Logfile of random's system information tool 1.08 (written by random/random)
Run by Dave at 2011-02-02 12:29:22
Microsoft Windows 7 GAMER™ 2010
System drive C: has 191 GB (40%) free of 477 GB
Total RAM: 4094 MB (70% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:29:26, on 2.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\GIGABYTE\Gamer HUD Lite\HUD.exe
C:\Program Files (x86)\Common Files\Lingea Shared\luc.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\Winamp\winamp.exe
C:\Program Files (x86)\QIP Infium\infium.exe
C:\Program Files\trend micro\Dave.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = start.qip.ru
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Welcome Center] C:\Windows\system32\rundll32.exe C:\Windows\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Welcome Center] C:\Windows\system32\rundll32.exe C:\Windows\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut (User 'Default user')
O4 - Startup: GIGABYTE Gamer HUD Lite.lnk = C:\Program Files (x86)\GIGABYTE\Gamer HUD Lite\HUD.exe
O4 - Startup: Lingea Update Center.lnk = C:\Program Files (x86)\Common Files\Lingea Shared\luc.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8670 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\GIGABYTE\Gamer HUD Lite\HUD.exe"
"C:\Program Files (x86)\Common Files\Lingea Shared\luc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-d74897c6-a982-4307-9b40-26e0eebbd187 -SystemEventPortName:HostProcess-16e58b06-bf6c-4cd7-b8f9-fce933647573 -IoCancelEventPortName:HostProcess-237e4638-518a-41cd-a732-45a62aed05a3 -NonStateChangingEventPortName:HostProcess-03dfeee2-eaf8-441c-83c2-0b75786a7fbd -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:f148db9b-7c5a-4329-bc0a-ffc6667363d2
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe" /SILENT
"C:\Program Files (x86)\Winamp\winamp.exe"
"C:\Program Files (x86)\QIP Infium\infium.exe"
C:\Windows\system32\msiexec.exe /V
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\NOTEPAD.EXE" C:\rsit\info.txt
"C:\PROGRAMY\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Ad-Aware Update (Weekly).job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\Dave\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2009-07-14 150768]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [2010-03-25 1548096]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2716216]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-01-03 15028104]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
GIGABYTE Gamer HUD Lite.lnk - C:\Program Files (x86)\GIGABYTE\Gamer HUD Lite\HUD.exe
Lingea Update Center.lnk - C:\Program Files (x86)\Common Files\Lingea Shared\luc.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=0
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-02-02 12:28:06 ----D---- C:\rsit
2011-02-02 12:28:06 ----D---- C:\Program Files\trend micro
2011-02-02 12:26:59 ----D---- C:\Program Files (x86)\Trend Micro
2011-01-11 14:20:13 ----D---- C:\Users\Dave\AppData\Roaming\NVIDIA
2011-01-11 14:06:07 ----D---- C:\Windows\E10DB5DAE57640EAA7FC1CB2A7B283A6.TMP
2011-01-11 14:05:08 ----HD---- C:\Windows\msdownld.tmp
2011-01-11 14:05:08 ----D---- C:\Windows\SYSWOW64\directx
2011-01-11 13:39:06 ----D---- C:\Program Files (x86)\Mass Effect 2
2011-01-11 11:20:19 ----D---- C:\Program Files (x86)\Mass Effect
2011-01-10 22:53:15 ----D---- C:\ProgramData\Media Center Programs
2011-01-08 21:15:25 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-01-08 20:54:58 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-01-08 20:54:27 ----D---- C:\Windows\SYSWOW64\URTTEMP
2011-01-08 20:53:28 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-01-08 20:53:27 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2011-01-08 20:53:26 ----A---- C:\Windows\SYSWOW64\pbsvc.exe
2011-01-08 16:52:44 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2011-01-08 16:52:44 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2011-01-08 16:52:44 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2011-01-08 16:52:44 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2011-01-08 16:52:44 ----A---- C:\Windows\system32\XAudio2_7.dll
2011-01-08 16:52:44 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2011-01-08 16:52:44 ----A---- C:\Windows\system32\xactengine3_7.dll
2011-01-08 16:52:44 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2011-01-08 16:52:43 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2011-01-08 16:52:43 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2011-01-08 16:52:43 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2011-01-08 16:52:43 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2011-01-08 16:52:43 ----A---- C:\Windows\system32\D3DX9_43.dll
2011-01-08 16:52:43 ----A---- C:\Windows\system32\d3dx11_43.dll
2011-01-08 16:52:43 ----A---- C:\Windows\system32\d3dx10_43.dll
2011-01-08 16:52:43 ----A---- C:\Windows\system32\d3dcsx_43.dll
2011-01-08 16:39:04 ----D---- C:\Program Files (x86)\Activision
2011-01-08 13:26:49 ----D---- C:\Program Files (x86)\Mortal Kombat Gold
2011-01-07 21:20:22 ----D---- C:\ProgramData\Electronic Arts
2011-01-07 21:20:22 ----D---- C:\ProgramData\EA Core
2011-01-07 21:12:55 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2011-01-07 21:12:55 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2011-01-07 21:12:55 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2011-01-07 21:12:55 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2011-01-07 21:12:55 ----A---- C:\Windows\system32\XAudio2_6.dll
2011-01-07 21:12:55 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2011-01-07 21:12:55 ----A---- C:\Windows\system32\xactengine3_6.dll
2011-01-07 21:12:55 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2011-01-07 21:12:54 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2011-01-07 21:12:54 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2011-01-07 21:12:54 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-01-07 21:12:54 ----A---- C:\Windows\system32\xactengine3_5.dll
2011-01-07 21:12:53 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2011-01-07 21:12:53 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2011-01-07 21:12:53 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-01-07 21:12:53 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-01-07 21:12:52 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2011-01-07 21:12:52 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2011-01-07 21:12:52 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2011-01-07 21:12:52 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-01-07 21:12:52 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-01-07 21:12:52 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-01-07 21:12:50 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2011-01-07 21:12:50 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2011-01-07 21:12:50 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-01-07 21:12:50 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-01-07 21:12:49 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2011-01-07 21:12:49 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2011-01-07 21:12:49 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2011-01-07 21:12:49 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-01-07 21:12:49 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-01-07 21:12:49 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-01-07 21:12:48 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2011-01-07 21:12:48 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2011-01-07 21:12:48 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-01-07 21:12:48 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-01-07 21:12:47 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2011-01-07 21:12:47 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2011-01-07 21:12:47 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-01-07 21:12:47 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-01-07 21:12:46 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2011-01-07 21:12:46 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2011-01-07 21:12:46 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2011-01-07 21:12:46 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2011-01-07 21:12:46 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2011-01-07 21:12:46 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-01-07 21:12:46 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-01-07 21:12:46 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-01-07 21:12:46 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-01-07 21:12:46 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-01-07 21:12:45 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2011-01-07 21:12:45 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2011-01-07 21:12:45 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2011-01-07 21:12:45 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-01-07 21:12:45 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-01-07 21:12:45 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-01-07 21:12:44 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2011-01-07 21:12:44 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-01-07 21:12:44 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-01-07 21:12:44 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-01-07 21:12:43 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2011-01-07 21:12:43 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-01-07 21:12:42 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2011-01-07 21:12:42 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2011-01-07 21:12:42 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2011-01-07 21:12:42 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2011-01-07 21:12:42 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-01-07 21:12:42 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-01-07 21:12:42 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-01-07 21:12:42 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-01-07 21:12:41 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2011-01-07 21:12:41 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2011-01-07 21:12:41 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2011-01-07 21:12:41 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-01-07 21:12:41 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-01-07 21:12:41 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-01-07 21:12:40 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2011-01-07 21:12:40 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2011-01-07 21:12:40 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-01-07 21:12:40 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-01-07 21:12:39 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2011-01-07 21:12:39 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2011-01-07 21:12:39 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2011-01-07 21:12:39 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-01-07 21:12:39 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-01-07 21:12:39 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-01-07 21:12:38 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2011-01-07 21:12:38 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-01-07 21:12:37 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2011-01-07 21:12:37 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2011-01-07 21:12:37 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2011-01-07 21:12:37 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-01-07 21:12:37 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-01-07 21:12:37 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-01-07 21:12:36 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2011-01-07 21:12:36 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2011-01-07 21:12:36 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-01-07 21:12:36 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-01-07 21:12:35 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2011-01-07 21:12:35 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2011-01-07 21:12:35 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-01-07 21:12:35 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-01-07 21:12:34 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-01-07 21:12:34 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-01-07 21:12:33 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2011-01-07 21:12:33 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2011-01-07 21:12:33 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2011-01-07 21:12:33 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2011-01-07 21:12:33 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-01-07 21:12:33 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-01-07 21:12:33 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-01-07 21:12:33 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-01-07 21:12:32 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2011-01-07 21:12:32 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2011-01-07 21:12:32 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-01-07 21:12:32 ----A---- C:\Windows\system32\xinput1_3.dll
2011-01-07 21:12:32 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-01-07 21:12:32 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-01-07 21:12:31 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2011-01-07 21:12:31 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2011-01-07 21:12:31 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-01-07 21:12:31 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-01-07 21:12:30 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2011-01-07 21:12:30 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2011-01-07 21:12:30 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-01-07 21:12:30 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-01-07 21:12:29 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2011-01-07 21:12:29 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-01-07 21:12:29 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-01-07 21:12:29 ----A---- C:\Windows\system32\d3dx10.dll
2011-01-07 21:12:28 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2011-01-07 21:12:28 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2011-01-07 21:12:28 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-01-07 21:12:28 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-01-07 21:12:28 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-01-07 21:12:28 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-01-07 21:12:27 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2011-01-07 21:12:27 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2011-01-07 21:12:27 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-01-07 21:12:27 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-01-07 21:12:26 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2011-01-07 21:12:26 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2011-01-07 21:12:26 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2011-01-07 21:12:26 ----A---- C:\Windows\system32\xinput1_2.dll
2011-01-07 21:12:26 ----A---- C:\Windows\system32\xinput1_1.dll
2011-01-07 21:12:26 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-01-07 21:12:25 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2011-01-07 21:12:25 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-01-07 21:12:20 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2011-01-07 21:12:20 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2011-01-07 21:12:20 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-01-07 21:12:20 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-01-07 21:12:20 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-01-07 21:12:20 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-01-07 21:12:19 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2011-01-07 21:12:19 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2011-01-07 21:12:19 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-01-07 21:12:19 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-01-07 21:12:18 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2011-01-07 21:12:18 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-01-07 21:12:17 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2011-01-07 21:12:17 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-01-07 21:12:16 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2011-01-07 21:12:16 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2011-01-07 21:12:16 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-01-07 21:12:16 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-01-07 21:11:20 ----D---- C:\ProgramData\Solidshield
2011-01-07 18:46:57 ----SHD---- C:\Users\Dave\AppData\Roaming\.#
2011-01-07 18:46:51 ----D---- C:\Program Files (x86)\Hero Fighter
2011-01-07 18:32:57 ----D---- C:\Program Files (x86)\LittleFighter2
======List of files/folders modified in the last 1 months======
2011-02-02 12:29:25 ----D---- C:\Windows\Temp
2011-02-02 12:29:04 ----D---- C:\Windows\Prefetch
2011-02-02 12:28:53 ----D---- C:\PROGRAMY
2011-02-02 12:28:06 ----RD---- C:\Program Files
2011-02-02 12:27:02 ----SHD---- C:\Windows\Installer
2011-02-02 12:26:59 ----RD---- C:\Program Files (x86)
2011-02-02 12:26:54 ----SHD---- C:\System Volume Information
2011-02-02 12:26:09 ----D---- C:\Users\Dave\AppData\Roaming\Skype
2011-02-02 10:52:01 ----D---- C:\Windows\system32\config
2011-02-02 10:45:09 ----D---- C:\Windows\System32
2011-02-02 10:45:09 ----D---- C:\Windows\inf
2011-02-02 10:45:09 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-02-02 10:41:16 ----D---- C:\Users\Dave\AppData\Roaming\skypePM
2011-02-02 10:41:00 ----D---- C:\ProgramData\NVIDIA
2011-02-01 23:53:16 ----D---- C:\Users\Dave\AppData\Roaming\dvdcss
2011-02-01 22:36:17 ----D---- C:\Users\Dave\AppData\Roaming\vlc
2011-02-01 21:57:06 ----D---- C:\FILMY
2011-02-01 17:25:58 ----D---- C:\Windows\Tasks
2011-02-01 10:48:45 ----D---- C:\Windows\system32\Tasks
2011-01-30 19:02:57 ----RD---- C:\Program Files (x86)\Skype
2011-01-30 19:02:57 ----D---- C:\Program Files (x86)\Common Files
2011-01-28 23:09:56 ----D---- C:\HRY
2011-01-27 18:01:23 ----D---- C:\Program Files (x86)\Opera
2011-01-26 13:57:22 ----D---- C:\Windows\system32\NDF
2011-01-20 13:56:46 ----A---- C:\Windows\system32\lsdelete.exe
2011-01-19 21:30:18 ----D---- C:\Windows
2011-01-11 14:16:16 ----D---- C:\Windows\winsxs
2011-01-11 14:05:08 ----D---- C:\Windows\SysWOW64
2011-01-11 13:26:56 ----D---- C:\Windows\system32\catroot2
2011-01-10 22:53:15 ----HD---- C:\ProgramData
2011-01-08 21:15:28 ----SD---- C:\ProgramData\Microsoft
2011-01-08 20:55:10 ----D---- C:\Windows\Registration
2011-01-08 20:55:03 ----RSD---- C:\Windows\assembly
2011-01-08 20:54:27 ----D---- C:\Program Files (x86)\Internet Explorer
2011-01-08 20:53:26 ----D---- C:\Windows\system32\LogFiles
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-26 834544]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 136584]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 145336]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-12-18 123200]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl664.sys [2009-06-10 1311232]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S3 akgf5eca;akgf5eca; C:\Windows\system32\drivers\akgf5eca.sys []
S3 androidusb;ADB Interface Driver; C:\Windows\System32\Drivers\androidusb.sys [2010-04-29 32768]
S3 E1G60;Intel(R) PRO/1000 NDIS 6 Adapter Driver; C:\Windows\system32\DRIVERS\E1G6032E.sys [2009-06-10 145792]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; \??\C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [2010-11-06 17440]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-10-08 990312]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-01-08 66872]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-08 369256]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-01-20 1402272]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe []
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 23296]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
-----------------EOF-----------------

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Preventivka - zda se mi ze je PC zpomalene..
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Preventivka - zda se mi ze je PC zpomalene..
Zdravim a pekny den preji
Co to mate za edici W7 - GAMER 2010
To je oficialni edice, kterou vydal microsoft
Dle meho to zavani nelegalnim OS
Poprosim i o druhy log z RSIT s nazvem info.txt, je ulozen v c:\rsit






Re: Preventivka - zda se mi ze je PC zpomalene..
info.txt logfile of random's system information tool 1.08 2011-02-02 12:28:12
======Uninstall list======
-->MsiExec /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
7-Zip 9.09 (x64 edition)-->MsiExec.exe /I{23170F69-40C1-2702-0909-000001000000}
Ad-Aware-->"C:\ProgramData\{437292BE-95BD-4B12-B699-6D217A03ACAF}\Ad-AwareInstall.exe" REMOVE=TRUE MODIFY=FALSE
Ad-Aware-->C:\ProgramData\{437292BE-95BD-4B12-B699-6D217A03ACAF}\Ad-AwareInstall.exe
Adobe AIR-->C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Community Help-->msiexec /qb /x {0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}
Adobe Community Help-->MsiExec.exe /I{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}
Adobe Flash Player 10 Plugin 64-bit-->C:\Windows\system32\Macromed\Flash\FlashUtil64_10_2_161_Plugin.exe -maintain plugin
Adobe Flash Player 10 Plugin-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10k_Plugin.exe -maintain plugin
Adobe Media Player-->msiexec /qb /x {DE3A9DC5-9A5D-6485-9662-347162C7E4CA}
Adobe Media Player-->MsiExec.exe /I{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}
Adobe Photoshop CS5-->C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\PDApp.exe --appletID="DWA_UI" --appletVersion="1.0" --mode="Uninstall" --mediaSignature="{15FEDA5F-141C-4127-8D7E-B962D1742728}"
Adobe Reader 9.4.1 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A94000000001}
CCleaner-->"C:\Program Files (x86)\CCleaner\uninst.exe"
Cole2k Media - Codec Pack (Advanced) 7.9.0-->C:\Windows\SysWOW64\C2MP\Uninst.exe
Combined Community Codec Pack 2009-09-09-->"C:\Program Files (x86)\Combined Community Codec Pack\unins000.exe"
DAEMON Tools Toolbar-->C:\Program Files (x86)\DAEMON Tools Toolbar\uninst.exe
Game Booster-->"C:\Program Files (x86)\IObit\Game Booster\unins000.exe"
Gamer HUD Lite-->MsiExec.exe /I{8FE4D086-63BD-44EB-882C-C7EA5A1EF016}
HiJackThis-->MsiExec.exe /X{45A66726-69BC-466B-A7A4-12FCBA4883D7}
Lineage® II: The Chaotic Throne - Freya-->"C:\Program Files (x86)\InstallShield Installation Information\{21040472-F8DF-48A9-A093-2986C1495670}\setup.exe" -runfromtemp -l0x0009 -removeonly
Lingea EasyLex 2-->C:\Program Files (x86)\Lingea\EasyLex2\Setup.exe /u
Little Fighter 2 version 2.0a-->C:\Program Files (x86)\LittleFighter2\LF2_v2.0a\Uninstal.exe
Mass Effect 2-->"C:\Program Files (x86)\Mass Effect 2\Uninstall\unins000.exe"
Mass Effect-->C:\Program Files (x86)\Common Files\BioWare\Uninstall Mass Effect.exe
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110405-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{071c9b48-7c32-4621-a0ac-3f809523288f}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17-->MsiExec.exe /X{8220EEFE-38CD-377E-8595-13398D740ACE}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319-->MsiExec.exe /X{196BB40D-1578-3D01-B289-BEFC77A11A1E}
Microsoft_VC80_ATL_x86_x64-->MsiExec.exe /I{925D058B-564A-443A-B4B2-7E90C6432E55}
Microsoft_VC80_CRT_x86_x64-->MsiExec.exe /I{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}
Microsoft_VC80_CRT_x86-->MsiExec.exe /I{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}
Microsoft_VC80_MFC_x86_x64-->MsiExec.exe /I{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}
Microsoft_VC80_MFC_x86-->MsiExec.exe /I{D1A19B02-817E-4296-A45B-07853FD74D57}
Microsoft_VC80_MFCLOC_x86_x64-->MsiExec.exe /I{1E9FC118-651D-4934-97BE-E53CAE5C7D45}
Microsoft_VC80_MFCLOC_x86-->MsiExec.exe /I{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}
Microsoft_VC90_ATL_x86_x64-->MsiExec.exe /I{8557397C-A42D-486F-97B3-A2CBC2372593}
Microsoft_VC90_ATL_x86-->MsiExec.exe /I{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}
Microsoft_VC90_CRT_x86_x64-->MsiExec.exe /I{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}
Microsoft_VC90_CRT_x86-->MsiExec.exe /I{08D2E121-7F6A-43EB-97FD-629B44903403}
Microsoft_VC90_MFC_x86_x64-->MsiExec.exe /I{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}
Microsoft_VC90_MFC_x86-->MsiExec.exe /I{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}
Need for Speed(TM) Hot Pursuit-->MsiExec.exe /X{83A606F5-BF6F-42ED-9F33-B9F74297CDED}
NVIDIA 3D Vision Controller Driver-->"C:\Program Files (x86)\InstallShield Installation Information\{714B9C6C-70FC-4750-98E2-61520B906C45}\setup.exe" -runfromtemp -l0x0009 -removeonly
NVIDIA 3D Vision Driver 260.89-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.3DVision
NVIDIA 3D Vision PowerPack - Santa Cruz Beach Boardwalk (MPO)-->"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\PowerPack uninstallers\NVIDIA 3D Vision PowerPack - Santa Cruz Beach Boardwalk (MPO)\unins000.exe"
NVIDIA Graphics Driver 260.89-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.Driver
NVIDIA PhysX System Software 9.10.0514-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.PhysX
NVIDIA PhysX-->MsiExec.exe /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
NVIDIA Stereoscopic 3D Driver-->"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvStInst.exe" /uninstall /ask
Opera 11.01-->"C:\Program Files (x86)\Opera\Opera.exe" /uninstall
PDF Settings CS5-->MsiExec.exe /I{A78FE97A-C0C8-49CE-89D0-EDD524A17392}
PunkBuster Services-->C:\Windows\system32\pbsvc.exe -u
PVSonyDll-->MsiExec.exe /I{3D3E663D-4E7E-4577-A560-7ECDDD45548A}
S.T.A.L.K.E.R. - Shadow of Chernobyl [v1.0005]-->"C:\Program Files (x86)\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\unins000.exe"
Skype Toolbars-->MsiExec.exe /I{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}
Skype™ 5.1-->MsiExec.exe /X{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}
Spyware Terminator-->"C:\Program Files (x86)\Spyware Terminator\unins000.exe"
TeamSpeak 3 Client-->"C:\Program Files\TeamSpeak 3 Client\uninstall.exe"
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\Windows\SysWOW64\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
VLC media player 1.0.3-->C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe
Winamp-->"C:\Program Files (x86)\Winamp\UninstWA.exe"
Windows Live Messenger-->MsiExec.exe /X{A85FD55B-891B-4314-97A5-EA96C0BD80B5}
WinRAR arkivering-->C:\Program Files\WinRAR\uninstall.exe
World of Warcraft-->C:\Program Files (x86)\Common Files\Blizzard Entertainment\World of Warcraft (2)\Uninstall.exe
======System event log======
Computer Name: Dave-PC
Event Code: 20
Message: Installation Failure: Windows failed to install the following update with error 0x800f0902: Security Update for Windows 7 for x64-based Systems (KB2207566).
Record Number: 2065
Source Name: Microsoft-Windows-WindowsUpdateClient
Time Written: 20101026205024.816644-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: Dave-PC
Event Code: 20
Message: Installation Failure: Windows failed to install the following update with error 0x800f0902: Security Update for Windows 7 for x64-based Systems (KB2296011).
Record Number: 2064
Source Name: Microsoft-Windows-WindowsUpdateClient
Time Written: 20101026205024.754243-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: Dave-PC
Event Code: 20
Message: Installation Failure: Windows failed to install the following update with error 0x800f0902: Update for Windows 7 for x64-based Systems (KB982110).
Record Number: 2063
Source Name: Microsoft-Windows-WindowsUpdateClient
Time Written: 20101026205024.723043-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: Dave-PC
Event Code: 4001
Message: WLAN AutoConfig service has successfully stopped.
Record Number: 1854
Source Name: Microsoft-Windows-WLAN-AutoConfig
Time Written: 20101026202541.766575-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: WIN-COKLM18CPON
Event Code: 10010
Message: The server {9E175B68-F52A-11D8-B9A5-505054503030} did not register with DCOM within the required timeout.
Record Number: 1634
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20101026201518.000000-000
Event Type: Error
User:
=====Application event log=====
Computer Name: Dave-PC
Event Code: 3036
Message: The content source <iehistory://{S-1-5-18}/> cannot be accessed.
Context: Windows Application, SystemIndex Catalog
Details:
(HRESULT : 0x80004005) (0x80004005)
Record Number: 401
Source Name: Microsoft-Windows-Search
Time Written: 20101026202508.000000-000
Event Type: Warning
User:
Computer Name: Dave-PC
Event Code: 1
Message: The application (Daemon Tools, from vendor DT Soft Ltd.) has the following problem: Daemon Tools is incompatible with this version of Windows. For more information, contact DT Soft Ltd..
Record Number: 399
Source Name: Microsoft-Windows-ApplicationExperienceInfrastructure
Time Written: 20101026202420.497232-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: Dave-PC
Event Code: 1008
Message: The Windows Search Service is starting up and attempting to remove the old search index {Reason: Full Index Reset}.
Record Number: 356
Source Name: Microsoft-Windows-Search
Time Written: 20101026201925.000000-000
Event Type: Warning
User:
Computer Name: Dave-PC
Event Code: 11
Message: Possible Memory Leak. Application (C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted) (PID: 1000) has passed a non-NULL pointer to RPC for an [out] parameter marked [allocate(all_nodes)]. [allocate(all_nodes)] parameters are always reallocated; if the original pointer contained the address of valid memory, that memory will be leaked. The call originated on the interface with UUID ({3F31C91E-2545-4B7B-9311-9529E8BFFEF6}), Method number (20). User Action: Contact your application vendor for an updated version of the application.
Record Number: 355
Source Name: Microsoft-Windows-RPC-Events
Time Written: 20101026201920.836093-000
Event Type: Warning
User: NT AUTHORITY\LOCAL SERVICE
Computer Name: WIN-COKLM18CPON
Event Code: 6001
Message: The winlogon notification subscriber <GPClient> failed a notification event.
Record Number: 319
Source Name: Microsoft-Windows-Winlogon
Time Written: 20091111061923.000000-000
Event Type: Warning
User:
=====Security event log=====
Computer Name: WIN-COKLM18CPON
Event Code: 4624
Message: An account was successfully logged on.
Subject:
Security ID: S-1-5-18
Account Name: WIN-COKLM18CPON$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon Type: 5
New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x1bc
Process Name: C:\Windows\System32\services.exe
Network Information:
Workstation Name:
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 343
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20091111061745.828125-000
Event Type: Audit Success
User:
Computer Name: WIN-COKLM18CPON
Event Code: 4672
Message: Special privileges assigned to new logon.
Subject:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 342
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20091111061743.796875-000
Event Type: Audit Success
User:
Computer Name: WIN-COKLM18CPON
Event Code: 4624
Message: An account was successfully logged on.
Subject:
Security ID: S-1-5-18
Account Name: WIN-COKLM18CPON$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon Type: 5
New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x1bc
Process Name: C:\Windows\System32\services.exe
Network Information:
Workstation Name:
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 341
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20091111061743.796875-000
Event Type: Audit Success
User:
Computer Name: WIN-COKLM18CPON
Event Code: 4738
Message: A user account was changed.
Subject:
Security ID: S-1-5-21-3145379063-154467699-3503877159-500
Account Name: Administrator
Account Domain: WIN-COKLM18CPON
Logon ID: 0x178a8
Target Account:
Security ID: S-1-5-21-3145379063-154467699-3503877159-500
Account Name: Administrator
Account Domain: WIN-COKLM18CPON
Changed Attributes:
SAM Account Name: -
Display Name: -
User Principal Name: -
Home Directory: -
Home Drive: -
Script Path: -
Profile Path: -
User Workstations: -
Password Last Set: -
Account Expires: -
Primary Group ID: -
AllowedToDelegateTo: -
Old UAC Value: 0x211
New UAC Value: 0x211
User Account Control: -
User Parameters: -
SID History: -
Logon Hours: -
Additional Information:
Privileges: -
Record Number: 340
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20091111061738.031250-000
Event Type: Audit Success
User:
Computer Name: WIN-COKLM18CPON
Event Code: 1102
Message: The audit log was cleared.
Subject:
Security ID: S-1-5-21-3145379063-154467699-3503877159-500
Account Name: Administrator
Domain Name: WIN-COKLM18CPON
Logon ID: 0x178a8
Record Number: 339
Source Name: Microsoft-Windows-Eventlog
Time Written: 20091111061719.468750-000
Event Type: Audit Success
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
"PROCESSOR_REVISION"=170a
-----------------EOF-----------------
======Uninstall list======
-->MsiExec /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
7-Zip 9.09 (x64 edition)-->MsiExec.exe /I{23170F69-40C1-2702-0909-000001000000}
Ad-Aware-->"C:\ProgramData\{437292BE-95BD-4B12-B699-6D217A03ACAF}\Ad-AwareInstall.exe" REMOVE=TRUE MODIFY=FALSE
Ad-Aware-->C:\ProgramData\{437292BE-95BD-4B12-B699-6D217A03ACAF}\Ad-AwareInstall.exe
Adobe AIR-->C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Community Help-->msiexec /qb /x {0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}
Adobe Community Help-->MsiExec.exe /I{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}
Adobe Flash Player 10 Plugin 64-bit-->C:\Windows\system32\Macromed\Flash\FlashUtil64_10_2_161_Plugin.exe -maintain plugin
Adobe Flash Player 10 Plugin-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10k_Plugin.exe -maintain plugin
Adobe Media Player-->msiexec /qb /x {DE3A9DC5-9A5D-6485-9662-347162C7E4CA}
Adobe Media Player-->MsiExec.exe /I{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}
Adobe Photoshop CS5-->C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\PDApp.exe --appletID="DWA_UI" --appletVersion="1.0" --mode="Uninstall" --mediaSignature="{15FEDA5F-141C-4127-8D7E-B962D1742728}"
Adobe Reader 9.4.1 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A94000000001}
CCleaner-->"C:\Program Files (x86)\CCleaner\uninst.exe"
Cole2k Media - Codec Pack (Advanced) 7.9.0-->C:\Windows\SysWOW64\C2MP\Uninst.exe
Combined Community Codec Pack 2009-09-09-->"C:\Program Files (x86)\Combined Community Codec Pack\unins000.exe"
DAEMON Tools Toolbar-->C:\Program Files (x86)\DAEMON Tools Toolbar\uninst.exe
Game Booster-->"C:\Program Files (x86)\IObit\Game Booster\unins000.exe"
Gamer HUD Lite-->MsiExec.exe /I{8FE4D086-63BD-44EB-882C-C7EA5A1EF016}
HiJackThis-->MsiExec.exe /X{45A66726-69BC-466B-A7A4-12FCBA4883D7}
Lineage® II: The Chaotic Throne - Freya-->"C:\Program Files (x86)\InstallShield Installation Information\{21040472-F8DF-48A9-A093-2986C1495670}\setup.exe" -runfromtemp -l0x0009 -removeonly
Lingea EasyLex 2-->C:\Program Files (x86)\Lingea\EasyLex2\Setup.exe /u
Little Fighter 2 version 2.0a-->C:\Program Files (x86)\LittleFighter2\LF2_v2.0a\Uninstal.exe
Mass Effect 2-->"C:\Program Files (x86)\Mass Effect 2\Uninstall\unins000.exe"
Mass Effect-->C:\Program Files (x86)\Common Files\BioWare\Uninstall Mass Effect.exe
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110405-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{071c9b48-7c32-4621-a0ac-3f809523288f}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17-->MsiExec.exe /X{8220EEFE-38CD-377E-8595-13398D740ACE}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319-->MsiExec.exe /X{196BB40D-1578-3D01-B289-BEFC77A11A1E}
Microsoft_VC80_ATL_x86_x64-->MsiExec.exe /I{925D058B-564A-443A-B4B2-7E90C6432E55}
Microsoft_VC80_CRT_x86_x64-->MsiExec.exe /I{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}
Microsoft_VC80_CRT_x86-->MsiExec.exe /I{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}
Microsoft_VC80_MFC_x86_x64-->MsiExec.exe /I{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}
Microsoft_VC80_MFC_x86-->MsiExec.exe /I{D1A19B02-817E-4296-A45B-07853FD74D57}
Microsoft_VC80_MFCLOC_x86_x64-->MsiExec.exe /I{1E9FC118-651D-4934-97BE-E53CAE5C7D45}
Microsoft_VC80_MFCLOC_x86-->MsiExec.exe /I{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}
Microsoft_VC90_ATL_x86_x64-->MsiExec.exe /I{8557397C-A42D-486F-97B3-A2CBC2372593}
Microsoft_VC90_ATL_x86-->MsiExec.exe /I{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}
Microsoft_VC90_CRT_x86_x64-->MsiExec.exe /I{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}
Microsoft_VC90_CRT_x86-->MsiExec.exe /I{08D2E121-7F6A-43EB-97FD-629B44903403}
Microsoft_VC90_MFC_x86_x64-->MsiExec.exe /I{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}
Microsoft_VC90_MFC_x86-->MsiExec.exe /I{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}
Need for Speed(TM) Hot Pursuit-->MsiExec.exe /X{83A606F5-BF6F-42ED-9F33-B9F74297CDED}
NVIDIA 3D Vision Controller Driver-->"C:\Program Files (x86)\InstallShield Installation Information\{714B9C6C-70FC-4750-98E2-61520B906C45}\setup.exe" -runfromtemp -l0x0009 -removeonly
NVIDIA 3D Vision Driver 260.89-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.3DVision
NVIDIA 3D Vision PowerPack - Santa Cruz Beach Boardwalk (MPO)-->"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\PowerPack uninstallers\NVIDIA 3D Vision PowerPack - Santa Cruz Beach Boardwalk (MPO)\unins000.exe"
NVIDIA Graphics Driver 260.89-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.Driver
NVIDIA PhysX System Software 9.10.0514-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.PhysX
NVIDIA PhysX-->MsiExec.exe /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
NVIDIA Stereoscopic 3D Driver-->"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvStInst.exe" /uninstall /ask
Opera 11.01-->"C:\Program Files (x86)\Opera\Opera.exe" /uninstall
PDF Settings CS5-->MsiExec.exe /I{A78FE97A-C0C8-49CE-89D0-EDD524A17392}
PunkBuster Services-->C:\Windows\system32\pbsvc.exe -u
PVSonyDll-->MsiExec.exe /I{3D3E663D-4E7E-4577-A560-7ECDDD45548A}
S.T.A.L.K.E.R. - Shadow of Chernobyl [v1.0005]-->"C:\Program Files (x86)\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\unins000.exe"
Skype Toolbars-->MsiExec.exe /I{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}
Skype™ 5.1-->MsiExec.exe /X{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}
Spyware Terminator-->"C:\Program Files (x86)\Spyware Terminator\unins000.exe"
TeamSpeak 3 Client-->"C:\Program Files\TeamSpeak 3 Client\uninstall.exe"
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\Windows\SysWOW64\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
VLC media player 1.0.3-->C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe
Winamp-->"C:\Program Files (x86)\Winamp\UninstWA.exe"
Windows Live Messenger-->MsiExec.exe /X{A85FD55B-891B-4314-97A5-EA96C0BD80B5}
WinRAR arkivering-->C:\Program Files\WinRAR\uninstall.exe
World of Warcraft-->C:\Program Files (x86)\Common Files\Blizzard Entertainment\World of Warcraft (2)\Uninstall.exe
======System event log======
Computer Name: Dave-PC
Event Code: 20
Message: Installation Failure: Windows failed to install the following update with error 0x800f0902: Security Update for Windows 7 for x64-based Systems (KB2207566).
Record Number: 2065
Source Name: Microsoft-Windows-WindowsUpdateClient
Time Written: 20101026205024.816644-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: Dave-PC
Event Code: 20
Message: Installation Failure: Windows failed to install the following update with error 0x800f0902: Security Update for Windows 7 for x64-based Systems (KB2296011).
Record Number: 2064
Source Name: Microsoft-Windows-WindowsUpdateClient
Time Written: 20101026205024.754243-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: Dave-PC
Event Code: 20
Message: Installation Failure: Windows failed to install the following update with error 0x800f0902: Update for Windows 7 for x64-based Systems (KB982110).
Record Number: 2063
Source Name: Microsoft-Windows-WindowsUpdateClient
Time Written: 20101026205024.723043-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: Dave-PC
Event Code: 4001
Message: WLAN AutoConfig service has successfully stopped.
Record Number: 1854
Source Name: Microsoft-Windows-WLAN-AutoConfig
Time Written: 20101026202541.766575-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: WIN-COKLM18CPON
Event Code: 10010
Message: The server {9E175B68-F52A-11D8-B9A5-505054503030} did not register with DCOM within the required timeout.
Record Number: 1634
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20101026201518.000000-000
Event Type: Error
User:
=====Application event log=====
Computer Name: Dave-PC
Event Code: 3036
Message: The content source <iehistory://{S-1-5-18}/> cannot be accessed.
Context: Windows Application, SystemIndex Catalog
Details:
(HRESULT : 0x80004005) (0x80004005)
Record Number: 401
Source Name: Microsoft-Windows-Search
Time Written: 20101026202508.000000-000
Event Type: Warning
User:
Computer Name: Dave-PC
Event Code: 1
Message: The application (Daemon Tools, from vendor DT Soft Ltd.) has the following problem: Daemon Tools is incompatible with this version of Windows. For more information, contact DT Soft Ltd..
Record Number: 399
Source Name: Microsoft-Windows-ApplicationExperienceInfrastructure
Time Written: 20101026202420.497232-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: Dave-PC
Event Code: 1008
Message: The Windows Search Service is starting up and attempting to remove the old search index {Reason: Full Index Reset}.
Record Number: 356
Source Name: Microsoft-Windows-Search
Time Written: 20101026201925.000000-000
Event Type: Warning
User:
Computer Name: Dave-PC
Event Code: 11
Message: Possible Memory Leak. Application (C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted) (PID: 1000) has passed a non-NULL pointer to RPC for an [out] parameter marked [allocate(all_nodes)]. [allocate(all_nodes)] parameters are always reallocated; if the original pointer contained the address of valid memory, that memory will be leaked. The call originated on the interface with UUID ({3F31C91E-2545-4B7B-9311-9529E8BFFEF6}), Method number (20). User Action: Contact your application vendor for an updated version of the application.
Record Number: 355
Source Name: Microsoft-Windows-RPC-Events
Time Written: 20101026201920.836093-000
Event Type: Warning
User: NT AUTHORITY\LOCAL SERVICE
Computer Name: WIN-COKLM18CPON
Event Code: 6001
Message: The winlogon notification subscriber <GPClient> failed a notification event.
Record Number: 319
Source Name: Microsoft-Windows-Winlogon
Time Written: 20091111061923.000000-000
Event Type: Warning
User:
=====Security event log=====
Computer Name: WIN-COKLM18CPON
Event Code: 4624
Message: An account was successfully logged on.
Subject:
Security ID: S-1-5-18
Account Name: WIN-COKLM18CPON$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon Type: 5
New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x1bc
Process Name: C:\Windows\System32\services.exe
Network Information:
Workstation Name:
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 343
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20091111061745.828125-000
Event Type: Audit Success
User:
Computer Name: WIN-COKLM18CPON
Event Code: 4672
Message: Special privileges assigned to new logon.
Subject:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 342
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20091111061743.796875-000
Event Type: Audit Success
User:
Computer Name: WIN-COKLM18CPON
Event Code: 4624
Message: An account was successfully logged on.
Subject:
Security ID: S-1-5-18
Account Name: WIN-COKLM18CPON$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon Type: 5
New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x1bc
Process Name: C:\Windows\System32\services.exe
Network Information:
Workstation Name:
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 341
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20091111061743.796875-000
Event Type: Audit Success
User:
Computer Name: WIN-COKLM18CPON
Event Code: 4738
Message: A user account was changed.
Subject:
Security ID: S-1-5-21-3145379063-154467699-3503877159-500
Account Name: Administrator
Account Domain: WIN-COKLM18CPON
Logon ID: 0x178a8
Target Account:
Security ID: S-1-5-21-3145379063-154467699-3503877159-500
Account Name: Administrator
Account Domain: WIN-COKLM18CPON
Changed Attributes:
SAM Account Name: -
Display Name: -
User Principal Name: -
Home Directory: -
Home Drive: -
Script Path: -
Profile Path: -
User Workstations: -
Password Last Set: -
Account Expires: -
Primary Group ID: -
AllowedToDelegateTo: -
Old UAC Value: 0x211
New UAC Value: 0x211
User Account Control: -
User Parameters: -
SID History: -
Logon Hours: -
Additional Information:
Privileges: -
Record Number: 340
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20091111061738.031250-000
Event Type: Audit Success
User:
Computer Name: WIN-COKLM18CPON
Event Code: 1102
Message: The audit log was cleared.
Subject:
Security ID: S-1-5-21-3145379063-154467699-3503877159-500
Account Name: Administrator
Domain Name: WIN-COKLM18CPON
Logon ID: 0x178a8
Record Number: 339
Source Name: Microsoft-Windows-Eventlog
Time Written: 20091111061719.468750-000
Event Type: Audit Success
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
"PROCESSOR_REVISION"=170a
-----------------EOF-----------------
Re: Preventivka - zda se mi ze je PC zpomalene..
vyosek píše:Co to mate za edici W7 - GAMER 2010
To je oficialni edice, kterou vydal microsoft
Dle meho to zavani nelegalnim OS
![]()