

Problém - PC třeba týden bootuje naprosto bez problémů a pak přijde den, kdy téměř nejde zapnout. Po zapnutí se to dostane do stavu, kdy dole běhá ta čára při startu Vist, zastaví se harddisk a tím to končí. PC je nutné několikrát resetovat, než normálně naběhne. Pak je zas třeba několik dní klid a tak se to pořád opakuje. Tu hru jsem samozřejmě už dávno odinstaloval, ale nepomohlo to. Díky za radu a bude to zřejmě na dlouhé lokte, na to PC se dostanu jen o víkendu...
Logfile of random's system information tool 1.08 (written by random/random)
Run by Jana at 2010-10-31 16:32:58
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 276 GB (73%) free of 376 GB
Total RAM: 2814 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:33:06, on 31.10.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ICQ6.5\ICQ.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10i_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\totalcmd\TOTALCMD.EXE
C:\Program Files\trend micro\Jana.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... pire_m3201
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... pire_m3201
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACA ... pire_m3201
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O4 - HKLM\..\Run: [PCMMediaSharing] "C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe"
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [adiras] C:\Windows\adirasx64.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
O4 - HKCU\..\Run: [ICQ] "C:\PROGRA~2\ICQ6.5\ICQ.exe" silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6.5\ICQ.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F27B76E2-1AEB-4B72-8887-B778E9FC3363}: NameServer = 160.218.161.54 194.228.41.65
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9380 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
wininit.exe
"C:\Program Files (x86)\AVG\AVG9\avgchsva.exe"
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
"C:\Program Files (x86)\AVG\AVG9\avgrsa.exe"
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
/pipeName=a2eb14b6-eda7-4a1a-b04e-7f3f790c81c7 /coreSdkOptions=30 /logConfFile="C:\ProgramData\avg9\temp\18a68c5c-d84f-4670-883f-4cfade1f8312-2b8-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG9\" /tempPath="C:\ProgramData\avg9\temp\"
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
Ati2evxx.exe -Client
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {0150F1A3-05A1-4F88-9F5C-03CDD0CD97A9}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {1F06DEA5-2C8E-45AB-95D1-8D12292D67C4}
"C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe"
"C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe"
"C:\Program Files\Acer\Empowering Technology\SysMonitor.exe"
"C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe" boot
"C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe"
"C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSLoader.exe"
"C:\Windows\RAVCpl64.exe"
"C:\Program Files\Acer\Empowering Technology\Service\ETService.exe"
"C:\Program Files (x86)\ICQ6.5\ICQ.exe" silent
"C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\AVG\AVG9\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG9\avgtray.exe"
"c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe"
"C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-8c21fbe8-57dd-4d18-a226-8e4c13c1e7d4 -SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-b63b8a35-58eb-4098-a460-32682ad52682 -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-219fc7a1-f355-4641-8db8-92fa2ce4e152 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:80452afb-ef74-4282-90f7-9c968865287a
"C:\Program Files (x86)\AVG\AVG9\avgemc.exe"
/pipeName=3bceb704-31dd-4067-a00d-a89da0616e4d /coreSdkOptions=0 /binaryPath="C:\Program Files (x86)\AVG\AVG9\"
"C:\Program Files (x86)\SAGEM\SAGEM F@st 800-840\dslmon.exe"
"C:\Program Files (x86)\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:4600 CREDAT:71937
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10i_ActiveX.exe -Embedding
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_s-1-5-21-426290378-1259937214-976701041-10004_ Global\UsGthrCtrlFltPipeMssGthrPipe_s-1-5-21-426290378-1259937214-976701041-10004 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:4600 CREDAT:6410
"C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:4600 CREDAT:203009
"C:\Windows\system32\SearchFilterHost.exe" 0 640 644 652 65536 648
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\totalcmd\TOTALCMD.EXE"
"C:\Users\Jana\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll [2010-10-26 2335584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
ShowBarObj Class - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\ActiveToolBand.dll [2008-07-29 378416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-08-04 1586472]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG9\avgssie.dll [2010-10-26 1623392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-11-18 408952]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll [2008-07-29 181296]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-07-29 142896]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1584184]
"Acer Empowering Technology Monitor"=C:\Program Files\Acer\Empowering Technology\SysMonitor.exe [2008-10-01 319488]
"EmpoweringTechnology"=C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe [2008-10-01 323584]
"eDataSecurity Loader"=C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe [2008-07-29 561200]
"RtHDVCpl"=C:\Windows\RAVCpl64.exe [2008-05-20 6296064]
"Skytel"=C:\Windows\Skytel.exe [2007-11-20 1826816]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ProductReg"=C:\Program Files\Acer\WR_PopUp\ProductReg.exe [2008-11-17 135168]
"ICQ"=C:\PROGRA~2\ICQ6.5\ICQ.exe [2009-11-16 172792]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"PCMMediaSharing"=C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe [2008-05-20 204908]
"StartCCC"=c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-08-29 61440]
"eRecoveryService"= []
"adiras"=C:\Windows\adirasx64.exe [2007-02-13 253008]
"AVG9_TRAY"=C:\PROGRA~2\AVG\AVG9\avgtray.exe [2010-10-04 2067808]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Microsoft Office.lnk - C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="avgrssta.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"BindDirectlyToPropertySetStorage"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-10-31 16:32:59 ----D---- C:\Program Files\trend micro
2010-10-31 16:32:58 ----D---- C:\rsit
2010-10-27 16:44:17 ----A---- C:\Windows\SYSWOW64\gameux.dll
2010-10-27 16:44:17 ----A---- C:\Windows\system32\gameux.dll
2010-10-27 16:44:16 ----A---- C:\Windows\SYSWOW64\GameUXLegacyGDFs.dll
2010-10-27 16:44:16 ----A---- C:\Windows\SYSWOW64\Apphlpdm.dll
2010-10-27 16:44:16 ----A---- C:\Windows\system32\Apphlpdm.dll
2010-10-27 16:44:15 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2010-10-26 16:20:09 ----D---- C:\Program Files (x86)\Microsoft.NET
2010-10-14 21:44:56 ----A---- C:\Windows\system32\ole32.dll
2010-10-14 21:44:55 ----A---- C:\Windows\SYSWOW64\ole32.dll
2010-10-14 21:44:53 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2010-10-14 21:44:53 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2010-10-14 21:44:51 ----A---- C:\Windows\SYSWOW64\t2embed.dll
2010-10-14 21:44:51 ----A---- C:\Windows\system32\t2embed.dll
2010-10-14 21:44:49 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2010-10-14 21:44:49 ----A---- C:\Windows\system32\comctl32.dll
2010-10-14 21:44:47 ----A---- C:\Windows\SYSWOW64\msshsq.dll
2010-10-14 21:44:47 ----A---- C:\Windows\system32\msshsq.dll
2010-10-14 21:44:45 ----A---- C:\Windows\system32\win32k.sys
2010-10-14 21:44:42 ----A---- C:\Windows\system32\mshtml.dll
2010-10-14 21:44:41 ----A---- C:\Windows\system32\ieframe.dll
2010-10-14 21:44:40 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2010-10-14 21:44:39 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2010-10-14 21:44:39 ----A---- C:\Windows\system32\urlmon.dll
2010-10-14 21:44:39 ----A---- C:\Windows\system32\msfeeds.dll
2010-10-14 21:44:38 ----A---- C:\Windows\SYSWOW64\wininet.dll
2010-10-14 21:44:38 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2010-10-14 21:44:38 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2010-10-14 21:44:38 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2010-10-14 21:44:38 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2010-10-14 21:44:38 ----A---- C:\Windows\system32\wininet.dll
2010-10-14 21:44:38 ----A---- C:\Windows\system32\mshtmled.dll
2010-10-14 21:44:38 ----A---- C:\Windows\system32\licmgr10.dll
2010-10-14 21:44:38 ----A---- C:\Windows\system32\iedkcs32.dll
2010-10-14 21:44:37 ----A---- C:\Windows\system32\occache.dll
2010-10-14 21:44:37 ----A---- C:\Windows\system32\mstime.dll
2010-10-14 21:44:37 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-10-14 21:44:37 ----A---- C:\Windows\system32\jsproxy.dll
2010-10-14 21:44:37 ----A---- C:\Windows\system32\ieui.dll
2010-10-14 21:44:37 ----A---- C:\Windows\system32\iesetup.dll
2010-10-14 21:44:37 ----A---- C:\Windows\system32\iertutil.dll
2010-10-14 21:44:37 ----A---- C:\Windows\system32\iernonce.dll
2010-10-14 21:44:37 ----A---- C:\Windows\system32\iepeers.dll
2010-10-14 21:44:36 ----A---- C:\Windows\SYSWOW64\occache.dll
2010-10-14 21:44:36 ----A---- C:\Windows\SYSWOW64\mstime.dll
2010-10-14 21:44:36 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2010-10-14 21:44:36 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2010-10-14 21:44:36 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2010-10-14 21:44:36 ----A---- C:\Windows\SYSWOW64\ieui.dll
2010-10-14 21:44:36 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2010-10-14 21:44:36 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2010-10-14 21:44:36 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2010-10-14 21:44:36 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2010-10-14 21:44:36 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2010-10-14 21:44:36 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2010-10-14 21:44:36 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2010-10-14 21:44:36 ----A---- C:\Windows\system32\ieUnatt.exe
2010-10-14 21:44:36 ----A---- C:\Windows\system32\iesysprep.dll
2010-10-14 21:44:36 ----A---- C:\Windows\system32\ie4uinit.exe
2010-10-14 21:44:35 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2010-10-14 21:44:35 ----A---- C:\Windows\system32\msfeedssync.exe
2010-10-14 21:44:28 ----A---- C:\Windows\system32\wmp.dll
2010-10-14 21:44:26 ----A---- C:\Windows\SYSWOW64\wmp.dll
2010-10-14 21:44:21 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2010-10-14 21:44:21 ----A---- C:\Windows\system32\wmploc.DLL
2010-10-14 21:44:13 ----A---- C:\Windows\system32\sscore.dll
2010-10-14 21:44:13 ----A---- C:\Windows\system32\srvsvc.dll
2010-10-14 21:44:13 ----A---- C:\Windows\system32\drivers\srvnet.sys
2010-10-14 21:44:13 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-10-14 21:44:13 ----A---- C:\Windows\system32\drivers\srv.sys
2010-10-14 21:44:12 ----A---- C:\Windows\SYSWOW64\sscore.dll
2010-10-14 21:44:12 ----A---- C:\Windows\SYSWOW64\netevent.dll
2010-10-14 21:44:12 ----A---- C:\Windows\system32\netevent.dll
2010-10-14 21:44:09 ----A---- C:\Windows\SYSWOW64\schannel.dll
2010-10-14 21:44:09 ----A---- C:\Windows\system32\schannel.dll
2010-10-14 21:44:08 ----A---- C:\Windows\SYSWOW64\wmpmde.dll
2010-10-14 21:44:08 ----A---- C:\Windows\system32\wmpmde.dll
======List of files/folders modified in the last 1 months======
2010-10-31 16:33:06 ----D---- C:\Windows\Prefetch
2010-10-31 16:32:59 ----RD---- C:\Program Files
2010-10-31 16:32:56 ----D---- C:\Windows\Temp
2010-10-31 16:27:25 ----D---- C:\Windows\system32\drivers\Avg
2010-10-31 16:25:52 ----D---- C:\Windows\System32
2010-10-31 16:25:52 ----D---- C:\Windows\inf
2010-10-31 16:25:52 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-10-31 16:21:07 ----D---- C:\Users\Jana\AppData\Roaming\ICQ
2010-10-28 17:31:59 ----D---- C:\Windows\Microsoft.NET
2010-10-28 17:09:50 ----RSD---- C:\Windows\assembly
2010-10-28 16:16:23 ----SHD---- C:\System Volume Information
2010-10-28 16:09:17 ----SHD---- C:\Windows\Installer
2010-10-28 16:03:47 ----D---- C:\Windows\winsxs
2010-10-28 16:03:47 ----D---- C:\Windows\SysWOW64
2010-10-28 16:03:45 ----D---- C:\Windows\AppPatch
2010-10-27 16:43:04 ----D---- C:\Windows\system32\catroot2
2010-10-27 16:43:04 ----D---- C:\Windows\system32\catroot
2010-10-26 16:26:18 ----D---- C:\Windows\SYSWOW64\cs-CZ
2010-10-26 16:26:18 ----D---- C:\Windows\system32\cs-CZ
2010-10-26 16:20:12 ----D---- C:\Windows\SYSWOW64\en-US
2010-10-26 16:20:12 ----D---- C:\Windows\system32\en-US
2010-10-26 16:20:09 ----RD---- C:\Program Files (x86)
2010-10-16 18:05:01 ----D---- C:\Windows\rescache
2010-10-15 22:11:52 ----D---- C:\Windows\SYSWOW64\migration
2010-10-15 22:11:52 ----D---- C:\Program Files\Internet Explorer
2010-10-15 22:11:52 ----D---- C:\Program Files (x86)\Internet Explorer
2010-10-15 22:11:51 ----D---- C:\Windows\system32\migration
2010-10-15 22:11:49 ----D---- C:\Windows\system32\drivers
2010-10-15 22:11:49 ----D---- C:\Program Files\Windows Media Player
2010-10-15 22:11:49 ----D---- C:\Program Files (x86)\Windows Media Player
2010-10-15 18:59:08 ----A---- C:\Windows\system32\mrt.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;ATI PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2008-04-28 16400]
R0 PSDFilter;PSDFilter; C:\Windows\system32\DRIVERS\psdfilter.sys [2008-07-29 22064]
R0 UBHelper;UBHelper; C:\Windows\system32\drivers\UBHelper.sys [2008-01-30 16384]
R1 AvgLdx64;AVG Free AVI Loader Driver x64; C:\Windows\System32\Drivers\avgldx64.sys [2010-07-15 269904]
R1 AvgMfx64;AVG Free On-access Scanner Minifilter Driver x64; C:\Windows\System32\Drivers\avgmfx64.sys [2010-06-02 35536]
R1 AvgTdiA;AVG Free Network Redirector x64; C:\Windows\System32\Drivers\avgtdia.sys [2010-07-15 317520]
R2 int15;int15; \??\C:\Windows\SysWOW64\drivers\int15_64.sys [2008-09-30 17952]
R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-07-29 21040]
R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-07-29 60976]
R3 adiusbaw;USB ADSL WAN Adapter; C:\Windows\system32\DRIVERS\adiusbawx64.sys [2007-02-07 169496]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-10-03 4766208]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 275456]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2008-05-20 1458080]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\Drivers\NTIDrvr.sys [2008-01-30 16384]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 108544]
R3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x64.sys [2007-12-28 391680]
S2 ELOADER;General Purpose USB Driver (adildrx64.sys); C:\Windows\System32\Drivers\adildrx64.sys [2007-02-07 58264]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 6144]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 11008]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 7040]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 6656]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 7936]
S3 TPM;Čip TPM; C:\Windows\system32\drivers\tpm.sys [2008-01-21 54840]
S4 ahcix64s;ahcix64s; C:\Windows\system32\drivers\ahcix64s.sys [2008-04-02 215568]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 8704]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 438328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service; C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-05-20 269448]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-10-03 908800]
R2 avg9emc;AVG Free E-mail Scanner; C:\Program Files (x86)\AVG\AVG9\avgemc.exe [2010-07-20 921952]
R2 avg9wd;AVG Free WatchDog; C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe [2010-07-15 308136]
R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-07-29 500784]
R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-10-01 24576]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-09-23 144632]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe [2008-06-13 241734]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 27648]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-09-23 50424]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2008-01-21 19968]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
-----------------EOF-----------------