-09-15 16:52:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2709162$
2012-09-15 16:52:06 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2012-09-15 16:52:06 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2012-09-15 16:52:03 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2012-09-15 16:52:03 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2012-09-15 16:52:02 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2012-09-15 16:52:01 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2012-09-15 16:52:01 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2012-09-15 16:52:01 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2012-09-15 16:52:00 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2012-09-15 16:52:00 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2012-09-15 16:51:59 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2012-09-15 16:51:59 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2012-09-15 16:51:58 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2012-09-15 16:51:57 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2012-09-15 16:51:56 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2012-09-15 16:51:56 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2012-09-15 16:51:55 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2012-09-15 16:51:54 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2012-09-15 16:51:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2012-09-15 16:51:49 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9$
2012-09-15 16:51:49 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2012-09-15 16:51:47 ----HDC---- C:\WINDOWS\$NtUninstallKB981349$
2012-09-15 16:51:47 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2012-09-15 16:51:46 ----HDC---- C:\WINDOWS\$NtUninstallXPSEPSCLP$
2012-09-15 16:51:46 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2012-09-15 16:51:46 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2012-09-15 16:22:51 ----D---- C:\WINDOWS\system32
2012-09-15 16:22:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2012-09-15 16:22:37 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\TuneUp Software
2012-09-14 22:37:26 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\Hamachi
2012-09-14 21:57:18 ----D---- C:\Program Files\OpenOffice.org 2.1
2012-09-14 21:31:16 ----D---- C:\WINDOWS\Debug
2012-09-14 21:31:15 ----D---- C:\WINDOWS\Minidump
2012-09-13 08:41:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2012-09-13 08:38:20 ----HD---- C:\WINDOWS\inf
2012-09-13 08:38:01 ----HD---- C:\WINDOWS\$hf_mig$
2012-09-13 08:35:31 ----A---- C:\WINDOWS\system32\MRT.exe
2012-09-08 23:11:50 ----HD---- C:\Program Files\InstallShield Installation Information
2012-09-06 13:48:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2012-09-06 13:47:54 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2012-09-06 03:06:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2012-09-06 03:06:48 ----D---- C:\Program Files\Common Files
2012-09-05 19:44:09 ----AC---- C:\WINDOWS\system32\CmdLineExt.dll
2012-09-03 17:32:49 ----D---- C:\WINDOWS\system32\DirectX
2012-09-01 19:31:58 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Mozilla
2012-09-01 05:04:54 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-08-30 12:50:33 ----D---- C:\Program Files\raidcall
2012-08-25 21:15:22 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\Mumble
2012-08-16 21:18:07 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Ventrilo
2012-08-16 03:15:12 ----D---- C:\WINDOWS\system32\drivers
2012-08-14 16:53:44 ----A---- C:\WINDOWS\wininit.ini
2012-08-14 16:53:27 ----D---- C:\WINDOWS\WinSxS
2012-08-14 16:33:08 ----SHD---- C:\System Volume Information
2012-08-14 16:33:08 ----D---- C:\WINDOWS\system32\Restore
2012-08-14 16:32:35 ----D---- C:\WINDOWS\SxsCaPendDel
2012-08-14 16:23:15 ----D---- C:\Program Files\Mv2Player
2012-08-14 16:22:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\SweetIM
2012-08-14 16:20:57 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-08-14 16:18:43 ----D---- C:\Program Files\TuneUp Utilities 2009
2012-08-14 16:16:00 ----RSD---- C:\WINDOWS\Fonts
2012-08-14 16:09:27 ----D---- C:\WINDOWS\Config
2012-08-05 03:28:55 ----A---- C:\WINDOWS\win.ini
2012-08-05 03:28:51 ----D---- C:\Program Files\Common Files\System
2012-08-04 14:42:16 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\RaidCall
2012-07-12 00:00:20 ----A---- C:\WINDOWS\system32\mshtml.dll
2012-07-06 15:58:55 ----A---- C:\WINDOWS\system32\netapi32.dll
2012-07-06 15:58:55 ----A---- C:\WINDOWS\system32\browser.dll
2012-06-29 13:26:18 ----D---- C:\Program Files\1ClickDownload
2012-06-28 23:33:24 ----A---- C:\WINDOWS\system32\wininet.dll
2012-06-28 23:33:24 ----A---- C:\WINDOWS\system32\urlmon.dll
2012-06-28 23:33:24 ----A---- C:\WINDOWS\system32\url.dll
2012-06-28 23:33:24 ----A---- C:\WINDOWS\system32\shdocvw.dll
2012-06-28 23:33:23 ----A---- C:\WINDOWS\system32\mstime.dll
2012-06-28 23:33:23 ----A---- C:\WINDOWS\system32\mshtmled.dll
2012-06-28 23:33:22 ----A---- C:\WINDOWS\system32\iepeers.dll
2012-06-28 23:33:22 ----A---- C:\WINDOWS\system32\ieencode.dll
2012-06-28 23:33:22 ----A---- C:\WINDOWS\system32\browseui.dll
2012-06-26 12:06:29 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\ICQ
2012-06-21 16:56:19 ----D---- C:\WINDOWS\Help

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nv_agp;NVIDIA nForce AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\nv_agp.sys [2004-04-02 21760]
R0 nvatabus;nvatabus; C:\WINDOWS\system32\DRIVERS\nvatabus.sys [2004-06-03 79360]
R0 nvp2p;NVIDIA PCI to PCI Bridge Filter; C:\WINDOWS\system32\DRIVERS\nvp2p.sys [2003-12-23 8576]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-06-10 45648]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2006-03-26 51200]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2006-03-13 6656]
R0 sfsync04;StarForce Protection Synchronization Driver (version 4.x); C:\WINDOWS\System32\drivers\sfsync04.sys [2006-03-24 50176]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2005-11-03 63488]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-07-11 721904]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-07-09 96104]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 SSHDRV76;SSHDRV76; \??\C:\WINDOWS\system32\drivers\SSHDRV76.sys []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-07-09 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-12-07 56816]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2007-04-25 4030144]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-02-26 3565568]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2011-12-17 25280]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-04-06 33536]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-04-06 12928]
R3 rtl8029;Realtek RTL8029(AS)-based PCI Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8029.SYS [2001-08-17 19017]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys []
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 a6nmed6q;a6nmed6q; C:\WINDOWS\system32\drivers\a6nmed6q.sys []
S3 adutvlms;adutvlms; C:\WINDOWS\system32\drivers\adutvlms.sys []
S3 GarenaPEngine;GarenaPEngine; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\RKI8F.tmp []
S3 GGSAFERDriver;GGSAFER Driver; \??\D:\Garena Plus\Room\safedrv.sys []
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2010-03-20 47360]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-08-06 185089]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-07-09 108289]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-02-25 602112]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-10-03 153376]
R2 StarWindServiceAE;StarWind AE Service; D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [2012-05-29 1528672]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-02-25 593920]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe /svc []
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S2 wmcmgc;Windows Management Configuration; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-06 250568]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe []
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe []
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe []
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe []
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe [2011-06-17 237008]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe []

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomalý pc + schovaná data?

#4 Příspěvek od Rudy »

Dvouklikem na soubor C:\Program Files\trend micro\Administrator.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.chatzum.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.chatzum.com/
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\ChatZum Toolbar\tbunsk9C.tmp\tbhelper.dll (file missing)
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (file missing)
O9 - Extra button: Download with YouTube Clip Extractor - {4adf5b46-bb68-4558-997e-3b68315a3930} - C:\Program Files\YouTube Clip Extractor\ClipExtractor.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O20 - Winlogon Notify: cryptnet32 - cryptnet32.dll (file missing)
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

teddys
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 19 zář 2012 20:02

Re: Pomalý pc + schovaná data?

#5 Příspěvek od teddys »

Děkuju

mimochodem tohle je moc zajímavé :D
Obrázek


Logfile of random's system information tool 1.09 (written by random/random)
Run by Administrator at 2012-09-19 22:18:14
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 6 GB (22%) free of 25 GB
Total RAM: 1535 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:18:24, on 19.9.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Stardock\Object Desktop\ThemeManager\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Dokumenty\Downloads\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.chatzum.com/
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://D:\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - res://D:\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://D:\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Administrator\Plocha\PartyPoker.lnk (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Administrator\Plocha\PartyPoker.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Stavová služba ASP.NET (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: .NET Runtime Optimization Service v2.0.50727_X86 (clr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (file missing)
O23 - Service: Windows Presentation Foundation Font Cache 3.0.0.0 (FontCache3.0.0.0) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Služba Windows CardSpace (idsvc) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe

--
End of file - 8523 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\WGASetup.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-30 75232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-12-12 194432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-10-18 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Google Update"=C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2012-09-01 116648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-02-25 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
C:\Program Files\Stardock\Object Desktop\ThemeManager\fastload.dll [2001-12-20 24576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\BitComet\BitComet.exe"="D:\BitComet\BitComet.exe:*:Enabled:BitComet.exe"
"D:\nhl 08\nhl2008.exe"="D:\nhl 08\nhl2008.exe:*:Enabled:nhl2008"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Program Files\Garena\Garena.exe"="C:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"D:\Warcraft III - funkční\Warcraft III.exe"="D:\Warcraft III - funkční\Warcraft III.exe:*:Enabled:Warcraft III"
"E:\Soldat\Soldat.exe"="E:\Soldat\Soldat.exe:*:Enabled:Soldat"
"H:\setup.exe"="H:\setup.exe:*:Enabled:setup.exe"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
"D:\Garena Plus\Room\garena_room.exe"="D:\Garena Plus\Room\garena_room.exe:*:Enabled:Garena"
"D:\nwn2\nwn2main.exe"="D:\nwn2\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main"
"D:\nwn2\nwn2main_amdxp.exe"="D:\nwn2\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD"
"D:\nwn2\nwupdate.exe"="D:\nwn2\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater"
"D:\nwn2\nwn2server.exe"="D:\nwn2\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.xvid"=xvidvfw.dll
"VIDC.FPS1"=frapsvid.dll
"msacm.lhacm"=lhacm.acm
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll
"vidc.mjpg"=bdmjpeg.dll
"vidc.mpeg"=bdmpegv.dll
"msacm.bdmpeg"=bdmpega.acm

======List of files/folders created in the last 3 months======

2012-09-19 22:18:14 ----DC---- C:\rsit
2012-09-19 21:00:57 ----D---- C:\Program Files\trend micro
2012-09-15 16:22:51 ----A---- C:\WINDOWS\system32\TURegOpt.exe
2012-09-15 16:22:26 ----D---- C:\Program Files\TuneUp Utilities 2012
2012-09-15 16:01:41 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\Toolbar4
2012-09-15 16:00:37 ----SHD---- C:\Documents and Settings\All Users\Data aplikací\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2012-09-06 13:47:59 ----D---- C:\Documents and Settings\All Users\Data aplikací\McAfee Security Scan
2012-09-06 13:47:57 ----D---- C:\Program Files\McAfee Security Scan
2012-09-06 03:06:48 ----D---- C:\Program Files\Common Files\Skype
2012-09-06 03:06:46 ----RD---- C:\Program Files\Skype
2012-09-01 00:04:14 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\GarenaPlus
2012-09-01 00:03:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\GarenaMessenger
2012-08-30 20:09:37 ----DC---- C:\Downloads
2012-08-30 01:15:30 ----AC---- C:\chatzum_nt.exe
2012-08-21 04:49:12 ----SHDC---- C:\Config.Msi
2012-08-16 21:17:32 ----D---- C:\Program Files\Ventrilo
2012-08-16 21:17:21 ----A---- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2012-08-16 21:17:08 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2012-08-16 04:01:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2731847$
2012-08-14 16:48:43 ----D---- C:\Program Files\CCleaner
2012-08-13 03:23:00 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\Party
2012-08-08 20:21:22 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\Apple Computer
2012-08-08 20:15:47 ----D---- C:\Program Files\QuickTime
2012-08-08 20:15:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2012-08-08 20:14:56 ----D---- C:\Program Files\Common Files\Apple
2012-08-08 20:13:39 ----D---- C:\Program Files\Apple Software Update
2012-08-08 20:13:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple
2012-08-06 22:53:16 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\runic games
2012-08-05 03:32:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2718523$
2012-06-29 13:26:44 ----AC---- C:\user.js
2012-06-29 13:26:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Tarma Installer

======List of files/folders modified in the last 3 months======

2012-09-19 22:17:28 ----D---- C:\WINDOWS\Prefetch
2012-09-19 22:15:38 ----D---- C:\WINDOWS\Temp
2012-09-19 22:15:38 ----D---- C:\WINDOWS\system32\CatRoot2
2012-09-19 22:14:15 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-09-19 21:48:51 ----D---- C:\WINDOWS
2012-09-19 21:47:03 ----SD---- C:\WINDOWS\Tasks
2012-09-19 21:47:03 ----RD---- C:\Program Files
2012-09-19 21:26:25 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2012-09-19 21:19:24 ----SHD---- C:\WINDOWS\Installer
2012-09-19 21:11:05 ----A---- C:\WINDOWS\NeroDigital.ini
2012-09-15 18:36:41 ----D---- C:\WINDOWS\SoftwareDistribution
2012-09-15 16:52:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2012-09-15 16:52:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2012-09-15 16:52:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2012-09-15 16:52:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2012-09-15 16:52:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2412687$
2012-09-15 16:52:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2479628$
2012-09-15 16:52:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2012-09-15 16:52:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2506223$
2012-09-15 16:52:22 ----HDC---- C:\WINDOWS\$NtUninstallKB2524375$
2012-09-15 16:52:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2555917$
2012-09-15 16:52:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2544521$
2012-09-15 16:52:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2567053$
2012-09-15 16:52:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$
2012-09-15 16:52:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2641653$
2012-09-15 16:52:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2639417$
2012-09-15 16:52:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2646524$
2012-09-15 16:52:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2660465$
2012-09-15 16:52:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2659262$
2012-09-15 16:52:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2686509$
2012-09-15 16:52:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2709162$
2012-09-15 16:52:06 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2012-09-15 16:52:06 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2012-09-15 16:52:03 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2012-09-15 16:52:03 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2012-09-15 16:52:02 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2012-09-15 16:52:01 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2012-09-15 16:52:01 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2012-09-15 16:52:01 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2012-09-15 16:52:00 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2012-09-15 16:52:00 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2012-09-15 16:51:59 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2012-09-15 16:51:59 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2012-09-15 16:51:58 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2012-09-15 16:51:57 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2012-09-15 16:51:56 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2012-09-15 16:51:56 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2012-09-15 16:51:55 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2012-09-15 16:51:54 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2012-09-15 16:51:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2012-09-15 16:51:49 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9$
2012-09-15 16:51:49 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2012-09-15 16:51:47 ----HDC---- C:\WINDOWS\$NtUninstallKB981349$
2012-09-15 16:51:47 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2012-09-15 16:51:46 ----HDC---- C:\WINDOWS\$NtUninstallXPSEPSCLP$
2012-09-15 16:51:46 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2012-09-15 16:51:46 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2012-09-15 16:22:51 ----D---- C:\WINDOWS\system32
2012-09-15 16:22:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2012-09-15 16:22:37 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\TuneUp Software
2012-09-14 22:37:26 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\Hamachi
2012-09-14 21:57:18 ----D---- C:\Program Files\OpenOffice.org 2.1
2012-09-14 21:31:16 ----D---- C:\WINDOWS\Debug
2012-09-14 21:31:15 ----D---- C:\WINDOWS\Minidump
2012-09-13 08:41:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2012-09-13 08:38:20 ----HD---- C:\WINDOWS\inf
2012-09-13 08:38:01 ----HD---- C:\WINDOWS\$hf_mig$
2012-09-13 08:35:31 ----A---- C:\WINDOWS\system32\MRT.exe
2012-09-08 23:11:50 ----HD---- C:\Program Files\InstallShield Installation Information
2012-09-06 13:48:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2012-09-06 13:47:54 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2012-09-06 03:06:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2012-09-06 03:06:48 ----D---- C:\Program Files\Common Files
2012-09-05 19:44:09 ----AC---- C:\WINDOWS\system32\CmdLineExt.dll
2012-09-03 17:32:49 ----D---- C:\WINDOWS\system32\DirectX
2012-09-01 19:31:58 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Mozilla
2012-09-01 05:04:54 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-08-30 12:50:33 ----D---- C:\Program Files\raidcall
2012-08-25 21:15:22 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\Mumble
2012-08-16 21:18:07 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Ventrilo
2012-08-16 03:15:12 ----D---- C:\WINDOWS\system32\drivers
2012-08-14 16:53:44 ----A---- C:\WINDOWS\wininit.ini
2012-08-14 16:53:27 ----D---- C:\WINDOWS\WinSxS
2012-08-14 16:33:08 ----SHD---- C:\System Volume Information
2012-08-14 16:33:08 ----D---- C:\WINDOWS\system32\Restore
2012-08-14 16:32:35 ----D---- C:\WINDOWS\SxsCaPendDel
2012-08-14 16:23:15 ----D---- C:\Program Files\Mv2Player
2012-08-14 16:22:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\SweetIM
2012-08-14 16:20:57 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-08-14 16:18:43 ----D---- C:\Program Files\TuneUp Utilities 2009
2012-08-14 16:16:00 ----RSD---- C:\WINDOWS\Fonts
2012-08-14 16:09:27 ----D---- C:\WINDOWS\Config
2012-08-05 03:28:55 ----A---- C:\WINDOWS\win.ini
2012-08-05 03:28:51 ----D---- C:\Program Files\Common Files\System
2012-08-04 14:42:16 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\RaidCall
2012-07-12 00:00:20 ----A---- C:\WINDOWS\system32\mshtml.dll
2012-07-06 15:58:55 ----A---- C:\WINDOWS\system32\netapi32.dll
2012-07-06 15:58:55 ----A---- C:\WINDOWS\system32\browser.dll
2012-06-29 13:26:18 ----D---- C:\Program Files\1ClickDownload
2012-06-28 23:33:24 ----A---- C:\WINDOWS\system32\wininet.dll
2012-06-28 23:33:24 ----A---- C:\WINDOWS\system32\urlmon.dll
2012-06-28 23:33:24 ----A---- C:\WINDOWS\system32\url.dll
2012-06-28 23:33:24 ----A---- C:\WINDOWS\system32\shdocvw.dll
2012-06-28 23:33:23 ----A---- C:\WINDOWS\system32\mstime.dll
2012-06-28 23:33:23 ----A---- C:\WINDOWS\system32\mshtmled.dll
2012-06-28 23:33:22 ----A---- C:\WINDOWS\system32\iepeers.dll
2012-06-28 23:33:22 ----A---- C:\WINDOWS\system32\ieencode.dll
2012-06-28 23:33:22 ----A---- C:\WINDOWS\system32\browseui.dll
2012-06-26 12:06:29 ----DC---- C:\Documents and Settings\Administrator\Data aplikací\ICQ
2012-06-21 16:56:19 ----D---- C:\WINDOWS\Help

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nv_agp;NVIDIA nForce AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\nv_agp.sys [2004-04-02 21760]
R0 nvatabus;nvatabus; C:\WINDOWS\system32\DRIVERS\nvatabus.sys [2004-06-03 79360]
R0 nvp2p;NVIDIA PCI to PCI Bridge Filter; C:\WINDOWS\system32\DRIVERS\nvp2p.sys [2003-12-23 8576]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-06-10 45648]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2006-03-26 51200]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2006-03-13 6656]
R0 sfsync04;StarForce Protection Synchronization Driver (version 4.x); C:\WINDOWS\System32\drivers\sfsync04.sys [2006-03-24 50176]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2005-11-03 63488]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-07-11 721904]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-07-09 96104]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 SSHDRV76;SSHDRV76; \??\C:\WINDOWS\system32\drivers\SSHDRV76.sys []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-07-09 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-12-07 56816]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2007-04-25 4030144]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-02-26 3565568]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2011-12-17 25280]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-04-06 33536]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-04-06 12928]
R3 rtl8029;Realtek RTL8029(AS)-based PCI Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8029.SYS [2001-08-17 19017]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys []
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 a8napyax;a8napyax; C:\WINDOWS\system32\drivers\a8napyax.sys []
S3 alkid994;alkid994; C:\WINDOWS\system32\drivers\alkid994.sys []
S3 GarenaPEngine;GarenaPEngine; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\RKI8F.tmp []
S3 GGSAFERDriver;GGSAFER Driver; \??\D:\Garena Plus\Room\safedrv.sys []
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2010-03-20 47360]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-08-06 185089]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-07-09 108289]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-02-25 602112]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-10-03 153376]
R2 StarWindServiceAE;StarWind AE Service; D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [2012-05-29 1528672]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-02-25 593920]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe /svc []
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S2 wmcmgc;Windows Management Configuration; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-06 250568]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe []
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe []
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe []
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe []
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe [2011-06-17 237008]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe []

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomalý pc + schovaná data?

#6 Příspěvek od Rudy »

Log již vypadá čistý.

V těch vlastnostech je uvedeno, kolik máte v daném adresáři souborů, složek a je veliký. Dále, kdy byl vytvořen a jaké má atributy. Co je na tom zvláštního? Velikost? Systémový adresář se neustále zvětšuje s tím, jak se instalují ovladače, aktualizace a některé programy.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

teddys
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 19 zář 2012 20:02

Re: Pomalý pc + schovaná data?

#7 Příspěvek od teddys »

velikost se mi nějak nezdá no ...
ale když to je jak říkáte :)


každopádně moc děkuju ;)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomalý pc + schovaná data?

#8 Příspěvek od Rudy »

Na to, že systém byl instalová před více, než 3 roky, bych tu velikost považoval za možnou. Navíc volného místa tím vyčištěním přibylo 20% (4GB).
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

teddys
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 19 zář 2012 20:02

Re: Pomalý pc + schovaná data?

#9 Příspěvek od teddys »

teddys píše: každopádně moc děkuju ;)
můžem lock :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomalý pc + schovaná data?

#10 Příspěvek od Rudy »

Nemáte zač a zamykám!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno